Managed Online Backup Compliance
|
|
|
- Patience Robinson
- 10 years ago
- Views:
Transcription
1 Managed Online Backup Compliance
2 Introduction Many of MAXfocus s new and existing customers who have started to use Managed Online Backup [MOB] have asked for a statement of compliance against existing standards and regulations with respect to data storage. This document attempts to establish the position of MAXfocus against some of the known standards in the data storage industry today and also details information on data encryption. This may be considered to be a live document that will be updated as we learn more information about standards in different regional geographies. This document will follow a question and answer format detailing many of the questions we have been asked to date with respect to compliance. MOB Compliance What data centers do MAXfocus use? UK, London: [located in Slough] USA, Atlanta: Australia, Sydney: Germany, Dusseldorf: What level of uptime do the Equinix data centers support? % This far exceeds that stipulated for Teir 4 data centers. What level of data compliance do the data centers support that MAXfocus use? DATA CENTRE COMPLIANCE ATLANTA SSAE16 SOC1 (formerly SAS70) ISO 9001: Quality Management OHSAS 18001: Health & Safety Management ISO/IEC 27001: Information Security Management [see detail below] LONDON Specifies the requirements for establishing, implementing, operating, monitoring, reviewing, maintaining and improving a documented Information Security Management System within the context of the organization's overall business risks. It specifies requirements for the implementation of security controls customized to the needs of individual organizations or parts thereof. Is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties. Is intended to be suitable for several different types of use, including the following: MAX RemoteManagement Managed Online Backup Compliance 2
3 1. use within organizations to formulate security requirements and objectives; 2. use within organizations as a way to ensure that security risks are cost effectively managed; 3. use within organizations to ensure compliance with laws and regulations; 4. use within an organization as a process framework for the implementation and management of controls to ensure that the specific security objectives of an organization are met; 5. definition of new information security management processes; 6. identification and clarification of existing information security management processes; 7. use by the management of organizations to determine the status of information security management activities; 8. use by the internal and external auditors of organizations to determine the degree of compliance with the policies, directives and standards adopted by an organization; 9. use by organizations to provide relevant information about information security policies, directives, standards and procedures to trading partners and other organizations with whom they interact for operational or commercial reasons; 10. implementation of business-enabling information security; 11. use by organizations to provide relevant information about information security to customers DUSSELDORF SYDNEY ISO/IEC [See above London for more detail] ISO/IEC 27001:2005 [See above London for more detail] Do we comply with Health Insurance Portability and Accountability [HIPAA] requirements? HIPAA REQUIREMENT Electronic personal health information (ephi) must be protected against any reasonably anticipated threats or hazards. Access to ephi must be protected against any reasonably anticipated uses or disclosures that are not permitted or required by the Privacy Rule. Maintenance of record of access authorizations If the data is processed through a third party, entities are required to enter into a chain of trust partner agreement MAXfocus RESPONSE At MAXfocus, data is housed in data centres from Equinix. These data centres are designed with power systems that have built-in redundancy, full Uninterruptible Power Supply (UPS) systems with N+1 levels or greater, and backup generator systems in the event of a local utility failure. Data is encrypted before transmission and is always maintained in an encrypted state at the data centre. The Backup Manager records when data has been uploaded and restored. We have a EULA that customer need to agree to before proceeding. MAX RemoteManagement Managed Online Backup Compliance 3
4 Do we comply with Sarbanes-Oxley [SoX] requirements? SOX REQUIREMENT Record material must be accessible. Information cannot be tampered with or altered by any employee. Certain data must be retained for a minimum of 7 years Information is available only to clients authorised personnel? MAXfocus RESPONSE All stored material is accessible and even in the event that the internet is down material may be recovered from the Local Speed Vault [LSV] if enabled. All data is encrypted before being sent to the data centre. As long as the MSP does not delete the client Storage Account the data will be held indefinitely. In the first release MAXfocus will retain the encryption keys. In a future release we will allow the option for the client to manage their own encryption keys. Do we comply with Payments Card Industry [PCI] requirements? PCI REQUIREMENT Protect cardholder data Encryption across all public networks MAXfocus RESPONSE All stored material is accessible and even in the event that the internet is down material may be recovered from the Local Speed Vault [LSV] if enabled. All data is encrypted before being sent to the data centre. What encryption standard do you use? AES 128 bit. Why did you elect to go with AES 128 bit as opposed to AES 256 bit? This is the standard protocol used for all secure web transactions today. It is exceptionally secure. Consider the example below. Using one trillion computers each generating 1 billion key attempts per second it would still take 4 billion years to run through all available key combinations. By that time the sun would have turned in to a red giant and the earth would be incinerated anyway! Who will hold the encryption key? In the initial release MAXfocus will hold the encryption key. In the future we will consider the option of allowing the Managed Service Provider/IT Service Company to hold the key. However in this case there will be no way for MAXfocus to retrieve this data if the key is lost, as it will only be known by the customer. MAX RemoteManagement Managed Online Backup Compliance 4
