Laserfiche WebLink
Security and Hosting Overview <br />June 2015 <br />Active and passive datacenters <br />ServerCentral c/o Equinix <br />ServerCentral c/o Telehouse North <br />Laarderhoogtweg 57 <br />14 Coriander Avenue <br />1101EB Amsterdam, Netherlands <br />London E14 2AA United Kingdom <br />The terms "active' and "passive' designate which of the production hosting <br />environments is being used as the primary (active) and which is being used as the backup <br />(passive or disaster recovery). These designations are not static and SAP Fieldglass will <br />occasionally fail over the active hosting environment to the passive hosting environment. <br />This practice ensures that SAP Fieldglass is capable and ready in the unlikely event a <br />disaster occurs and we need to fail over to the passive site. <br />1.2 Security Management <br />SAP Fieldglass' Security Team is responsible for implementing and maintaining the <br />security controls to ensure that SAP Fieldglass information systems are secure. SAP <br />Fieldglass has based its security program on industry standards and best practices. For <br />our established datacenters, these practices are audited annually by a third party with <br />results available to customers in October. <br />1.2.1 Security Policies, Standards and Procedures <br />SAP Fieldglass maintains a comprehensive set of policies that define the information <br />security goals and objectives. Each policy may be supported by a standard that dictates <br />the required security requirements to ensure the uniform application of technologies and <br />processes. <br />1.2.2 Risk Management <br />SAP Fieldglass manages risk by the identification of threats and vulnerabilities to its <br />information systems and through a control selection process. Controls selected fall into <br />the following categories: <br />• Policy <br />• Physical and Environmental Security <br />• Organizational Security <br />• Communications and Operations Management <br />• Acceptable Use <br />• Access Control <br />• Third Party Access <br />• Information Systems Acquisition, Development and Maintenance <br />• Asset Management <br />• Incident Management <br />• Personnel Security <br />SAP Fieldglass P a g e 6 1 21 <br />