<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy Archives - Inception CRM</title>
	<atom:link href="https://inceptioncrm.com/category/security-and-privacy/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>A Pharma CRM for Life Sciences Teams</description>
	<lastBuildDate>Thu, 03 Nov 2022 10:51:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://inceptioncrm.com/wp-content/uploads/2021/03/inception_logo_00.svg</url>
	<title>Security and Privacy Archives - Inception CRM</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Our IT Risk Management Methodology</title>
		<link>https://inceptioncrm.com/our-it-risk-management-methodology/</link>
		
		<dc:creator><![CDATA[Marketing Team]]></dc:creator>
		<pubDate>Tue, 10 Aug 2021 14:54:22 +0000</pubDate>
				<category><![CDATA[IT Risk Management]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Security and Privacy]]></category>
		<category><![CDATA[IT Risk Management Methodology]]></category>
		<category><![CDATA[Residual Risk]]></category>
		<category><![CDATA[Risk Analysis]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk Benefit Analysis]]></category>
		<category><![CDATA[Risk Control]]></category>
		<category><![CDATA[Risk Management]]></category>
		<guid isPermaLink="false">https://inceptioncrm.com/?p=3983</guid>

					<description><![CDATA[<p>We perform Risk Management for all software applications that we use, whether developed by us or sourced from 3rd-party vendors.</p>
<p>The post <a href="https://inceptioncrm.com/our-it-risk-management-methodology/">Our IT Risk Management Methodology</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We perform Risk Management for all software applications that we use, whether developed by us or sourced from 3rd-party vendors. </p>



<p class="wp-block-paragraph">The process for managing risk includes:</p>



<ul class="wp-block-list"><li>risk analysis</li><li>risk assessment</li><li>risk control</li><li>manufacturing and post-release information</li></ul>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading" id="h-risk-analysis">Risk Analysis</h3>



<p class="wp-block-paragraph">The first step in managing risk is identifying it &#8212; and understanding it. </p>



<p class="wp-block-paragraph">During risk analysis, we write down all of the known or possible defects (&#8220;hazards&#8221;) of a given product, and then analyze the risks of each. </p>



<p class="wp-block-paragraph">Our goal, in doing this, is to identify the seriousness of each risk. To that end, we classify each risk in terms of its severity, likelihood of occurrence, and probability of detection, following this scheme:</p>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list"><li><strong>Severity</strong> (Critical, Major, Minor, Trivial)</li><li><strong>Likelihood of Occurrence</strong> (High, Low, Very Low, Occurrence Not Anticipated)</li><li><strong>Probability of Detection</strong> (Practically Impossible to Detect, Random, High, Almost Certain / Impossible to Miss)</li></ul>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">After that, we assess the risk to determine what, if any, mitigation actions are needed to reduce or eliminate it, along with their priority.</p>



<h3 class="wp-block-heading"><br><strong>Risk Assessment</strong></h3>



<p class="wp-block-paragraph">A risk assessment has three possible outcomes:</p>



<ol class="wp-block-list"><li><strong>Accept the Risk</strong></li><li><strong>Reduce the Risk</strong></li><li><strong>Remove the Risk</strong></li></ol>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Our Risk Management Plan tells us how to respond based on the overall seriousness of the risk, as measured by the criteria mentioned previously. </p>



<p class="wp-block-paragraph">Generally, we accept risks only when we believe the severity of their impact will be low and/or we think their occurence is unlikely. We also consider how easily they can be detected and dealt with. </p>



<p class="wp-block-paragraph">In rare cases, when mitigation isn&#8217;t possible or easily achievable, we <meta charset="utf-8">eliminate the risk entirely by removing its source, whether it&#8217;s a component or feature within an application, or a process flow that introduces more problems than it solves. </p>



<p class="wp-block-paragraph">In most cases, however, we work to reduce risks by mitigating them. When risk reduction is selected, the risk is recorded as part of project and/or product risk documentation, along with any planned remediations. (Alternatively, if we decide to accept a given risk, we note that as well, along with the reasons for its acceptance.)</p>



<p class="wp-block-paragraph">Rick Control describes the process for dealing with risks that need to be reduced.<meta charset="utf-8"></p>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading"><strong>Risk Control</strong></h3>



<p class="wp-block-paragraph">Risk Control comprises four key areas:</p>



<p class="wp-block-paragraph"></p>



<ol class="wp-block-list"><li>Risk Reduction</li><li>Recommended Measures</li><li>Assessment of Residual Rick</li><li>Risk / Benefit Analysis</li></ol>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph"><strong>Risk Reduction</strong></p>