5 I understand there is a video tour of the London and Sydney data centers, where can I find this? London: Sydney: MAX RemoteManagement Managed Online Backup Compliance 5
6 USA, Canada, Central and South America 4309 Emperor Blvd, Suite 400, Durham, NC USA Europe and United Kingdom Vision Building, Greenmarket, Dundee, DD1 4QB, UK Australia and New Zealand 2/148 Greenhill Road, Parkside, SA SB0047-v1.0-EN 2014 LogicNow Ltd. All rights reserved. All product and company names herein may be trademarks of their respective owners. The information and content in this document is provided for informational purposes only and is provided as is with no warranty of any kind, either express or implied, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, and non-infringement. LogicNow is not liable for any damages, including any consequential damages, of any kind that may result from the use of this document. The information is obtained from publicly available sources. Though reasonable effort has been made to ensure the accuracy of the data provided, LogicNow makes no claim, promise or guarantee about the completeness, accuracy, recency or adequacy of information and is not responsible for misprints, out-of-date information, or errors. LogicNow makes no warranty, express or implied, and assumes no legal liability or responsibility for the accuracy or completeness of any information contained in this document. If you believe there are any factual errors in this document, please contact us and we will review your concerns as soon as practical. MAX RemoteManagement Managed Online Backup Compliance 6
Make life simple and make more money the easy way.
Technical factsheet Make life simple and make more money the easy way. MAX Backup - fast, reliable, automatic, offsite, secure backup and disaster recovery to make your life easier! No more worrying about
MAX Insight. HIPAA Hardening & Configuration Guide for MSP s
MAX Insight Whitepaper HIPAA Hardening & Configuration Guide for MSP s Detailed advice and recommendations on how to properly setup and configure the MAXfocus product platform for usage within HIPAA compliancy
An Effective MSP Approach Towards HIPAA Compliance
MAX Insight Whitepaper An Effective MSP Approach Towards HIPAA Compliance An independent review of HIPAA requirements, detailed recommendations and vital resources to aid in achieving compliance. Table
GFI Product Guide. GFI MailArchiver Archive Restrictions and Licensing Guide
GFI Product Guide GFI MailArchiver Archive Restrictions and Licensing Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty
GFI MAX RemoteManagement Building Blocks to Managed services
GFI MAX RemoteManagement Building Blocks to Managed services Overview GFI s Building Block Program is all about making Managed Services a practical reality for IT support companies. A recent survey found
GFI Product Guide. How to create a new SQL Server Instance in Microsoft SQL Server 2012 and SQL Server Express
GFI Product Guide How to create a new SQL Server Instance in Microsoft SQL Server 2012 and SQL Server Express The information and content in this document is provided for informational purposes only and
Archiving technologies
GFI White Paper Archiving technologies Have you ever considered the impact one untraceable email can have on an organization or individual s career? With so much corporate information contained within
How to create a complex and secure backup strategy
GFI White Paper How to create a complex and secure backup strategy Data is the lifeblood of every organization and business. Data theft and data loss through negligence or hardware failure can cause irreparable
Archive Legislation: Email archiving in the Netherlands. The key laws that affect your business
Archive Legislation: Email archiving in the Netherlands The key laws that affect your business Contents Laws regulating archiving 3 Who is required to archive email? 4 GFI Archiver 4 Archive Legislation:
GFI Product Comparison. GFI LanGuard 2011 vs Retina Network Security Scanner 5.12.1
GFI Product Comparison GFI LanGuard 2011 vs Retina Network Security Scanner 5.12.1 General features GFI LanGuard 2011 Retina 5.12.1 Scheduled scans Agent-less Agent-based Integration with Active Directory
GFI Product Comparison. GFI LanGuard 2011 vs Microsoft Baseline Security Analyzer 2.2
GFI Product Comparison GFI LanGuard 2011 vs Microsoft Baseline Security Analyzer 2.2 General features GFI LanGuard 2011 MBSA 2.2 Scheduled scans r Agent-less Agent-based Integration with Active Directory
MASSIVE NETWORKS Online Backup Compliance Guidelines... 1. Sarbanes-Oxley (SOX)... 2. SOX Requirements... 2
MASSIVE NETWORKS Online Backup Compliance Guidelines Last updated: Sunday, November 13 th, 2011 Contents MASSIVE NETWORKS Online Backup Compliance Guidelines... 1 Sarbanes-Oxley (SOX)... 2 SOX Requirements...
