SlideShare a Scribd company logo
1 of 10
SECURITY Incorporating Security in IT Solutions for Corporate Registers
SECURITY COMPONENTS Physical Security Server and System Software Security Database Security and Audit Trail Authentication to the Application Application Level Security Online Applications Security
PHYSICAL SECURITY OF IT Environmental design Air Conditioning, Dual UPS and Standby Generators Electronic and procedural access control Biometric Access control for controlling user access points  	Datacenter access limited to IT administrators Intrusion detection and Video monitoring Security alarms and CCTV for incident notification and verification
SECURITY COMPONENTS High Available  Cluster System For Database and Application Server - protection against a single server failure Disaster Recovery System- protection against disaster at Main site Firewall and Intrusion Prevention System Antivirus/ Antispyware server Data Protection System-  Automated backup of servers and databases
Up to date with latest Security patches and fixes Logging of access to all server services Use of encryption for network communication Maintain a proper system backup policy SERVERS AND OS SECURITY
USER AND PASSWORD MANAGEMENT Restriction of User ID to an agreed number of alphanumeric characters (Include special characters in Password @,#) Maintain password Complexity No shared ID issued to multiple users Disabling of Inactive account accounts after an agreed time period Locking of users of  a successive given attempts of failed login
USER AND PASSWORD MANAGEMENT cont.. Initial Password allocated to user will be one time. User forced to change his password on first log in  Users forced to change their password after an agreed time period from the last password change date. User sessions will time-out after an agreed period of inactivity
APPLICATION - LEVEL Access to user on system will be depending on their access rights (Filing officer accessing filing system, Cashier accessing cash collection system, Companies officer accessing Companies Administration Module, Management of ROC accessing all systems )  Access rights to record application Access rights to approve application Access rights to insert, update and delete
APPLICATION – AUDIT TRAIL Any record created in the database will have the user stored in the database and the date it has been created. The user who has last updated the record will be stored in the database.   Any table in the database can be audited and any updates made can be logged. Tracking of Status on Application (Recorded, In Progress, Rejected or Approved). Tracking of Status of Companies (Incorporated, Amalgamate, Dissolve, Wind-Up)
ELECTRONIC SUBMISSIONS Information recorded in a temporary database in the DMZ server. ROC Staff validate the data before sending it in the live database. Each company will have a password to access their account. They can use it to submit their applications online.

More Related Content

What's hot

Understanding 21 cfr part 11
Understanding 21 cfr part 11Understanding 21 cfr part 11
Understanding 21 cfr part 11
complianceonline123
 
Ch02 mis-ctrl-appl
Ch02 mis-ctrl-applCh02 mis-ctrl-appl
Ch02 mis-ctrl-appl
SR NAIDU
 

What's hot (20)

Understanding 21 cfr part 11
Understanding 21 cfr part 11Understanding 21 cfr part 11
Understanding 21 cfr part 11
 
A075434624
A075434624A075434624
A075434624
 
What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?What is a Firewall Risk Assessment?
What is a Firewall Risk Assessment?
 
SWITZ Business Security. Official presentation!
SWITZ Business Security. Official presentation!SWITZ Business Security. Official presentation!
SWITZ Business Security. Official presentation!
 
Blancco Management Console
Blancco Management ConsoleBlancco Management Console
Blancco Management Console
 
Securing control systems v0.4
Securing control systems v0.4Securing control systems v0.4
Securing control systems v0.4
 
Security and-visibility
Security and-visibilitySecurity and-visibility
Security and-visibility
 
21 cfr part 11 basic
21 cfr part 11 basic21 cfr part 11 basic
21 cfr part 11 basic
 
InduSoft Web Studio and Meeting FDA 21 CFR Part 11 Regulations for Food, Beve...
InduSoft Web Studio and Meeting FDA 21 CFR Part 11 Regulations for Food, Beve...InduSoft Web Studio and Meeting FDA 21 CFR Part 11 Regulations for Food, Beve...
InduSoft Web Studio and Meeting FDA 21 CFR Part 11 Regulations for Food, Beve...
 
