Laserfiche WebLink
Security and Hosting Overview <br />June 2015 <br />firewall has been configured to enforce protocols and ports that are able to cross LANs <br />with a default deny stance. <br />1.5.4 24/7 Monitoring <br />SAP Fieldglass provides 24/7 monitoring of suspicious activity. Any failure is promptly <br />reported and, after an initial analysis, escalated to the next appropriate level. <br />1.5.5 Enterprise SIEM <br />Our security incident and event management (SIEM) tool has been configured to collect <br />logs and events from all systems and devices within the SAP Fieldglass network. <br />Forwarders are used to collect, filter, normalize and forward relevant data to an Indexer. <br />Each installation listens for Syslog data and actively pulls WMI information from its <br />respective environment. Security related issues are monitored and alerted on where <br />required. <br />1.5.6 Network Pen Testing <br />On an annual basis, SAP Fieldglass engages a 3rd party security company to conduct pen <br />testing services on our network. <br />1.6 Data Management <br />1.6.1 Data Backups and Replication <br />SAP Fieldglass has a highly available backup solution that guarantees data can be restored <br />as expediently as possible. Our solution performs a continuous replication of data to our <br />passive production hosting facility. SAP Fieldglass takes incremental SQL backups every <br />15 minutes and full backups on a nightly basis. Backups are transferred to the passive <br />production hosting environment over a secure channel. SAP Fieldglass' solution offers <br />continuous protection of customer data geographically without imposing performance <br />degradation or scaling limitations. Data is encrypted both at rest and in transit with AES- <br />256. <br />Data backups and replication are performed between the active and passive production <br />environments. The US -based active production environment replicates data to the US - <br />based passive environment. Likewise, The EU-based active production environment <br />replicates data to the EU-based passive environment. <br />Also refer to section 3.1 Disaster Recovery. <br />1.6.2 Data Archiving <br />Data is archived throughout the year. Eligible transactional and reporting data are moved <br />from the active database to an archive database after 24 months. Archived data can be <br />accessed only by customer users with a user role of Administrator. Archive data is <br />accessed using the same login screen and user interface that is used to access current <br />data. Reports can also be generated using archive data from the standard interface. <br />SAP Fieldglass 14 1 21 <br />