NGA.NET e-recruitment Software and Systems Security
NGA.NET recognise that information, data security is a critical component
in the selection of a solutions partner. As such NGA.NET utilizes a 'defence
in depth' approach to safeguarding client and candidate data. NGA.NET
information data security is unrivalled in our market. The NGA.NET approach
is underpinned by the following mechanisms:
- Production systems are hosted in locked equipment racks at a secure
third party data centre, manned 24/7 with surveillance cameras and strict
verification policies. The data centre boosts high levels of redundancy
with twin ups/generators, multiple high speed internet connections,
failover air conditioning and the latest Halon fire suppression systems.
- Externally managed redundant firewall systems allowing only web traffic
(port 80/443) to certain application servers.
- Host based Intruder Detection systems configured to alter if changes
are made to key operating system or application files.
- Prevention of access to underlying infrastructure from application
regardless of access permission settings.
- AES 128bit encryption of all backups including those sent offsite
with NGA.NET’s offsite data storage provider.
- Application password controls including password expiry, invalid attempt
lockout, password construction requirements etc.
- SSL encryption between the NGA.NET application server and the user’s
browser
- Fixed (limited) functional access to application from candidate portal
and discrete user configurable access to the application from the client
portal.
- Inactivity Session timeouts
- Each client’s data is stored in a unique database to ensure there
is no possibility of cross contamination due to an external event.
- Audit trail of user actions within the application.