This was a flagship collaborative project to provide a web based asset tracking system that all members of the consortium and their suppliers would use to arrange and monitor transportation and location of assets (including people) on a global basis.
Client Requirement and Business Drivers
The system was required to provide a variety of access levels to the various user companies and individuals within them, but to at the same time ensure the protection of commercially sensitive and private data. Transportation was to be booked, training and health and safety records maintained, and the location of all individuals maintained while off-shore.
- The systems used by all members of the consortium were different but essentially performed the same function – successful roll-out of the project would enable all to securely take advantage of the efficiencies introduced by adoption of a commonly hosted and supported system
- The system would provide a common set of processes for booking transportation, ensuring training and health and safety records were up to date, and recording the location of assets while off-shore – this could only be achieved if all consortium members and users were confident in the availability, integrity and confidentiality of the information held
- Information held would be potentially commercially sensitive, relating to the movement of personnel around the globe
- Personal data in the form of employee and contractor records led to a high priority being put on security to comply with data protection requirements of multiple countries
- A final concern related to terrorism, with locations of staff while on flights and at offshore locations being held within the system – also potential issues with availability through potential attacks from some more extreme environmental groups
Commissum was engaged early in the project to provide a range of security related services. These included:
- Early briefing of the 3rd party project development team on issues relating to development of secure applications
- Audit of developer’s processes for development
- Design review for security throughout the project lifecycle
- Security testing at Factory Acceptance
- Regression testing in the final phases prior to go-live
- Final Site Acceptance Application and Infrastructure Security Testing
Commissum worked closely with all stakeholders in this very complex project, to ensure the final security of the system. The management organisation that acted on behalf of the consortium, a major coordinator of collaborative projects in the oil and gas sector continues to be a valued partner with other collaborative ventures currently in progress.