Data Storage Security
Master
data and transaction data is stored
in the database of the SAP system on which MIC has been installed. Data
storage occurs for the most part in Organizational
Management, in Case Management, and in
separate tables for this purpose. Due to the use of Organizational Management
in particular, we recommend running MIC on a separate client. For more
information and recommendations on the use of clients, see the application
documentation under
Management of Internal
Controls (FIN-CGV-MIC).
MIC requires a Web browser as the user interface. For data storage in the front end, non-persistent session cookies are used.
In some Web applications, MIC users can upload documents into the system. Knowledge Provider (KPro) is used for storing the data. Once uploaded, the documents can be accessed using an URL. The MIC-specific Roles and Authorizations Concept governs authorization for accessing the URL directly in the Web application. To prevent unauthorized access to the document through copying and sending the URL, an URL is only valid for a given user and for a restricted amount of time (two hours).