Survey: Web filtering in Small and Medium-sized Enterprises (SMEs)
September 2010 GFI Software www.gfi.com More and more organizations are seeing value in web filtering and web security solutions, a survey conducted by GFI Software shows, with seven in 10 stating they
Integrating faxes into today s world of healthcare e-records
GFI White Paper Integrating faxes into today s world of healthcare e-records This white paper examines the obstacles preventing the move away from fax machines, and the benefits of having a communications
GFI Product Guide. GFI MailArchiver Archive Assistant
GFI Product Guide GFI MailArchiver Archive Assistant The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either
GFI Product Guide. GFI Archiver Evaluation Guide
GFI Product Guide GFI Archiver Evaluation Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either express
GFI product comparison. GFI MailArchiver vs. Symantec Enterprise Vault
GFI product comparison GFI MailArchiver vs. Symantec Enterprise Vault General features GFI MailArchiver Symantec Enterprise Vault Supports Microsoft Exchange Server 2003, 2007 and 2010 Supports distributed
GFI Product Manual. GFI MailArchiver Evaluation Guide
GFI Product Manual GFI MailArchiver Evaluation Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either
Quick Start Guide for administrators
Quick Start Guide for administrators Contents Welcome 3 Your login information 3 Step 1: Adding mailboxes 3 Part 1: Add users 3 Part 2: Add aliases 3 Step 2: Adjusting your spam handling settings 4 Optional
How to configure IBM iseries (formerly AS/400) event collection with Audit and GFI EventsManager
GFI White Paper How to configure IBM iseries (formerly AS/400) event collection with Audit and GFI EventsManager This document explains how to configure and use GFI EventsManager to collect IBM iseries
GFI MailEssentials Online Archive Configuration and usage
GFI MailEssentials Online Archive Configuration and usage Contents Retention policies 3 Message tagging 4 Access rights 5 Journaling 5 Accessing archived messages 7 Archive search / Viewing archived messages
GFI product comparison. GFI MailArchiver vs. Microsoft Exchange 2010
GFI product comparison GFI MailArchiver vs. Microsoft Exchange 2010 GFI MailArchiver GFI MailArchiver is an industry-leading email management solution. It is used globally by administrators to lower email
BUILDING BACKUP AS A SERVICE (BaaS)
BUILDING BACKUP AS A SERVICE (BaaS) Whitepaper backup.gfimax.com Backup-as-a-Service (BaaS): A fantastic opportunity for MSPs and IT Support Providers Everyone needs backup. But, it is a thankless job,
GFI Archiver Evaluation guide: Online Demo Evaluation Guide
GFI Archiver Evaluation guide: Online Demo Evaluation Guide EN The information and content in this document is provided for informational purposes only and is provided as is with no warranty of any kind,
GFI Product comparison. GFI MailArchiver vs. Microsoft Exchange 2010
GFI Product comparison GFI MailArchiver vs. Microsoft Exchange 2010 GFI MailArchiver 2011 GFI MailArchiver is an industry-leading email management solution. It is used globally by administrators to lower
GFI Product Comparison. GFI MailArchiver 6.0 vs Quest Software Archive Manager
GFI Product Comparison GFI MailArchiver 6.0 vs Quest Software Archive Manager General features GFI MailArchiver 6.0 Quest Software Archive Manager Supports Microsoft Exchange 2000, 2003 and 2007 Supports
GFI MailEssentials 2014 Upgrade Guide A guide to upgrading from previous versions of GFI MailEssentials and GFI MailSecurity
GFI MailEssentials 2014 Upgrade Guide A guide to upgrading from previous versions of GFI MailEssentials and GFI MailSecurity The information and content in this document is provided for informational purposes
GFI Product Comparison. GFI MailArchiver 6.0 vs Stimulus Software MailArchiva
GFI Product Comparison GFI MailArchiver 6.0 vs Stimulus Software MailArchiva Overview GFI MailArchiver 6.0 is the business archiving solution for small and medium-sized enterprises (SMEs). Reduce PST management
Understanding data backups: why SMEs need them
GFI White Paper Understanding data backups: why SMEs need them Data is the lifeblood of every organization, yet many either fail to back up their data or they are not doing so properly. Losing data can
How To Set Up A Journaling Mailbox In Microsoft Office 365 And Gfi Mailarchiver
GFI Product Guide GFI MailArchiver and Office 365 Deployment Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any
