Table of Contents


  1. Preface
  2. Introduction to MDM Hub Security
  3. Resources
  4. Roles
  5. Users and User Groups
  6. Security Providers
  7. Application Level Security
  8. Password Hashing
  9. Glossary

Informatica Data Director

Informatica Data Director is a web-based data governance application for the MDM Hub. When you configure a Data Director application, business users can create, manage, consume, and monitor master data.
Informatica Data Director adheres to the top ten security recommendations of the Open Web Application Security Project (OWASP). Informatica uses IBM Security AppScan to test for security vulnerabilities, such as an SQL injection attack. The HTTP methods GET or POST can retrieve information from IDD, but other HTTP methods, such as DELETE or PUT, return an HTTP error.
When you configure a Data Director application, you can organize the tables in the
Operational Reference Store
into business entities or into subject areas. Both approaches provide a way to group related data that you want to treat as a unit, such as all data about a customer. Business entities are the recommended organizational approach since
Multidomain MDM
Version 10.1. Business entities are the core of the Entity 360 framework, which includes business entity services and modern entity views.
For data security, a Data Director application uses the user roles and resource privileges that are set on the
Operational Reference Store
. Recall that an MDM administrator uses the Security Access Manager workbench in the
Hub Console
to define resource privileges for each user role. In a Data Director application, users can perform the operations that are permitted by their user role.
The role privileges for business entities and subject areas are derived from the resource privileges in different ways, so the security might be slightly different. However, both approaches are equally secure. For more information about security for business entities, see the
Multidomain MDM Provisioning Tool Guide
. For more information about security configuration and data security for subject areas, see the
Multidomain MDM Data Director Implementation Guide


