Find the information you need on security, compliance and privacy
Security governance and compliance
Shared responsibility model
Privacy
Report a security incident
Security governance and compliance
Shared responsibility model
Security and compliance is a shared responsibility between Monitor and the customer. This shared model can help relieve the customer’s operational burden, since Monitor operates, manages and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates. The customer assumes responsibility and management of the customer domain, and Monitor of the Monitor domain, as shown below:
Customer
Responsibility for security operation of customer domain
- Monitor G5 identity and access management
- Monitor G5 customer data
- Security operation customer domain
- Network traffic protection (VPN customer side)
Monitor
Responsibility for security operation of Monitor domain
-
Network traffic protection (VPN Monitor side)
-
Monitor G5 maintaince (patch/update/backup)
-
Security operation Monitor domain
-
Operating system
- Compute | Storage | Database | Networking
- Data center
Frequently asked questions
Here we've compiled some of the most commonly asked questions in this area.
Is there a backup plan offered as standard with Monitor Cloud?
Monitor Cloud creates backup copies of the customer’s data on a daily basis. The customer and Monitor Cloud shall agree regarding backup copies, and the frequency with which they take place. Up to fourteen (14) backup copies and backup performed up to four (4) times a day are included in the Cloud Service Fee, although the Parties may agree a higher rate for a specific fee.
Does Monitor ERP support MFA (Multi-Factor Authentication)?
Yes: MFA requires the user to identify with an additional authentication factor – here there is a one-time code generated by an authentication app, in addition to the user password. This extra protection makes it harder for unauthorized individuals/attackers to gain access to the user’s user account. This helps protect confidential or sensitive information and prevent unauthorized access.
Does Monitor Cloud offer patch management?
The customer and Monitor Cloud shall agree upon how often, at what time of day, and how long following a new release of Monitor ERP the installation in Monitor Cloud will be carried out. Monitor Cloud ensures that only supported versions are used, and updates are carried out as soon as critical vulnerabilities are identified. Monitor Cloud monitors for security updates on all products in the Cloud environment.
Does Monitor Cloud have a physical security policy?
Yes, physical security at our office includes access control based on personal access cards, 24/7 CCTV monitoring and alarm systems.
The Monitor Cloud data center has high demands regarding physical protection and redundancy. This includes:
- Fully redundant cooling systems with different cooling sources.
- Double high voltage electricity transmission and distribution systems.
- Backup power with dual UPSs on separate groups.
- Diesel power as backup power for at least 5 days.
I have more questions on Security, Compliance, Privacy & Resiliency, who do I contact?
For more information relating to Monitor Cloud, we encourage you to reach out and get in touch with us here, and we'll be get back to you as soon as we can.