org.manager Data Security
Find out how Navigo & org.manager keep your data protected
- Data Segregation
- Secure Single Sign On
- Penetration Tests
- Data Encryption
- Encryption Keys
- MFA / Two Factor Authentication
- Anti-virus
- Updates
- Logging
- Monitoring
- Role Based Security
- Frequently Asked Questions
Data Segregation
Data is stored in individual containers to guarantee full isolation from other environments. Each tenant is separated from other tenants by operating its own containers (process isolation).
This ensures that each customer has its own application instance, and that data processing is strictly separated from one another.
Secure Single Sign On
org.manager is SAML-2 & OKTA compliant via the org.manager Authentication Agent module.
Secured Single Sign On authentication is typically configured between your Microsoft Entra ID and the org.manager application.
Different authentication methods, which are supported by the Microsoft IIS web server (e.g. SAP Logon Ticket), can be used as an alternative to Windows authentication.
Shibboleth SSO is supported
Authorisation is controlled via configurable rules which are defined by org.converter. As a result, it is possible to display to each user only those structures below their particular organisation, for example.
Penetration Tests
Penetration tests are performed and audited on a regular basis with the latest test results available on request. Infrastructure penetration testing is conducted by Microsoft.
Customers can test their own tenant on application.
Data Encryption
org.manager utilises end-to-end data encryption. All data is encrypted in-transit and at rest.
Azure's recommended cipher set is used for SSL handshake between the client and server. All SSL Certificates are SHA-256 with RSA Encryption.
When the organisation chart is retrieved by the user, the respective HTML/Javascript/image/PDF file is generated and delivered to the browser.
All communication between the browser and the server uses HTTPS. Any request received over HTTP is redirected to HTTPS.
Encryption at Rest
Each client stores data in a dedicated Azure Storage account. This account is transparently encrypted and decrypted using 256-bit AES encryption, one of the strongest block ciphers available, and is FIPS 140-2 compliant. Azure Storage encryption is comparable to BitLocker encryption in Windows. The data in a storage account is encrypted with keys managed by Microsoft.
See: Azure Data Encryption-at-Rest - Azure Security
Encryption in Transit
HTTPS
Access to the tenant application is protected by the Azure Application Gateway with integrated Web Application Firewall. The external IP of the Azure Application Gateway is protected by the Azure DDoS Protection Service. Encryption is performed using SSL with TLS 1.2 (best practice cipher suites) and TLS 1.3 (depending on the client browser). This can be verified by accessing your own tenant. The protocol actually used depends on the browser configuration and is therefore the responsibility of the customer.
SFTP
SFTP file uploads and outgoing data access within the tenant application are protected by the Azure firewall with integrated intrusion detection and prevention system (IDPS). The external IP of the Azure Application Gateway is protected by the Azure DDoS Protection Service.
Encryption Keys
Azure Key Vault is used to manage encryption keys.
MFA / Two Factor Authentication
Two factor authentication is used by Navigo in all applications including Azure.
Anti-virus
Anti-Virus software is run and maintained on a daily basis.
Microsoft Antimalware for Azure downloads updated antimalware definitions and engine updates multiple times per day and applies them automatically to the virtual machines running org.manager. See: Microsoft Antimalware for Azure Cloud Services and Virtual Machines
Updates
The hardware components running org.manager are monitored by Navigo personnel on a regular basis and updated regularly with the latest patches and updates.
Logging
Security logs are transferred and stored within Azure Logs Analytics Workspace. They are protected against manual modification by the administrator.
All login attempts are redirected to the customer's IdP and only valid attempts are processed by the application. Validation is performed within the authentication protocols eg SAML 2 or OAuth. Authentication is handled by customer’s IdP and thereby the access logs are in the responsibility of the customer.
Monitoring
Navigo use Azure Monitor alarms to monitor access and configuration changes to the environments. Logs persist for 90 days.
Azure Monitor is used to monitor all system and/or user events. This includes successful and attempted logins to Azure via the Azure Console or API. Authentication events are forwarded to Monitor which will in turn trigger an alarm in Azure and send a notification to our Slack Security Channels.