<p class="wp-block-paragraph">We take into account the following elements (listed in order of importance) when reducing a risk:</p>



<p class="wp-block-paragraph"></p>



<ul class="wp-block-list"><li>The product’s own reliability (in terms of information security, data privacy, data integrity and availability, etc.)</li><li>Protective measures that are part of the product or development process</li><li>Additional reliability or performance information</li></ul>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">Based on the above, we determine the mitigation measures we need to implement to reduce the risk and assign them to responsible staff members, along with a target implementation date. </p>



<p class="wp-block-paragraph"><strong>Recommended Measures</strong></p>



<p class="wp-block-paragraph">Once they&#8217;ve implemented the recommended measures, the team responsible for the product checks the results. In some cases, we might find there are still residual risks, even after the mitigation measures have been implemented. In such cases, we analyse the residual risks and assess them acceptability/unacceptability.</p>



<p class="wp-block-paragraph"><strong>Assessment of Residual Risk</strong></p>



<p class="wp-block-paragraph">We assess any residual risk that still exists against the same quantitative assessment criteria as the primary risk and document it accordingly. If the residual risk does not meet the required criteria, we implement additional risk control measures, then carry out risk-benefit analyses for any residual risk that still remains.</p>



<p class="wp-block-paragraph"><strong>Risk / Benefit</strong> <strong>Analysis</strong></p>



<p class="wp-block-paragraph">In cases where the residual risk is unacceptable (per our risk management plan) and further risk control is no longer feasible, we assess whether the benefits of the product exceed its risks. </p>



<p class="wp-block-paragraph">If they don&#8217;t, it means that the risk is unacceptable and we have to suspend the development and/or distribution of the product. But if the benefits of the product do exceed the residual risk, then we&#8217;re more likely to accept the risk.</p>



<p class="wp-block-paragraph"><strong>Other Created Hazards</strong></p>



<p class="wp-block-paragraph">Risk control measures are reviewed for their potential to cause other hazards. As a result of the application of risk control measures, new hazards may arise which need to be assessed by analogy as existing risks.</p>
<p>The post <a href="https://inceptioncrm.com/our-it-risk-management-methodology/">Our IT Risk Management Methodology</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Our Configuration Management Procedure</title>
		<link>https://inceptioncrm.com/our-configuration-management-procedure/</link>
		
		<dc:creator><![CDATA[Marketing Team]]></dc:creator>
		<pubDate>Mon, 09 Aug 2021 14:29:03 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Security and Privacy]]></category>
		<category><![CDATA[Application Configuration]]></category>
		<category><![CDATA[Application Enhancements]]></category>
		<category><![CDATA[Application Testing and Validation]]></category>
		<category><![CDATA[Change Management]]></category>
		<category><![CDATA[Configuration Management]]></category>
		<category><![CDATA[Configuration Management Procedure]]></category>
		<category><![CDATA[Configuration Manager]]></category>
		<category><![CDATA[Hardware Validation]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Software Lifecycle]]></category>
		<category><![CDATA[Software Validation]]></category>
		<category><![CDATA[Systems Validation]]></category>
		<guid isPermaLink="false">https://inceptioncrm.com/?p=3976</guid>

					<description><![CDATA[<p>D3S requires traceability of configuration for software products delivered to our customers, as well as for systems installed on our hardware.</p>
<p>The post <a href="https://inceptioncrm.com/our-configuration-management-procedure/">Our Configuration Management Procedure</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">D3S requires traceability of configuration for all software systems and related hardware. These include D3S software products delivered to customers, as well as installed systems on servers and other infrastructure components. </p>



<p class="wp-block-paragraph">In all cases, we require the following configuration elements to be fully described:</p>



<ul class="wp-block-list"><li>required configuration settings or parameters</li><li>reasons for each setting, with reference to controlling specifications</li><li>tools or methods use to set the required options</li><li>dependencies and impacts on other modules or systems</li><li>infrastructure items (e.g. OS, layer software)</li><li>security of settings</li></ul>



