Compliance and Business Continuity Management
Business Continuity Management (BCM) is an ongoing process of risk assessment and management with the purpose of ensuring that a business can continue if risks materialise. These risks could be from the external environment (over which a company has no control, such as a Denial of Service attack) or from within an organisation, such as deliberate or accidental restriction of access availability.
iPEP technology enables access to critical applications by important personnel at all times and is therefore a valuable component of any business compliance strategy. Information must be made available to all relevant departments when required, irrespective of current conditions of performance and load.
iPEP provides the capability to prioritise the users of a web based application and to also prioritise specific applications. Key personnel accessing their managed applications can be given priority access over and above any other person accessing the applications, guaranteeing timely application access and ensuring that service delivery is within limits specified in any Service Level agreement (SLA).
When authorised personnel need access to web based applications, they simply identify themselves to the web application server, which then allows iPEP to identify them as a high priority user. When they subsequently access the application, they are given priority access over and above any other lower priority visitor to the application. In extreme circumstances, where the system is already at limits, the critical user session can replace an existing, lower priority visitor, thus guaranteeing access at all times for critical visitors to critical applications. It is important to note that this is achieved in real time, without any changes to the web facing application (nb.to provide tight integration with the Application Server may require some changes).
To ensure the web application continues to responds to requests, especially during time of elevated activity, iPEP is able to impose visitor limits at all levels of the application. This stops the application become overloaded, slowing down and eventually failing to respond.
Another important aspect of compliance is providing real time views of current application usage, including, by whom and for how long. These application flows can be reviewed and monitored in real time to ensure application access. This provides an early warning system for application failure or access problems, for example, if application usage drops sharply from normal then this could indicate a problem with application availability. Additionally, if response times increase abnormally or if the number of visitors suddenly increases abnormally then this may indicate a security breach such as a DoS attack.
A further function of iPEP, when enabled, allows personnel access to the web based application irrespective of current network and system constraints. This can be viewed as a backdoor entrance to the system, providing guaranteed access to web based applications in time of real emergencies.
For critical web facing business applications adhering to availability compliance rules and organisational BCM policies, NetPrecept's iPEP Technology is an essential component delivering:
- Application availability
- Guaranteed application response during crisis
- Priority application access