Abhishek control a9.3_a9.4
Abhishek control a9.3_a9.4Abhishek control a9.3_a9.4
Abhishek control a9.3_a9.4
 
IS audit checklist
IS audit checklistIS audit checklist
IS audit checklist
 
21 CFR part 11 Overview
21 CFR part 11 Overview21 CFR part 11 Overview
21 CFR part 11 Overview
 
Ch02 mis-ctrl-appl
Ch02 mis-ctrl-applCh02 mis-ctrl-appl
Ch02 mis-ctrl-appl
 
ObserveIT Remote Access Monitoring Software - Corporate Presentation
ObserveIT Remote Access Monitoring Software - Corporate PresentationObserveIT Remote Access Monitoring Software - Corporate Presentation
ObserveIT Remote Access Monitoring Software - Corporate Presentation
 
IT and part 11
IT and part 11IT and part 11
IT and part 11
 
21 code of federal regulation
21 code of federal regulation21 code of federal regulation
21 code of federal regulation
 
Iso 27001 control a.12.1,a.12.2 & a.12.3 - by software outsourcing company in...
Iso 27001 control a.12.1,a.12.2 & a.12.3 - by software outsourcing company in...Iso 27001 control a.12.1,a.12.2 & a.12.3 - by software outsourcing company in...
Iso 27001 control a.12.1,a.12.2 & a.12.3 - by software outsourcing company in...
 
Check Point: Compliance Blade
Check Point: Compliance BladeCheck Point: Compliance Blade
Check Point: Compliance Blade
 
Automated monitoring of application updates and vulnerabilities - Apptimized ...
Automated monitoring of application updates and vulnerabilities - Apptimized ...Automated monitoring of application updates and vulnerabilities - Apptimized ...
Automated monitoring of application updates and vulnerabilities - Apptimized ...
 
Csv 21 Cfr11
Csv 21 Cfr11Csv 21 Cfr11
Csv 21 Cfr11
 

Viewers also liked

4.1 security data & hijacking of companies (australia)
4.1 security data & hijacking of companies (australia)4.1 security data & hijacking of companies (australia)
4.1 security data & hijacking of companies (australia)
Corporate Registers Forum
 
7.3 automation of company registry (lesotho)
7.3 automation of company registry (lesotho)7.3 automation of company registry (lesotho)
7.3 automation of company registry (lesotho)
Corporate Registers Forum
 
1 1 Business Registration Reforms (W Bank) 2
1 1 Business Registration Reforms (W Bank) 21 1 Business Registration Reforms (W Bank) 2
1 1 Business Registration Reforms (W Bank) 2
Corporate Registers Forum
 
5.1 moving towards excellence (cook islands)
5.1 moving towards excellence (cook islands)5.1 moving towards excellence (cook islands)
5.1 moving towards excellence (cook islands)
Corporate Registers Forum
 

Viewers also liked (16)

6.2 business registration reform (rwanda)
6.2 business registration reform (rwanda)6.2 business registration reform (rwanda)
6.2 business registration reform (rwanda)
 
2.2 company names (singapore)
2.2 company names (singapore)2.2 company names (singapore)
2.2 company names (singapore)
 
2.3 company names (zambia)
2.3 company names (zambia)2.3 company names (zambia)
2.3 company names (zambia)
 
6.1 integration of services (singapore)
6.1 integration of services (singapore)6.1 integration of services (singapore)
6.1 integration of services (singapore)
 
2.4 company name approval (china)
2.4 company name approval (china)2.4 company name approval (china)
2.4 company name approval (china)
 
2.1 company name reservations (s africa)
2.1 company name reservations (s africa)2.1 company name reservations (s africa)
2.1 company name reservations (s africa)
 
4.1 security data & hijacking of companies (australia)
4.1 security data & hijacking of companies (australia)4.1 security data & hijacking of companies (australia)
4.1 security data & hijacking of companies (australia)
 
7.1 ecrf crf survey 2009 (sweden)
7.1 ecrf crf survey 2009 (sweden)7.1 ecrf crf survey 2009 (sweden)
7.1 ecrf crf survey 2009 (sweden)
 
3.3 data accuracy & integrity (uk)
3.3 data accuracy & integrity (uk)3.3 data accuracy & integrity (uk)
3.3 data accuracy & integrity (uk)
 
7.3 automation of company registry (lesotho)
7.3 automation of company registry (lesotho)7.3 automation of company registry (lesotho)
7.3 automation of company registry (lesotho)
 
2.5 corporate name policy (canada)
2.5 corporate name policy (canada)2.5 corporate name policy (canada)
2.5 corporate name policy (canada)
 