WHITE PAPER. HIPAA-Compliant Data Backup and Disaster Recovery
WHITE PAPER HIPAA-Compliant Data Backup and Disaster Recovery DOCUMENT INFORMATION HIPAA-Compliant Data Backup and Disaster Recovery PRINTED March 2011 COPYRIGHT Copyright 2011 VaultLogix, LLC. All Rights
The business implications of not having a backup strategy: where businesses get it wrong
GFI White Paper The business implications of not having a backup strategy: where businesses get it wrong A business that fails to maintain a copy of its data is asking for trouble. It is extremely easy
GFI MailSecurity deployment strategies
GFI White Paper GFI MailSecurity deployment strategies Which operating mode(s) to use in your network environment GFI MailSecurity can be deployed as an SMTP gateway or as a VS API version for Microsoft
GFI FAXmaker for Exchange/SMTP 12: An introduction to the architecture and deployment options
GFI FAXmaker for Exchange/SMTP 12: An introduction to the architecture and deployment options An overview of how GFI FAXmaker works, and how to deploy it This white paper describes the different ways in
GFI Product Comparison. GFI MailArchiver 6.0 vs Waterford Technologies MailMeter Archive
GFI Product Comparison GFI MailArchiver 6.0 vs Waterford Technologies MailMeter Archive General features GFI MailArchiver 6.0 Waterford Technologies MailMeter Archive Supports Microsoft Exchange Server
Email security Cloud vs. On-premise solutions
GFI White Paper Email security Cloud vs. On-premise solutions Choosing whether to put your email security in the cloud or host it on premise is a major decision. Hopefully this white paper will help. Contents
The importance of an Acceptable Use Policy
GFI White Paper The importance of an Acceptable Use Policy In an ideal world, employees would use the computers and Internet access provided their employer solely for business use. It is however, sadly,
GFI Product Manual. GFI MailArchiver Outlook Addon
GFI Product Manual GFI MailArchiver Outlook Addon The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either express
GFI Product Comparison. GFI MailEssentials vs Symantec Mail Security for Microsoft Exchange 7.0
GFI Product Comparison GFI MailEssentials vs Symantec Mail Security for Microsoft Exchange 7.0 GFI MailEssentials Symantec Mail Security for Microsoft Exchange 7.0 Supports Microsoft Exchange Server 2003
GFI Product Comparison. GFI MailArchiver 6.0 vs EMC EmailXtender Archive Edition
GFI Product Comparison GFI MailArchiver 6.0 vs EMC EmailXtender Archive Edition General features GFI MailArchiver 6.0 EMC EmailXtender Archive Edition Supports Microsoft Exchange Server 2000, 2003 and
GFI Product Manual. Outlook Connector User Manual
GFI Product Manual Outlook Connector User Manual http://www.gfi.com [email protected] The information and content in this document is provided for informational purposes only and is provided "as is" with no
How to keep spam off your network
GFI White Paper How to keep spam off your network What features to look for in anti-spam technology A buyer s guide to anti-spam software, this white paper highlights the key features to look for in anti-spam
Datto Compliance 101 1
Datto Compliance 101 1 Overview Overview This document provides a general overview of the Health Insurance Portability and Accounting Act (HIPAA) compliance requirements for Managed Service Providers (MSPs)
Archive Legislation: Email archiving in Switzerland. The key laws that affect your business
Archive Legislation: Email archiving in Switzerland The key laws that affect your business Contents Basic provisions for document retention: Obligation to archive for 10 years 3 Tax law requirements 3
GFI White Paper: GFI FaxMaker and HIPAA compliance
GFI White Paper: GFI FaxMaker and HIPAA compliance This document outlines the requirements of HIPAA in terms of faxing protected health information and how GFI Software s GFI FaxMaker, an easy-to-use fax
Endpoint Protection Performance Benchmarks
Endpoint Protection Performance Benchmarks GFI Software conducted objective performance testing on four, publically available business endpoint protection security software products on Windows 7 Professional
SAS 70 Type II Audits
Thinking from IntraLinks SAS 70 Type II Audits SAS 70 Type II Audits Ensuring Data Security, Reliability and Integrity If your organization shares sensitive data over the Internet, you need rigorous controls
GFI Product Guide. Archive Assistant
GFI Product Guide Archive Assistant The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either express or implied,