<p class="wp-block-paragraph"></p>



<p class="wp-block-paragraph">For infrastructure components, the basic rule for configuration is to apply custom configurations and not use default settings, especially those governing access and user authentication. For software products, configuration reflects customer needs, and changes are performed on the basis of customer demands.<br><br>We manage all changes to our software applications and their supporting environments through our ticketing and issue tracking system. We typically handle these changes as new features or change requests. Each ticket has an author, specification, approval clause (if necessary) and version number. Per our release policy, all requested changes are assigned to a new software version. </p>



<p class="wp-block-paragraph">When the scope of the version is final and we&#8217;ve implemented all included features, we prepare the version for the quality assurance (QA) process. If the version has an impact on documentation, the relevant documents are also updated. Each revision includes a version number, date, author and description of changes for traceability of changes.</p>



<p class="wp-block-paragraph"><a href="https://inceptioncrm.com/how-we-manage-versions/">Click here to learn more about how we manage software versions.</a></p>
<p>The post <a href="https://inceptioncrm.com/our-configuration-management-procedure/">Our Configuration Management Procedure</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Our Approach to Disaster Recovery</title>
		<link>https://inceptioncrm.com/our-approach-to-disaster-recovery/</link>
		
		<dc:creator><![CDATA[Marketing Team]]></dc:creator>
		<pubDate>Mon, 09 Aug 2021 14:01:51 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Security and Privacy]]></category>
		<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Continuity of Operations]]></category>
		<category><![CDATA[Data Center Operations]]></category>
		<category><![CDATA[Data Security]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Disaster Recovery Plan]]></category>
		<category><![CDATA[DRP]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<guid isPermaLink="false">https://inceptioncrm.com/?p=3970</guid>

					<description><![CDATA[<p>D3S maintains detailed plans for the recovery of our systems and infrastructure in the event of a disaster. </p>
<p>The post <a href="https://inceptioncrm.com/our-approach-to-disaster-recovery/">Our Approach to Disaster Recovery</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">D3S maintains detailed plans for the recovery of our systems and infrastructure in the event of a disaster. These plans inform our staff of the procedures they should follow to restore normal IT operations. </p>



<p class="wp-block-paragraph">Our DRP focuses, in particular, on our data center operations (DC Ops) and the critical infrastructure located within our primary data center, where critical services are located.</p>



<p class="wp-block-paragraph">The DRP provides a complete manual for our IT staff. It includes analyses of the various risks to individual parts of our computing systems and descriptions of their importance for business support, as well as the consequences of their outages for business processes in our company. </p>



<p class="wp-block-paragraph">More importantly, our DRP describes in detail the specific steps necessary to restore critical functions. SOPs include mandatory communication procedures before, during and after the restoration of the affected systems and the tests that need to be performed after the DRP activities have ceased.</p>



<h3 class="wp-block-heading" id="h-frequency-of-drp-testing">Frequency of DRP Testing</h3>



<p class="wp-block-paragraph">We test our disaster recovery plans with regular frequency, typically 1-2 times per year, with tests focused on both our primary and secondary data centers. In addition, we assess our ability to recover production data on a daily basis via automated monitoring of incremental backups of our production environments, which are copied daily to paired staging environments and then validated for records consistency and integrity.</p>



<p class="wp-block-paragraph"><strong>Primary DC DRP Tests:</strong> </p>



<p class="wp-block-paragraph">Following any major upgrade to our primary data center infrastructure, we perform controlled shutdowns of the entire infrastructure in order to mitigate any hardware or software issues detected during previous tests that cannot be performed in live operational environments. We also use these shutdowns to address known bottlenecks and improve network throughput and storage subsystem IO.</p>



<p class="wp-block-paragraph">During the controlled shutdowns, we test redundancy within the primary data center, making sure that systems will remain operational when one or more core infrastructure components are down. Following this, we test environment recovery according to the DRP, following the test steps for recovery in the event of a complete data center loss. The purpose of these tests is to validate the primary DC as fully operational and confirm the correct configuration of newly installed hardware.</p>



<p class="wp-block-paragraph"><strong>Secondary DC DRP Tests</strong>:</p>



<p class="wp-block-paragraph">Tests focused on the secondary data center are typically done following any new hardware upgrade. A complete secondary DC loss is simulated, with data and configuration recovery from the primary DC. The goal is to test the complete replication of the primary DC within the secondary DC. Additional tests validate the secondary DC as fully operational without access to the primary DC.</p>
<p>The post <a href="https://inceptioncrm.com/our-approach-to-disaster-recovery/">Our Approach to Disaster Recovery</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How We Select Vendors</title>
		<link>https://inceptioncrm.com/how-we-select-vendors/</link>
		