1 1 Business Registration Reforms (W Bank) 2
1 1 Business Registration Reforms (W Bank) 21 1 Business Registration Reforms (W Bank) 2
1 1 Business Registration Reforms (W Bank) 2
 
5.6 it stream moderator (mauritius)
5.6 it stream moderator (mauritius)5.6 it stream moderator (mauritius)
5.6 it stream moderator (mauritius)
 
5.1 moving towards excellence (cook islands)
5.1 moving towards excellence (cook islands)5.1 moving towards excellence (cook islands)
5.1 moving towards excellence (cook islands)
 
4.2 new zealand case study
4.2 new zealand case study4.2 new zealand case study
4.2 new zealand case study
 
5.4 it security audit (mauritius)
5.4  it security audit (mauritius)5.4  it security audit (mauritius)
5.4 it security audit (mauritius)
 

Similar to 5.5 incorporating security in it solutions (mauritius)

Similar to 5.5 incorporating security in it solutions (mauritius) (20)

Secure Mobility from GGR Communications
Secure Mobility from GGR CommunicationsSecure Mobility from GGR Communications
Secure Mobility from GGR Communications
 
MARS User Login Logout MIS for Cisco Call Manager
MARS User Login Logout MIS for Cisco Call ManagerMARS User Login Logout MIS for Cisco Call Manager
MARS User Login Logout MIS for Cisco Call Manager
 
Security As A Service
Security As A ServiceSecurity As A Service
Security As A Service
 
Web based Peripheral trouble shooting management system
Web based Peripheral trouble shooting management systemWeb based Peripheral trouble shooting management system
Web based Peripheral trouble shooting management system
 
E swis
E swisE swis
E swis
 
ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and StandardsICAB - ITA Chapter 5 class 7-8 - Controls and Standards
ICAB - ITA Chapter 5 class 7-8 - Controls and Standards
 
Cybercom Enhanced Security Platform
Cybercom Enhanced Security PlatformCybercom Enhanced Security Platform
Cybercom Enhanced Security Platform
 
The Information Office
The Information OfficeThe Information Office
The Information Office
 
A Complete Software Engineer With Hardware / Networking Skill's
A Complete Software Engineer With Hardware / Networking Skill'sA Complete Software Engineer With Hardware / Networking Skill's
A Complete Software Engineer With Hardware / Networking Skill's
 
It security
It securityIt security
It security
 
Co p
Co pCo p
Co p
 
VEHICLE MANAGEMENT SYSTEM
VEHICLE MANAGEMENT SYSTEMVEHICLE MANAGEMENT SYSTEM
VEHICLE MANAGEMENT SYSTEM
 
SphereShield for Skype for Business - Compliance and Security
SphereShield for Skype for Business - Compliance and SecuritySphereShield for Skype for Business - Compliance and Security
SphereShield for Skype for Business - Compliance and Security
 
Ikon Managed Services
Ikon Managed ServicesIkon Managed Services
Ikon Managed Services
 
Ikon Managed Services
Ikon Managed ServicesIkon Managed Services
Ikon Managed Services
 
Co p
Co pCo p
Co p
 
VBOT
VBOTVBOT
VBOT
 
Bitrix Software Security
Bitrix Software SecurityBitrix Software Security
Bitrix Software Security
 
eFACiLiTY Helpdesk and Knowledge Base System
eFACiLiTY Helpdesk and Knowledge Base SystemeFACiLiTY Helpdesk and Knowledge Base System
eFACiLiTY Helpdesk and Knowledge Base System
 
IDSA at Denver IAM Meetup
IDSA at Denver IAM MeetupIDSA at Denver IAM Meetup
IDSA at Denver IAM Meetup
 

More from Corporate Registers Forum

More from Corporate Registers Forum (20)

South Africa - Digital AFS Reporting via xBRL
South Africa - Digital AFS Reporting via xBRLSouth Africa - Digital AFS Reporting via xBRL
South Africa - Digital AFS Reporting via xBRL
 
United Kingdom - Companies House Response to the Covid-19 Pandemic
United Kingdom - Companies House Response to the Covid-19 PandemicUnited Kingdom - Companies House Response to the Covid-19 Pandemic
United Kingdom - Companies House Response to the Covid-19 Pandemic
 
Slovenia - AJPES Digitisation a more transparent non possessory lien rights r...
Slovenia - AJPES Digitisation a more transparent non possessory lien rights r...Slovenia - AJPES Digitisation a more transparent non possessory lien rights r...
Slovenia - AJPES Digitisation a more transparent non possessory lien rights r...
 
