Laserfiche WebLink
Security and Hosting Overview <br />June 2015 <br />1 Introduction <br />This document provides a general overview of the SAP Fieldglass security and hosting <br />infrastructure. It is effective as of the revision date indicated below. However, as security needs <br />continue to evolve, the specific information relating to the topics covered may be subject to <br />change over time. <br />Security <br />The SAP Fieldglass solution was architected to be the most reliable and secure Vendor <br />Management System available today. <br />SAP Fieldglass is proud to offer our customers, subject to review and acceptance by our audit <br />partner, the following assurances: <br />• ISO 27001 certified since 2011 <br />• SSAE 16/ISAE 3402 Type 2 SOC1 audits conducted since 2005 <br />• SSAE 16 Type 2 SOC2 audits in the Trust Services Principles for: <br />• Security — the system is protected, both logically and physically, against <br />unauthorized access <br />• Availability — the system is available for operation and use as committed or <br />agreed to <br />• Processing Integrity — system processing is complete, accurate, timely, and <br />authorized <br />• Confidentiality — information that is designated as "confidential" is protected as <br />committed or agreed <br />• SSAE 16 Type 1 SOC2 audit in the Trust Services Principle for Privacy (Type 2 audit <br />scheduled for Q3 2015) <br />• Annual third party pen testing of our network and application <br />This document provides an understanding of how SAP Fieldglass handles the following areas <br />across its global operations: <br />• Scope of Operations <br />• Security Management <br />• Application Security <br />• Physical Security <br />• Network Security <br />• Data Management <br />• Release Management <br />• Disaster Recovery <br />• Business Continuity <br />SAP Fieldglass P a g e 4 1 21 <br />