Data processing
The way data is processed in Product Master is controlled by the business users through the user interface, in concert with defined workflows that reflect the requirements of product categories and secondary specifications. Tasks can also be invoked through the Product Master API by calling applications.
Encryption for data at rest as well as in transit are available and it is recommended to be implemented if exposure exist for unauthorized access to the MDM systems environment. This is especially applicable if remote connections extend beyond your firewall.
Physical storage and hosting of personal data
Product Master is a potentially critical part of an enterprise's systems environment and this
means that measures need to be taken to ensure the appropriate level of protection and redundancy
are implemented to achieve suitable SLA level. In other words, high availability and disaster
recovery architectures are common for Product Master deployments. Several patterns exist for this,
but a full review of these in this document is not appropriate. Contact your IBM representative for
more information and assistance to address your unique needs. However, the following aspects should
be considered, if applicable:
- Primary data center
- Per the information in this document.
- Backup sites
- If applicable, the same measure and protections as they are in place for the primary data center should apply to any back-up sites. Furthermore, the connectivity and switchover facilities that exist between the primary site and these must ensure the integrity of the data protection of the MDM data, especially the personal data content.
- Archives
- Product Master does not include an archiving capability. However, if archiving is implemented through external facilities, its data protection, access rules, and so on should be in line with the main Product Master instance, or potentially even more restrictive.
- Mirroring
- In some configuration mirroring, data replication or other forms of maintaining multiple instances of the Product Master environments are used. In those cases, the same consideration apply as described above for backup sites with the additional consideration of the mechanisms used to direct the transaction activities (request/responses) to the correct instance (such as load balancers).