GFI White Paper. Going beyond Exchange 2010 - Why it pays to have a dedicated email archiving solution
GFI White Paper Going beyond Exchange 2010 - Why it pays to have a dedicated email archiving solution Contents Introduction 3 The state of email archiving and data retention 3 The compliance challenge
GFI Cloud white paper. Cloud-based services: Easing the IT burden while taking control. www.gficloud.com
GFI Cloud white paper Cloud-based services: Easing the IT burden while taking control www.gficloud.com Contents Introduction 3 Transferring workload into the cloud 4 Managing the cloud 5 Summary 6 About
Product comparison. GFI LanGuard 2014 vs. Microsoft Windows InTune (October 2013 Release)
Product comparison GFI LanGuard 2014 vs. Microsoft Windows InTune (October 2013 Release) GFI LanGuard 2014 Windows Intune General features Scheduled scans Agent-less r Agent-based Integration with Active
GFI Product Guide. GFI Archiver and Office 365 Deployment Guide
GFI Product Guide GFI Archiver and Office 365 Deployment Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind,
GFI Product Comparison. GFI MailEssentials vs Barracuda Spam Firewall
GFI Product Comparison GFI MailEssentials vs Barracuda Spam Firewall GFI MailEssentials Barracuda Spam Firewall Integrates closely with Microsoft Exchange Server 2003/2007/2010 Integrates closely with
docs.rackspace.com/api
docs.rackspace.com/api Rackspace Cloud Backup Release (2015-09-09) 2015 Rackspace US, Inc. This document is intended for software developers who are interested in developing applications using the Rackspace
GFI White Paper. How Web Reputation increases your online protection
GFI White Paper How Web Reputation increases your online protection Contents Introduction to Web Reputation 3 Why use Web Reputation? 3 The value of using Web Reputation and antivirus software 3 The value
A to Z Information Services stands out from the competition with CA Recovery Management solutions
Customer success story October 2013 A to Z Information Services stands out from the competition with CA Recovery Management solutions Client Profile Industry: IT Company: A to Z Information Services Employees:
Social networking at work: Thanks, but no thanks?
GFI White Paper Social networking at work: Thanks, but no thanks? Millions of people around the world with access to the Internet are members of one or more social networks. They have a permanent online
Patch management with GFI LanGuard and Microsoft WSUS
GFI White Paper Patch management with GFI LanGuard and Microsoft WSUS A cost-effective and easy solution for network-wide patch management This white paper provides an overview of how to use GFI LanGuard
Network Security Report:
Network Security Report: The State of Network Security in Schools Managing tight budgets. Complying with regulatory requirements. Supporting Internet-based learning technologies. There are many challenges
PCI Policy Compliance Using Information Security Policies Made Easy. PCI Policy Compliance Information Shield Page 1
PCI Policy Compliance Using Information Security Policies Made Easy PCI Policy Compliance Information Shield Page 1 PCI Policy Compliance Using Information Security Policies Made Easy By David J Lineman
Product comparison. GFI LanGuard 2014 vs. Microsoft Windows Server Update Services 3.0 SP2
Product comparison GFI LanGuard 2014 vs. Microsoft Windows Server Update Services 3.0 SP2 General features GFI LanGuard 2014 Microsoft WSUS 3.0 SP2 Scheduled scans Agent-less r Agent-based Integration
My Docs Online HIPAA Compliance
My Docs Online HIPAA Compliance Updated 10/02/2013 Using My Docs Online in a HIPAA compliant fashion depends on following proper usage guidelines, which can vary based on a particular use, but have several
HIPAA Security Matrix
HIPAA Matrix Hardware : 164.308(a)(1) Management Process =Required, =Addressable Risk Analysis The Covered Entity (CE) can store its Risk Analysis document encrypted and offsite using EVault managed software
Mobile Banking Service Agreement (Addendum to your Primary Online Banking Service Agreement)
Mobile Banking Service Agreement (Addendum to your Primary Online Banking Service Agreement) I. INTRODUCTION PARTIES AND DEFINITIONS This Mobile Banking Service Agreement (as amended from time to time,
Projectplace: A Secure Project Collaboration Solution
Solution brief Projectplace: A Secure Project Collaboration Solution The security of your information is as critical as your business is dynamic. That s why we built Projectplace on a foundation of the
