Empatixlogo

Security

All software made in the eMPATIX Framework has the following security modes.

Role security
Every user can have zero or more roles attached.

The roles control

  • Which templates you can view
  • Which actions you can run (clicking buttons that changes data)
  • Which tables you can not see, which you can see, which you can edit.
Fallback security
Independent from the role security is the fallback security model seeks to minimize damage if role security is compromised.

eMPATIX is spitted into three interfaces
  1. Internet. Everybody has access by default. Public assess.
  2. Extranet. Requires login. User can only see information related to the person logged in. eMPATIX checks the context for information belonging to either PersonID or CompanyID of the logged in person.
  3. Intranet. Requires login. A person is only allowed to log in to the intranet if found in a relationship with the company defined as owning the software according to the concern model. That means if a customer try’s to log in if given role access, they will still be denied login unless separately admitted in the template control mechanisms that is used to secure Intranet access.
Template security
  • Deny first policy on everything, if security is not specified, you do not have access.
  • Templates that are not entered into the security system is not accessible by default.

All activity in eMPATIX are logged and these logs provide detailed information on each transaction and can be sampled for irregularities.

Please read more about: Data Breach


Facts about Security

EXTERNAL THREATS Modern ERP systems are designed to facilitate the sharing of information with selected trading partners with systems such as supply chain management. The ERP implementations must therefore allow external users to access the company's core systems so the traditional approach of blocking external access is no longer appropriate.

INTERNAL THREATS Modern ERP systems are designed to integrate the various business functions - and Product clerk may have a legitimate reason to access the Inventory Management module in the ERP system etc!

In a study completed by the Ponemon Institute on data breach detection and management Hacking seems to be only 1% of the cases.

The two most important causes seems to be negligent insiders (75%) and outsourcing of data (42%).

Please contact PT Empatix at Phone +62-21-3141241 or E-mail post@empatix.com