This document explores the most popular security options and currently available. Most of us are familiar with these solutions but we have probably never examined the issues associated with login security.
This document is intended to outline the options available from Business Express bxp for business managers seeking to make informed decisions as to what security options would serve their organisation best.
There is a simple table at the end of the document to help you decide the options best for your organisation.
All n One’s Business Express bxp is a pure SaaS solution hosted in Dublin by Sungard. This partnership provides a range of security features and infrastructure options which means that end users don’t have IaaS or PaaS considerations. Detailed technical security documentation is available from All n One on request.
By default Business Express bxp uses Firstname | Surname, however you can use a number of fields for the unique identifier.
* Username (Firstname Surname combination)
* Work Email address
Business Express bxp has inbuilt routines that swap a user back if they accidentally try to move off HTTPS. Token and user account management combinations reduce the likelihood of effective hacker attack. The Sungard Network Operations Centre (NOC) performs 24 / 7 monitoring and auto adaptation to the most common communications attacks such as DDos (Distributed Denial of Service) and Brute Force hacking. In addition there is a Cisco Adaptive Security Agent (ASA) within the solution architecture.
One of the most common types of security breaches is simply sticking a USB key into the server and downloading files from the server. All n One and Sungard to provide physically secured access to the Business Express bxp private cloud. If you’d like further details on this or any other aspect of our security please contact us and we’ll be happy to provide details.
For clients whose phone system is linked to Business Express bxp we have implemented the ability to have a secondary session key for the phone system which allows the phone system to log the user in on call arrival at the agents’ desk using of Locked Session Keys.
An API allows external systems to interact with a solution (in this case Business Expressbxp) without the need for human intervention. These automated login engines pose their own security risk and for this reason bxp separates the User Interface, username and password and an API username and password so that external systems compromise is a minimum impact on the User Interface.