![]() ![]() |
||||||
|
|
||||||
|
||||||
Telecom Expense Management TechnologyWhy it Matters | Functionality | Delivery Model | Infrastructure | ArchitectureBillPort® Application ArchitectureApplication SecurityInvoice Insight implements BillPort® 's security in multiple layers including network, physical, application, and database. Our host server is located behind a securely configured firewall and connected to the Internet via a high-speed line with backups. Invoice Insight has been certified by Entrust and issued a digital certificate to support Secure Socket Layer (SSL) communications between the user's Web browser and our Web server. In addition, we generate session-specific Globally Unique User IDs (GUIDs) that timeout after a period of inactivity to prevent any unauthorized access. Security Policies and Procedures Invoice Insight's policy is to prohibit the dispersal of customer data to any third party, for any reason, without express written permission. We are dedicated to ensuring the confidentiality, integrity, and availability of all system information. We employ combined mangament, operational, and technical security controls to meet our security goals. People and Culture Invoice Insight is foremost a technology company. Our employees realize that the core of our business is the provision of information technology to some of the world's largest organizations. We strive always to ensure that our customers' data are protected against all threats, current and emerging. We take security very seriously and violation of company security policies is grounds for dismissal. Logical Security and User Groups BillPort® enforces logical access controls, utilizing the concepts of least privilege and separation of duties. The system establishes profiles for each user ID, granting and restricting access such that only those system functions necessary to perform authorized tasks are permitted. More technically, these profiles are implemented by associating users with groups. Groups receive independent read, update, insert, and delete privileges. Viruses Symantec (Norton) anti-virus software runs on all Invoice Insight computer hardware. Anti-virus updates and the security patches for operating systems, Web servers, and network devices are automatically downloaded and applied on a daily basis. In our history, no Invoice Insight server has ever been compromised due to a virus attack. Regulatory Compliance Because some Invoice Insight clients are U.S. government agencies, including the U.S. Army and U.S. Coast Guard, Invoice Insight complies with stringent regulatory requirements, including those of the Office of Management and Budget (OMB) Circular A-130 and the National Institute of Standards and Technologies (NIST) 800 Series. Monitoring Invoice Insight administrators utilize firewall logs, operating system-level logs, and database logs to monitor system activity. ISS Black Ice intrusion detection software (IDS) also protect Invoice Insight servers. Tools Network security is implemented using Secure Socket Layer (SSL) with 1024-bit RSA key encryption and two securely configured firewalls, in series. Other data encryption techniques include the md5RSA signature algorithm and the sha1thumbprint algorithm. Backup and Data Recovery The BillPort® server platform is centrally managed and monitored to tune performance, maximize uptime, and ensure that the latest operating system and database upgrades are applied. Our platform uses redundant array of independent disks (RAID) technology and our IT support team performs daily backups of all system data. We have developed and frequently tested a system-wide backup and recovery plan for the entire server platform using the popular Grandfather-Father-Son (GFS) tape rotation strategy. We also have in place a system fail-over process to ensure continuity of operations even in the event of total site failure. Archives of client data can be generated and sent to the client on a negotiated schedule. |
|
Invoice Insight is a leading provider of automated telecom cost management and telecom expense management solutions. Through BillPort™ technology and on-demand services, we help organizations with their telecom invoice management, telecom inventory management, telecom service ordering, telecom audit and contract management, telecom sourcing, telecom procurement, telecom MAC/D, and other telecommunication management needs. We help enterprises achieve telecommunication cost reduction using BillPort™ TEM technology or our telecom consulting and telecommunication audit automation services. We also provide e-gov (e-government or electronic government) solutions to Federal agencies, including government invoice processing, Federal expense management solutions, government telecom management software and other Federal, state and local government expense management and invoice management solutions. Terms and Definitions. Click to download the Free Macromedia Flash Player 7 Invoice Insight Corporate: 703-334-0070 © 2003, Invoice Insight, LLC. All Rights Reserved |