Singapore - Seamless Filing Project
Singapore - Seamless Filing ProjectSingapore - Seamless Filing Project
Singapore - Seamless Filing Project
 
Azerbaijan - State Tax Service State Registration with Single Procedure
Azerbaijan - State Tax Service State Registration with Single ProcedureAzerbaijan - State Tax Service State Registration with Single Procedure
Azerbaijan - State Tax Service State Registration with Single Procedure
 
North Macedonia - Joint Platform for Starting a Business
North Macedonia  -  Joint Platform for Starting a BusinessNorth Macedonia  -  Joint Platform for Starting a Business
North Macedonia - Joint Platform for Starting a Business
 
Ultimate Beneficial Ownership Register - Belgium
Ultimate Beneficial Ownership Register - BelgiumUltimate Beneficial Ownership Register - Belgium
Ultimate Beneficial Ownership Register - Belgium
 
CRF 2019 Work Session 4 intro and conclusions
CRF 2019 Work Session 4  intro and conclusionsCRF 2019 Work Session 4  intro and conclusions
CRF 2019 Work Session 4 intro and conclusions
 
Ws6 panel challenges in modern registry management
Ws6 panel   challenges in modern registry managementWs6 panel   challenges in modern registry management
Ws6 panel challenges in modern registry management
 
Business Registration Service of Kenya
Business Registration Service of KenyaBusiness Registration Service of Kenya
Business Registration Service of Kenya
 
Introduction to EBRA Conference June 2019
Introduction to EBRA Conference June 2019Introduction to EBRA Conference June 2019
Introduction to EBRA Conference June 2019
 
Commercial Registers Economic & Digital Infrastructure
Commercial Registers  Economic & Digital InfrastructureCommercial Registers  Economic & Digital Infrastructure
Commercial Registers Economic & Digital Infrastructure
 
New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.
 
Singapore. ACRA's Data Services Journey.
Singapore.  ACRA's Data Services Journey.Singapore.  ACRA's Data Services Journey.
Singapore. ACRA's Data Services Journey.
 
Data and Users. The Experience of the IBFC in Labuan.
Data and Users.  The Experience of the IBFC in Labuan.Data and Users.  The Experience of the IBFC in Labuan.
Data and Users. The Experience of the IBFC in Labuan.
 
Data Usage from Business Registries
Data Usage from Business RegistriesData Usage from Business Registries
Data Usage from Business Registries
 
Supporting a new iXBRL mandate (CIPC)
Supporting a new iXBRL mandate (CIPC)Supporting a new iXBRL mandate (CIPC)
Supporting a new iXBRL mandate (CIPC)
 
South Africa - CIPC XBRL Project Journey and Update
South Africa - CIPC XBRL Project Journey and UpdateSouth Africa - CIPC XBRL Project Journey and Update
South Africa - CIPC XBRL Project Journey and Update
 
Business Registers - A European Perspective
Business Registers - A European PerspectiveBusiness Registers - A European Perspective
Business Registers - A European Perspective
 
Challenges in Modern Registry Management - US persceptive.
Challenges in Modern Registry Management - US persceptive. Challenges in Modern Registry Management - US persceptive.
Challenges in Modern Registry Management - US persceptive.
 

Recently uploaded

Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
allensay1
 
Jual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan Cytotec
Jual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan CytotecJual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan Cytotec
Jual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan Cytotec
ZurliaSoop
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
daisycvs
 

Recently uploaded (20)

Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGBerhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
 
Pre Engineered Building Manufacturers Hyderabad.pptx
Pre Engineered  Building Manufacturers Hyderabad.pptxPre Engineered  Building Manufacturers Hyderabad.pptx
Pre Engineered Building Manufacturers Hyderabad.pptx
 
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGBerhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
 
