

SECURITY IS ALWAYS THE NUMBER ONE PRIORITY AT ARBES
ARBES OBS Security
The
architecture of the ARBES
OBS system and the related ARBES information systems and the
expertise in
the creation of banking applications is based on the following
principles and
technologies:
Standards,
Algorithms
- ARBES OBS has been built from the outset with Service
Oriented Architecture
in mind. The functionality of all modules
is securely exposed to third-party software.
- Secure
Socket Layer for all Internet-based
connections - SSL3
(128/40 bits)
- Triple
DES (168 bits),
IDEA (128 bits), SHA-1,
MD5,
RSA
(1024 bits) for cryptographic operations
Database
- Proven ORACLE database technology
- As
an ORACLE
Certified Partner,
ARBES has access to the latest security developments and database
products and our qualified specialists are continuously trained.
- Solid use of database security support
- Different
levels of stored procedures for different DB tasks
- No
direct manipulation with raw data
Client
Authentication
- Hardware tokens
- Permanent
passwords
- One-time passwords
- Public/private
keys
- Smart cards
- iKeys
- Registered GSM phones
Security in
Network
Topology
- The central
access right control system allows
for the
information system administrator to assign user access rights depending
on the type of user.
- It is possible to activate
the
four-eyes principle
for
processes and records to be approved by multiple users in selected,
operationally strategic ARBES applications.
- Disaster recovery
–
ARBES offers consultation and
methodology design for disaster situation solutions for which it is
necessary to restore system
activity, restore data or activate a backup work location.
- Separate
office, delivery channel and core system networks
- Extensive
use of firewalls, proxy servers, packet filters,
etc.
Monitoring
- Continuous check of all servers and
services
- Notification of the appropriate
administrators about system
problems or misbehavior
- Execution of fail-over
procedures in the case of disaster
- Monitoring
tools can be plugged into other
third-party software/tools