Audit Trail logs against each record, listing every activity against that record and by who. There is also a System Log which logs configuration changes made and by who.
Azure Servers also utilise Azure Network Watcher. Network Watcher monitors the open ports and categorise access / attempted access.
Role Based Security
Frequently Asked Questions
|
Questions |
Answers |
|---|---|
|
Does org.manager support role based user access and restrict access to protect employee data? |
Yes. See Role Based Security
|
|
What are your Data Portability and Data Lifecycle policies? |
org.manager accepts a daily feed of data from a customer’s payroll / HRIS system. On termination this feed ceases and the existing Customer data is permanently deleted after 60 days from the date of the expiry or termination of your agreement. Hardware decommissioning completed by Microsoft Azure. |
|
What are your IT Change Management policies? |
Navigo maintains a structured release process and release notes. For Cloud Hosted org.manager customers, Windows patches are applied once a month after 9pm AEST and org.manager version updates are issued every 4 months, giving three releases per year. Subscribe to our Status Page for further details regarding dates and times for patches, maintenance, feature upgrades and any rare unplanned outages. |
|
Data Interchange Formats |
The following formats are supported by default as a data source for org.manager:
|
|
API Interfaces |
Not available. org.manager consumes data from leading data sources (HRIS, or Payroll) via CSV, SQL, LDAP Oracle or SAP formats. |
|
Mobile Access |
IOS (v9+) and Android (v6+) via mobile responsive design and iPad App. The content / design displayed on mobile devices can be configured without any coding involved and supports all platforms. |
|
WCAG Standards |
Navigo & Ingentis are committed to WCAG compliance and associated product updates. org.manger comes with a speech recognition feature which enables the navigation and the use of features such as print, search or export by speech command. The user interface and the content / design of the org charts can be configured without any coding involved. This ensures an output which is aligned to the latest standards. org.manager does not support ‘text to speech’ as a specific function. For further information see: |
|
SAP Interface |
org.manager includes a powerful SAP function module which can access PA, PD and OM including custom info types. The function module can be customised if required. org.manager connects to the functional module via web service or the function module creates a file extract. org.manager is an object and relation independent solution which can display any evaluation path. V2 of the OM Interface (OMI) is designed as a data source for SAP HR/HCM (OM, PA, PD, PY TM) information for org.manager. Data are acquired in different ways:
There are two different methods of data acquisition:
|
|
Are Police Checks completed on all employees? |
Yes. Mandatory for all Navigo employees. |
|
Is there an ongoing security awareness and training program for all workers? |
Navigo maintains security awareness training for all staff. This includes security awareness training at onboarding and annual updates for all staff. |
|
Is antivirus software current and active on all Windows desktop and Windows server systems? |
Yes |
|
Are all email attachments scanned for malicious code? |
Yes |
|
Do all laptops used have an active firewall? |
Yes |
|
Is there a hardening standard for servers, workstations and networking equipment that may store, process or transmit our organisation's data? |
Yes. Cloud Hosted
Services
On Premise
Services
|
|
Does the Change control process include applying security related fixes and service packs? |
Yes |
|
Is a PKI solution utilising Hardware Security Module being utilised? |
Yes. Navigo hosting uses Azure Microsoft Azure Stack Readiness Checker See: Azure Stack Hub public key infrastructure certificate requirements - Azure Stack Hub |
|
Will access to website, administrative management interfaces be locked down to authorised IP ranges and specific ports? |
Yes. Restrictions on the IP addresses that can connect to the administration ports of networking equipment and servers from external networks are implemented. |
|
Do you allow for host-based intrusion detection and prevention service (IDS/IDP) agents to be installed within the virtual machines? |
No. Host-based agents are not installed. Threat monitoring is provided at the network layer by Azure Firewall with an integrated intrusion detection and prevention system (IDPS), and at the application layer by the Web Application Firewall (WAF), part of the application gateway in the current architecture, runs incoming traffic inspections and checks for common threats based on the Open Web Application Security Project (OWASP).
|