KALYANI 💋 Call Girl 9827461493 Call Girls in Escort service book now
KALYANI 💋 Call Girl 9827461493 Call Girls in  Escort service book nowKALYANI 💋 Call Girl 9827461493 Call Girls in  Escort service book now
KALYANI 💋 Call Girl 9827461493 Call Girls in Escort service book now
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
GUWAHATI 💋 Call Girl 9827461493 Call Girls in Escort service book now
GUWAHATI 💋 Call Girl 9827461493 Call Girls in  Escort service book nowGUWAHATI 💋 Call Girl 9827461493 Call Girls in  Escort service book now
GUWAHATI 💋 Call Girl 9827461493 Call Girls in Escort service book now
 
Jual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan Cytotec
Jual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan CytotecJual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan Cytotec
Jual Obat Aborsi ( Asli No.1 ) 085657271886 Obat Penggugur Kandungan Cytotec
 
Puri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDING
Puri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDINGPuri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDING
Puri CALL GIRL ❤️8084732287❤️ CALL GIRLS IN ESCORT SERVICE WE ARW PROVIDING
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...
Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...
Bangalore Call Girl Just Call♥️ 8084732287 ♥️Top Class Call Girl Service Avai...
 
KOTA 💋 Call Girl 9827461493 Call Girls in Escort service book now
KOTA 💋 Call Girl 9827461493 Call Girls in  Escort service book nowKOTA 💋 Call Girl 9827461493 Call Girls in  Escort service book now
KOTA 💋 Call Girl 9827461493 Call Girls in Escort service book now
 
PARK STREET 💋 Call Girl 9827461493 Call Girls in Escort service book now
PARK STREET 💋 Call Girl 9827461493 Call Girls in  Escort service book nowPARK STREET 💋 Call Girl 9827461493 Call Girls in  Escort service book now
PARK STREET 💋 Call Girl 9827461493 Call Girls in Escort service book now
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service AvailableBerhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
Berhampur Call Girl Just Call 8084732287 Top Class Call Girl Service Available
 
PHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation FinalPHX May 2024 Corporate Presentation Final
PHX May 2024 Corporate Presentation Final
 
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service AvailableNashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
 

5.5 incorporating security in it solutions (mauritius)

  • 1. SECURITY Incorporating Security in IT Solutions for Corporate Registers
  • 2. SECURITY COMPONENTS Physical Security Server and System Software Security Database Security and Audit Trail Authentication to the Application Application Level Security Online Applications Security
  • 3. PHYSICAL SECURITY OF IT Environmental design Air Conditioning, Dual UPS and Standby Generators Electronic and procedural access control Biometric Access control for controlling user access points Datacenter access limited to IT administrators Intrusion detection and Video monitoring Security alarms and CCTV for incident notification and verification
  • 4. SECURITY COMPONENTS High Available Cluster System For Database and Application Server - protection against a single server failure Disaster Recovery System- protection against disaster at Main site Firewall and Intrusion Prevention System Antivirus/ Antispyware server Data Protection System- Automated backup of servers and databases
  • 5. Up to date with latest Security patches and fixes Logging of access to all server services Use of encryption for network communication Maintain a proper system backup policy SERVERS AND OS SECURITY
  • 6. USER AND PASSWORD MANAGEMENT Restriction of User ID to an agreed number of alphanumeric characters (Include special characters in Password @,#) Maintain password Complexity No shared ID issued to multiple users Disabling of Inactive account accounts after an agreed time period Locking of users of a successive given attempts of failed login
  • 7. USER AND PASSWORD MANAGEMENT cont.. Initial Password allocated to user will be one time. User forced to change his password on first log in Users forced to change their password after an agreed time period from the last password change date. User sessions will time-out after an agreed period of inactivity
  • 8. APPLICATION - LEVEL Access to user on system will be depending on their access rights (Filing officer accessing filing system, Cashier accessing cash collection system, Companies officer accessing Companies Administration Module, Management of ROC accessing all systems ) Access rights to record application Access rights to approve application Access rights to insert, update and delete
  • 9. APPLICATION – AUDIT TRAIL Any record created in the database will have the user stored in the database and the date it has been created. The user who has last updated the record will be stored in the database. Any table in the database can be audited and any updates made can be logged. Tracking of Status on Application (Recorded, In Progress, Rejected or Approved). Tracking of Status of Companies (Incorporated, Amalgamate, Dissolve, Wind-Up)
  • 10. ELECTRONIC SUBMISSIONS Information recorded in a temporary database in the DMZ server. ROC Staff validate the data before sending it in the live database. Each company will have a password to access their account. They can use it to submit their applications online.