		<dc:creator><![CDATA[Marketing Team]]></dc:creator>
		<pubDate>Mon, 09 Aug 2021 10:58:55 +0000</pubDate>
				<category><![CDATA[Resources]]></category>
		<category><![CDATA[Security and Privacy]]></category>
		<category><![CDATA[Data Center Provider]]></category>
		<category><![CDATA[Hosting Partner]]></category>
		<category><![CDATA[Selecting Suppliers]]></category>
		<category><![CDATA[Subcontractors]]></category>
		<category><![CDATA[Vendor Selection]]></category>
		<category><![CDATA[Vendors]]></category>
		<guid isPermaLink="false">https://inceptioncrm.com/?p=3959</guid>

					<description><![CDATA[<p>We select vendors based on their ability to support the needs of our customers, as well as the security and availability of our solutions. </p>
<p>The post <a href="https://inceptioncrm.com/how-we-select-vendors/">How We Select Vendors</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We select vendors based on their ability to comply with the demands of our business, our customers&#8217; businesses, and any applicable regulatory demands concerning privacy, security, and availability. We assess them using both quantitative and qualitative criteria.</p>



<p class="wp-block-paragraph">Quantitative criteria include the quality of their services, their prices, the reliability and speed with which they can deliver, and their payment terms and conditions. </p>



<p class="wp-block-paragraph">We also consider, from a more qualitative perspective, their industry standing, service history, track record with similar customers, audit certifications, and compliance with international standards. </p>



<p class="wp-block-paragraph">Invariablly, we also take into account more subjective criteria, such as personal relationships with their management and staff, and the over relationship approach of their organization.</p>



<p class="wp-block-paragraph">In the case of our <a href="https://inceptioncrm.com/our-data-center-architecture/">data center provider</a>, for example, we selected the vendor who offered the highest quality service within the Czech Republic. We based our quality assessment on their tier rating, contractual guarantees, network availability and reach, and the security of their physical premises. Their position as a trusted vendor for major telecom companies, banks, and government ministries also helped identify them as a reliable site for hosting sensitive information.</p>



<p class="wp-block-paragraph">We source hardware only from reputable suppliers. Typically, we base our selection on functional fit and price, as well as product availability. This is especially true when deciding between suppliers who vendor the same products. However, we favor reliability and speed of delivery, as well, and are willing to pay more for better conditions. </p>



<p class="wp-block-paragraph">We source software only from vendors who meet industry standards. Price is less important, in this case, since those vendors tend to dominant their respective business areas and their products are well known and represent standards within the business &#8212; for example, Microsoft, Cisco, etc. </p>



<h3 class="wp-block-heading" id="h-use-of-subcontractors-in-our-projects">Use of Subcontractors in our Projects</h3>



<p class="wp-block-paragraph">For each customer project, we document all 3rd-party services and subcontractors whose services we plan to use during software development, or whose components we plan to integrate into the final product. We include these references both within the list of deliverables and in the product/service specification prior to implementation. </p>



<p class="wp-block-paragraph">If, for some reason, we need to use a different sub-contractor, we inform customers prior to making any changes. We also make sure customers understand the reason for the change. The customer can accept or dec line to accept the change, accepting any stated risks.</p>



<p class="wp-block-paragraph">While changes are rare within a given project lifecycle, they do happen on occasion, in most cases because the 3rd-party no longer provides / plans to discontinue the service. Other reasons can include changes in the subcontractor&#8217;s policies that conflict with our own guarantees, price changes, and changes in their terms and conditions. </p>



<p class="wp-block-paragraph">In such cases, we source an alternative provider and present it to the customer for their acceptance. Upon the customer&#8217;s acceptance, we initiate the change and update the list of <meta charset="utf-8">3rd-party services and subcontractors accordingly.</p>
<p>The post <a href="https://inceptioncrm.com/how-we-select-vendors/">How We Select Vendors</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How We Ensure Business Continuity</title>
		<link>https://inceptioncrm.com/how-we-ensure-business-continuity/</link>
		
		<dc:creator><![CDATA[Marketing Team]]></dc:creator>
		<pubDate>Wed, 04 Aug 2021 09:55:17 +0000</pubDate>
				<category><![CDATA[Business Continuity]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Security and Privacy]]></category>
		<category><![CDATA[BCP]]></category>
		<category><![CDATA[Business Continuity Planning]]></category>
		<category><![CDATA[Continuity of Operations]]></category>
		<category><![CDATA[Disaster Recovery]]></category>
		<category><![CDATA[Remote Work Policy]]></category>
		<guid isPermaLink="false">https://inceptioncrm.com/?p=3908</guid>

