Architecture Security
oTMS strictly adheres to various international standards such as ISO27001 since 2017, passed strict security audits for Fortune 500 and local SOEs and implements information security governance and control of the SaaS system and data security management.


oTMS Application Security Overview
Infrastructure:
– Standardized Server Configuration
– Antivirus & Vulnerability scan
Network:
– Web Application Firewall
– Network Segregation

Application:
– Multi-factor Authentication
– Role Based Authorization
– Strong User Management
Data:
– TLS Transfer
– Sensitive Data Encryption – 256 AES
– Daily Data Backup
– Business Continuity Plan

Third Party Security
- The critical 3rd party vendor of oTMS is the AWS Cloud where all SaaS services are hosted.
- AWS Cloud must ensure a securely managed and operated infrastructure, physical devices.
- oTMS buy paid WAF(Web Application Firewall) from AWS Cloud to ensure the protection and manage all attacks.

