Security
Security
All systems incorporate separate access, database, function and data security levels to control user access.
Modern network deployment requires a high degree of access security, control of user functionality and restricted access to data, to prevent internal and external unauthorised interference with sensitive, corporate information.
As a result of changes to disclosure and reporting standards, enhanced business processes and extended audit requirements, asset management systems are fast becoming repositories for extensive quantities of detailed confidential information and this requires enhanced security options within the system.
Activa Asset Management achieves this with a five-level security protocol;
As a result of changes to disclosure and reporting standards, enhanced business processes and extended audit requirements, asset management systems are fast becoming repositories for extensive quantities of detailed confidential information and this requires enhanced security options within the system.
Activa Asset Management achieves this with a five-level security protocol;
- User accounts with definable and enforceable password complexity rules
- database profiles to restrict user access to authorised databases only
- function profiles to limit and enforce functional and data entry options
- data profiles to mask unauthorised data on a need to know basis
- data encryption and compression for network and internet data transfer
A user 'login id' is auto populated from the network session but the password is not. A full suite of password complexity and sunset rules [or otherwise]can be configured and administered centrally including the exclusion of a nominated number of historical passwords. Functionality includes the ability to disable individual features or user accounts, or to enforce password reviews at both the individual user level or globally.
In a multi-database system, user access is always via a System database that acts as a portal to all other databases. This System database contains only security information and is used to restrict individual user access to nominated databases only. This is achieved defining a Database Profile for each user account.
Function Profiles limit user access to specified menu items and can be applied to further limit and enforce capabilites within individual functions and even to specific data fields. They are designed and deployed centrally but apply across all databases in the system for each user. There is no limit to the number of Function Profiles that can be created and existing profiles can be modified at any time to reflect changing permissions or policies.
Access to system data can be further restricted by Data Profiles. These are optional but apply to all users if switched on. Data Profiles ensure that an individual user can only see the information for which he or she is authorised.
Additional information stored in the system in the form of documents, spreadsheets, PDF files, images and others are only transferred bewteen the database and the client [and vice versa] as encrypted, compressed files. Access to view and manage this information is controlled by the Function Profile.
| Bookmark Page | Download PDF | |
| Article last updated : Apr 17 2012 9:59AM | |