					<description><![CDATA[<p>D3S maintains detailed plans to ensure the total continuity of our business services in event of an emergency. </p>
<p>The post <a href="https://inceptioncrm.com/how-we-ensure-business-continuity/">How We Ensure Business Continuity</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">D3S maintains detailed plans for the continuity of services in the event that we are no longer to conduct &#8220;business as usual&#8221; from our regular business offices. </p>



<p class="wp-block-paragraph">These include policies governing the remote work of employees in the face of office closures; handover of duties in the event of employee incapacitation; restoration of critical business systems and communication channels; continued service provision and billing; and procedures for restoring a normal flow of operations. </p>



<p class="wp-block-paragraph">Business continuity planning is integral to our ability to maintain the continuity of our services. It addresses the key functions of our business: software development, software/service availability, project management, project delivery, customer support, and billing. </p>



<p class="wp-block-paragraph">During the recent Covid-19 public health emergency, when a government-imposed moratorium on public gatherings closed our business offices, we shifted internal work communication entirely to online channels. Employees who were unable to attend to their duties had their work temporarily reassigned until they could get back online from a stable location.</p>



<p class="wp-block-paragraph">As a result, our customers experienced zero interruption in service, support, or software availability. Payments and invoices were issued on time. From an outside perspective, our business continued as usual. </p>



<p class="wp-block-paragraph">While our offices have since reopened with normal on-site operations, our customers can expect total continuity of service from D3S in the event of another emergency. </p>
<p>The post <a href="https://inceptioncrm.com/how-we-ensure-business-continuity/">How We Ensure Business Continuity</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Our Data Center Architecture</title>
		<link>https://inceptioncrm.com/our-data-center-architecture/</link>
		
		<dc:creator><![CDATA[Marketing Team]]></dc:creator>
		<pubDate>Tue, 03 Aug 2021 14:28:46 +0000</pubDate>
				<category><![CDATA[Data Center Architecture]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Security and Privacy]]></category>
		<category><![CDATA[Data Center]]></category>
		<category><![CDATA[DC]]></category>
		<category><![CDATA[DC Ops]]></category>
		<category><![CDATA[IT Architecture]]></category>
		<guid isPermaLink="false">https://inceptioncrm.com/?p=3869</guid>

					<description><![CDATA[<p>D3S’s hosted computing environment operates within two data centers managed by one of the leading hosting providers in the Czech Republic. </p>
<p>The post <a href="https://inceptioncrm.com/our-data-center-architecture/">Our Data Center Architecture</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h3 class="wp-block-heading" id="h-hosting-provider">Hosting Provider</h3>



<p class="wp-block-paragraph">D3S’s hosted computing environment uses connectivity provided by the hosting provider, <meta charset="utf-8"><a href="https://www.dialtelecom.cz/" target="_blank" rel="noreferrer noopener">Dial Telecom, a.s.</a>, an international provider and one of the leading backbone providers in the Czech Republic. </p>



<h3 class="wp-block-heading">Data Center Locations</h3>



<p class="wp-block-paragraph">D3S’s hosted computing environment operates within two data centers, each located just over 200 km away from the other in Prague and Brno, which meets the precondition for minimal safe distance in the event of a natural disaster or terrorist attack.</p>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img fetchpriority="high" decoding="async" src="https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.002.png" alt="Data Center Locations" class="wp-image-3875" width="430" height="430" srcset="https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.002.png 600w, https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.002-300x300.png 300w, https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.002-150x150.png 150w" sizes="(max-width: 430px) 100vw, 430px" /></figure></div>



<p class="wp-block-paragraph">Both data centers meet the highest safety and operational parameters required for data centers providing professional hosting services and secure hosting of sensitive data. Both centers are ISO 27001 certified (among other certifications) and are subject to regular corporate and government audits.</p>



<h3 class="wp-block-heading">Internet Connectivity</h3>



<p class="wp-block-paragraph">The hosting provider supports D3S with independent internet connectivity to our services.</p>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img decoding="async" src="https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.001-1.png" alt="Data Center Connectivity " class="wp-image-3880" width="412" height="412" srcset="https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.001-1.png 512w, https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.001-1-300x300.png 300w, https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.001-1-150x150.png 150w" sizes="(max-width: 412px) 100vw, 412px" /></figure></div>



