343
edits
Changes
no edit summary
''Separation should exist between different consumers of the service to prevent one malicious or compromised consumer from affecting the service or data of another.''
All instances of the service are segregated by client. This means that one client instance of the software is unable to get any data from another client system. As the system is a SaaS Solution users from the same system will have to log in using different usernames/passwords. All events that occur from the users are stored in log files so it is possible to review all colleague activity though an audit trail functionality built into bxp.For more information on data segregation please view - [http://www.bxpsoftware.com/wixi/index.php?title=The_bxp_Infrastructure#Logical_Infrastructure The bxp Infrastructure]
''The service provider should have processes and procedures in place to ensure the operational security of the service.''
All n One is 80% compliant with ISO 27001 and Cobit 5. All n One currently requires an external audit for validation. Company policies and procedures are stored in a secure internal network. All n One also supplies the public with a company wikipedia that provides information on the service. Our hosting infrastructure is ISO 27001 complaint which shows that SunGard AS Ireland has developed and implemented a best-in-class information security management system (ISMS) for itself and its customers. For additional information on All n One's certification status please view:- [http://www.bxpsoftware.com/wixi/index.php?title=Security_-_Start_Here Introduction to bxp security]
''Service provider staff should be subject to personnel security screening and security education for their role.''
All colleagues are screened though our HR interview process. All n One strives to provide its colleagues with the safest most enjoyable environment and all HR processes are compliant with the data protection act of Ireland. All colleagues are trained in their field of expertise and are also required to complete a data protection course annually to mitigate against any accidental data loss or data exposure. For more information on our HR and operational processes please view. - [http://www.bxpsoftware.com/wixi/index.php?title=Security_-_Start_Here#Operational_Procedures Operational Procedures and Human Resource Procedures]
''Services should be designed and developed to identify and mitigate threats to their security.''
All n One complete vulnerability scans on our service and network in order to find issues to mitigate against. This provides us with the high level of security expected from Industry standard. We also have a policy set for developement work which can be viewed - [http://www.bxpsoftware.com/wixi/index.php?title=How_bxp_is_developed bxp development]
''The service provider should ensure that its supply chain satisfactorily supports all of the security principles that the service claims to implement.''
Our software is hosted in a 3rd party data center, provided by SunGard. Our other partners include Continuum, NB1 Consult Limited and Sheehan & Associates Accountants. Additional information can be found here. - [http://www.bxpsoftware.com/wixi/index.php?title=All_n_One_Partners_and_Suppliers All n One Partners and Suppliers]
''Consumers should be provided with the tools required to help them securely manage their service.''
Clients of the service are told to nominate a security champion for our SaaS Service. This member of staff will be able to use enhanced security features to manage their instance of bxp software (All n One's software). With this the client should be able to manage authentication and seperation of access control within the interface. The system champion will also be able to run reports on the actions of users on their instance of bxp through the audit trail functionality.[http://www.bxpsoftware.com/wixi/index.php?title=User_Profiling_-_Start_Here User Profiling] . bxp software also provides a means for data protection automation which can be viewed from the following link - [http://www.bxpsoftware.com/wixi/index.php?title=Data_Protection_and_Data_Retention Data Protection automation]
''Access to all service interfaces (for consumers and providers) should be constrained to authenticated and authorised individuals.''
All n One utalises the latest in TLS technology to provide out clients with the most secure login possible. By utalizing Google's password strength meter API we also have the ability to reject passwords not considered to be "Best" by Google's standards. We also provide the ability to lock down login attempts to only be successful from a particular IP of range of IP's. In order for All n One to manage our hosted servers we have created a secure encrypted VPN connection with SunGard AS. The office in which the operations team work on bxp software developement is also fully secured with the latest intevo security system from Kantech which was installed by ADT.[http://www.bxpsoftware.com/wixi/index.php?title=Bxp_-_Ballymount_Security Ballymount security]
''The methods used by the service provider’s administrators to manage the operational service should be designed to mitigate any risk of exploitation that could undermine the security of the service.''
At All n One we review log files from the service and offer a full audit trail service to our clients for their instances. Our hosting environment SunGard also mitigates against any DDOS or networking attacks through their technical operations centre (TOC). All n One's security department also give consistent security updates to staff and services when available. For more information on our security department view - [http://www.bxpsoftware.com/wixi/index.php?title=Bxp_API Security Department]
''Consumers should be provided with the audit records they need to monitor access to their service and the data held within it.''
All n One provides a full audit trail to clients of actions completed on their instance of the service. For additional information on bxp audit logs operation view: - [http://www.bxpsoftware.com/wixi/index.php?title=Bxp_-_Audit_Logs bxp audit logs]
== Secure use of the service by the consumer ==
''Consumers have certain responsibilities when using a cloud service in order for it to remain as secure as possible and for their data to be adequately protected.''
We provide a set of guidelines to promote the secure using of our service to these users. The following link has the guidelines for bxp usage- [http://www.bxpsoftware.com/wixi/index.php?title=You_and_your_bxp You and your bxp]
'''All n One provide training for their bxp software to any client who signs up to the service. For this All n One train the client on how to use the system and control the security aspects of the service for their users. The client can also turn on controls as to what a particular user can access so sensitive data could be removed from viewing by a standard colleague.'''