<h3 class="wp-block-heading">Primary Data Center (PDC)</h3>



<p class="wp-block-paragraph">The primary data center (PDC) provides services necessary for the operation of client applications (such as Inception CRM) and their services. This data center has the following operational and technical parameters:</p>



<ul class="wp-block-list"><li>The PDC is located in our lockable racks</li><li>The PDC is geographically located in Prague (12 km from D3S HQ)</li><li>The PDC is located on the secure premises of Dial Telecom, a.s.</li><li>Dial Telecom is responsible for the physical security of (access perimeter security) of the data center and its assets.</li><li>Physical access to data center is restricted to authorized persons only</li><li>Internet connectivity and power supplies are secured by redundant connections and backup electricity (both diesel generators and multiple grids)</li><li>Air-conditioned rack space</li><li>VPN access for most administrative tasks</li><li>Connectivity to secondary data center enabling continuous data exchange to ensure security of backups, availability of failover services, and overall business continuity</li></ul>



<h3 class="wp-block-heading">Secondary Data Center (2DC)</h3>



<p class="wp-block-paragraph">To reduce the risks associated with the possible failure of the PDC and the increase in resistance in the event of its failure, D3S operates a separate backup data center. This secondary data center (2DC) has the following operational and technical parameters:</p>



<ul class="wp-block-list"><li>It is geographically distant from the PDC (more than 200 km away)</li><li>Physical perimeter protection of the data center is at the same level as the PDC</li><li>The 2DC has the same functionality as the PDC</li><li>The 2DC contains full backups of customer data to meet RTO and RPO objectives</li><li>The 2DC is connected to the PDC via permanent VPN</li><li>Server Manager and other management roles are the same for both 2DC and PDC</li></ul>



<h3 class="wp-block-heading">Administration</h3>



<p class="wp-block-paragraph">All application, database, storage servers located in data centers use the D3S Active Directory structure: primary and secondary domain controllers running Windows Servers. Management of these domain controllers and domain accounts are performed by D3S technicians.</p>



<p class="wp-block-paragraph">All server administrators (application, database, backup) in the data center have their own unique domain accounts for managing servers.</p>



<p class="wp-block-paragraph">For remote data center management, we use a built-in IpSEC VPN provided by Fortigate Firewall.</p>



<h3 class="wp-block-heading"><a href="#servers"></a>Servers</h3>



<p class="wp-block-paragraph">A brief list of primary server types used in the D3S data center for DevOps and ITOps is provided for illustration:</p>



<figure class="wp-block-table"><table><tbody><tr><td><strong>Server Type</strong></td><td><strong>Operating System</strong></td><td><strong>Available Functions</strong></td></tr><tr><td>Firewalls</td><td>FortiOS</td><td>The main firewall of our data center</td></tr><tr><td>Hypervisors</td><td>VMWare ESXi </td><td>Hosting all other operating systems</td></tr><tr><td>Application Servers</td><td>Windows Servers</td><td>Hosted applications on IIS server</td></tr><tr><td>Database Servers</td><td>Windows Servers + Microsoft SQL Servers</td><td>Hosted customer data</td></tr><tr><td>Domain Controllers</td><td>Windows Servers</td><td>Active Directory, DNS</td></tr><tr><td>Storage Servers</td><td>Synology DSM</td><td>Backups, Application packages</td></tr></tbody></table></figure>



<h3 class="wp-block-heading">DMZ<a href="#secondary-data-center-2dc"></a></h3>



<p class="wp-block-paragraph">Our DMZ – or &#8220;demilitarized zone&#8221; – contains the following servers:</p>



<ul class="wp-block-list"><li>Email server</li><li>Web server</li></ul>



<div class="wp-block-image"><figure class="aligncenter size-full is-resized"><img decoding="async" src="https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.003.png" alt="Data Center Architecture" class="wp-image-3876" width="572" height="572" srcset="https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.003.png 600w, https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.003-300x300.png 300w, https://inceptioncrm.com/wp-content/uploads/2021/08/SOP.028.IT_ARCHITECTURE.003-150x150.png 150w" sizes="(max-width: 572px) 100vw, 572px" /></figure></div>



<p class="wp-block-paragraph">The email and web servers are the only servers located outside of our internal network.</p>
<p>The post <a href="https://inceptioncrm.com/our-data-center-architecture/">Our Data Center Architecture</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How We Monitor Our Systems</title>
		<link>https://inceptioncrm.com/how-we-monitor-our-systems/</link>
		
		<dc:creator><![CDATA[Marketing Team]]></dc:creator>
		<pubDate>Tue, 03 Aug 2021 10:36:58 +0000</pubDate>
				<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Resources]]></category>
		<category><![CDATA[Security and Privacy]]></category>
		<category><![CDATA[AlertManager]]></category>
		<category><![CDATA[Alerts]]></category>
		<category><![CDATA[Application Monitoring]]></category>
		<category><![CDATA[blackbox exporter]]></category>
		<category><![CDATA[Data Viewing]]></category>
		<category><![CDATA[Docker]]></category>
		<category><![CDATA[Grafana]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Kubernetes]]></category>
		<category><![CDATA[Logs Collection]]></category>
		<category><![CDATA[Loki]]></category>
		<category><![CDATA[Metrics Collection]]></category>
		<category><![CDATA[Monitoring Architecture]]></category>
		<category><![CDATA[Prometheus]]></category>
		<category><![CDATA[Slack]]></category>
		<category><![CDATA[StatusCake]]></category>
		<category><![CDATA[Synology]]></category>
		<category><![CDATA[System Monitoring]]></category>
		<category><![CDATA[UptimeRobot]]></category>
		<guid isPermaLink="false">https://inceptioncrm.com/?p=3688</guid>

					<description><![CDATA[<p>D3S uses cutting-edge tools, including Loki, Grafana and Prometheus, to actively monitor key components of our production infrastructure. </p>
<p>The post <a href="https://inceptioncrm.com/how-we-monitor-our-systems/">How We Monitor Our Systems</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">D3S actively monitors key components of our production infrastructure. To do this, we use a combination of cutting-edge tools, including Loki, Grafana, Prometheus, AlertMonitoring, and UptimeRobot.</p>



<p class="wp-block-paragraph">Loki collects and labels logs from our applications. Prometheus meanwhile collects data that are published by <strong>blackbox_exporter </strong>(services reachability and self tests), <strong>db_checker </strong>(database integrity checks) and metrics from Kubernetes. </p>



<p class="wp-block-paragraph">Prometheus also contains alerting rules. All alerts are caught by <strong>AlertManager</strong>, which provides pager services through <strong>Slack</strong>. We use Slack to coordinate our monitoring activities. </p>



<p class="wp-block-paragraph">We use <strong>Grafana</strong> to view and analyse all data collected by Prometheus and Loki. To achieve better reliability of our monitoring, we use <strong>UptimeRobot </strong>(a 3rd-party tool that runs outside of our infrastructure), to mirror reachability tests from <strong>blackbox_exporter</strong>.</p>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading" id="h-what-we-monitor">What We Monitor</h3>



<ul class="wp-block-list"><li><strong>Services Reachability</strong><br><ul><li>We conduct tests via HTTP GET (blackbox_exporter). We collect test results from two instances of blackbox_exporter, both of which run in docker on Synology servers. These Synology servers are located outside of D3S&#8217;s infrastructure.</li><li>We use HTTP GET to run two types of tests:<ul><li>A basic test checks to see if the landing page of an application or service is reachable and returning a 2xx response.</li><li>Additional testing is performed using a self-test, which is triggered by RestAPI.<br><br></li></ul></li></ul></li><li><strong>Database Integrity</strong><br><ul><li>We use db_checker, an internally developed tool, to check database integrity. It is a C# application running in docker that runs SQL queries against tested databases. Tests are specified in XML with use of CRON-like syntax. </li><li>Tests are divided into general (synchronization, jobs, &#8230;) and client specific queries to ensure a high level of quality assurance.<br><br></li></ul></li><li><strong>Kubernetes Metrics</strong><br><ul><li>Prometheus Operator runs on Kubernetes and collects all runtime metrics from it. Grafana runs on Synology in our data center and is connected to it. We observe Kubernetes nodes, pods, network, RabbitMQ, and more.<br><br></li></ul></li><li><strong>Dead Man Switch</strong><br><ul><li>All blackbox_exporters periodically call the API in <strong>StatusCake</strong>. If StatusCake does not receive an &#8220;I am alive&#8221; signal every five minutes it starts issuing alerts. We do this to make sure that the entire Prometheus stack is working and that Slack is receiving correct data.<br></li></ul></li></ul>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading">Technologies</h3>



<h4 class="wp-block-heading">Logs Collection</h4>



<p class="wp-block-paragraph">We use <a href="https://grafana.com/oss/loki/">Loki</a>, a log aggregation system, to collect logs. Loki does not index data but rather identifies each log stream by set of labels. This results in a relatively low demand on system resources. Even though searching though it is not as fast as an indexed system, its low demand allows it to run continuously.</p>



<h4 class="wp-block-heading">Metrics Collection</h4>



<p class="wp-block-paragraph"><strong>Prometheus</strong></p>



<p class="wp-block-paragraph"><a href="https://prometheus.io" target="_blank" rel="noreferrer noopener">Prometheus</a> periodically collects data from configured metrics that are published by application components. We implement alerts using Prometheus&#8217;s query language.</p>



<p class="wp-block-paragraph"><strong>AlertManager</strong></p>



<p class="wp-block-paragraph"><a href="https://prometheus.io/docs/alerting/overview/" target="_blank" rel="noreferrer noopener">AlertManager</a> handles alerts sent by Prometheus. We use AlertManager to deduplicate and group errors so that our response team responds only to relevant errors. We also use AlertManager to specify silences in the event of planned/controlled outages to prevent the IT Security Team from receiving irrelevant messages. Alerts in a &#8220;firing&#8221; status are sent to Slack, where our service teams receive notifications.</p>



<h4 class="wp-block-heading">Data Viewing</h4>



<p class="wp-block-paragraph">We use <a href="https://grafana.com/" target="_blank" rel="noreferrer noopener">Grafana</a> for querying, visualizing and alerting over data metrics. Grafan allows us to create custom dashboards for faster and easier analysis of ingested data.</p>



<p class="wp-block-paragraph"></p>



<h3 class="wp-block-heading">Monitoring Architecture</h3>



<p class="wp-block-paragraph">The Prometheus stack mainly runs on a Synology server in Docker, where Loki, Prometheus, Grafana, AlertManager, and other data monitoring tools are located. Blackbox_exporters are located on Synology devices outside of our data center network, though we keep one instance of blackbox_exporter on Synology in our data center as a &#8220;dead man switch&#8221;. Each application we monitor has a plugin that sends data to Loki for labeling and storage.</p>



<p class="wp-block-paragraph">Prometheus reads data from Prometheus metrics servers, which are connected to production environment applications. Prometheus also periodically runs alerts (queries in Promql language) and if it detects an error, it sends it to AlertManager. AlertManager than deduplicates and groups these errors and sends relevant ones to Slack, which we use as our pager system.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="865" src="https://inceptioncrm.com/wp-content/uploads/2021/08/Monitoring-Architecture-1024x865.png" alt="Monitoring Architecture" class="wp-image-3777" srcset="https://inceptioncrm.com/wp-content/uploads/2021/08/Monitoring-Architecture-1024x865.png 1024w, https://inceptioncrm.com/wp-content/uploads/2021/08/Monitoring-Architecture-300x253.png 300w, https://inceptioncrm.com/wp-content/uploads/2021/08/Monitoring-Architecture-768x649.png 768w, https://inceptioncrm.com/wp-content/uploads/2021/08/Monitoring-Architecture-1320x1115.png 1320w, https://inceptioncrm.com/wp-content/uploads/2021/08/Monitoring-Architecture.png 1404w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h3 class="wp-block-heading">Best Practices</h3>



<p class="wp-block-paragraph">We apply the following best practices to alerting and dashboard configuration:</p>



<h4 class="wp-block-heading">Alerting</h4>



<ul class="wp-block-list"><li>Alerts should be as short as possible while containing important information</li><li>Alerts that are fired too often should be revised</li><li>Fire alerts after a reasonable downtime (10 minutes for front end services is reasonable)</li><li>Alerts should be divided into groups of interest (developers and DevOps subscribe to relevant groups) </li></ul>



<p class="wp-block-paragraph"></p>



<h4 class="wp-block-heading">Dashboards </h4>



<ul class="wp-block-list"><li>Do not use the ROWS component of dashboards</li><li>There should not be more than 6 graphs or tables on one dashboard </li><li>Use drill down (Main dashboard → Component overview → Detail)</li></ul>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://inceptioncrm.com/how-we-monitor-our-systems/">How We Monitor Our Systems</a> appeared first on <a href="https://inceptioncrm.com">Inception CRM</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
