ESSS Vendor Evaluation Form WhiteCanyon Software



Similar documents
Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply

Identify Storage Technologies and Understand RAID

Cloud Services Frequently Asked Questions FAQ

Understand Business Continuity

HarePoint HelpDesk for SharePoint. For SharePoint Server 2010, SharePoint Foundation User Guide

VCU Payment Card Policy

9 ITS Standards Specification Catalog and Testing Framework

Diagnosis and Troubleshooting

Improved Data Center Power Consumption and Streamlining Management in Windows Server 2008 R2 with SP1

GUIDANCE FOR BUSINESS ASSOCIATES

Bitrix Intranet. Product Requirements

The Relativity Appliance Installation Guide

CSC IT practix Recommendations

Session 9 : Information Security and Risk

IN-HOUSE OR OUTSOURCED BILLING

Readme File. Purpose. Introduction to Data Integration Management. Oracle s Hyperion Data Integration Management Release 9.2.

Wireless Light-Level Monitoring

Presentation: The Demise of SAS 70 - What s Next?

expertise hp services valupack consulting description security review service for Linux

Process Automation With VMware

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013

UC4 AUTOMATED VIRTUALIZATION Intelligent Service Automation for Physical and Virtual Environments

Licensing Windows Server 2012 R2 for use with virtualization technologies

HIPAA Compliance 101. Important Terms. Pittsburgh Computer Solutions

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy

HP ExpertOne. HP2-T21: Administering HP Server Solutions. Table of Contents

efusion Table of Contents

Avatier Identity Management Suite

Installation Guide Marshal Reporting Console

SBClient and Microsoft Windows Terminal Server (Including Citrix Server)

In addition to assisting with the disaster planning process, it is hoped this document will also::

Installation Guide Marshal Reporting Console

HIPAA HITECH ACT Compliance, Review and Training Services

White Paper for Mobile Workforce Management and Monitoring Copyright 2014 by Patrol-IT Inc.

Electronic and Information Resources Accessibility Compliance Plan

Help Desk Level Competencies

service description Colocation of Equipment Infrastructure as a Service

BES12 Jumpstart Program Description ( Jumpstart Program Description )

Preparing to Deploy Reflection : A Guide for System Administrators. Version 14.1

Licensing Windows Server 2012 for use with virtualization technologies

McAfee Enterprise Security Manager. Data Source Configuration Guide. Infoblox NIOS. Data Source: September 2, Infoblox NIOS Page 1 of 8

AML Internet Manor Court, Manor Farm House, London Road, Derby, Derbyshire, DE72 2GR. Tel: Fax:

PROTIVITI FLASH REPORT

AvePoint Privacy Impact Assessment 1

POLICY 1390 Information Technology Continuity of Business Planning Issued: June 4, 2009 Revised: June 12, 2014

Using PayPal Website Payments Pro UK with ProductCart

Electronic Data Interchange (EDI) Requirements

Architecting HP Server Solutions

Process of Setting up a New Merchant Account

Configuring and Monitoring SysLog Servers

FOCUS Service Management Software Version 8.5 for Passport Business Solutions Installation Instructions

Citrix XenServer from HP Getting Started Guide

How To Install Fcus Service Management Software On A Pc Or Macbook

How To Set Up Call Hme On A Brcade Data Center Powerbook

Readme File. Purpose. What is Translation Manager 9.3.1? Hyperion Translation Manager Release Readme

Cisco IT Essentials v4.1. Course Overview. Total Hours: 240

Restricted Document. Pulsant Technical Specification

Delivering Business Value Through IT Cost Transparency Using IT CMF

Optimal Payments Extension. Supporting Documentation for the Extension Package v1.1

Serv-U Distributed Architecture Guide

Mobilizing Healthcare Staff with Cloud Services

State of Wisconsin. File Server Service Service Offering Definition

Service Level Agreement (SLA) Hosted Products. Netop Business Solutions A/S

How Does Cloud Computing Work?

CORE 8 to 9 Data Migration Guide

AHLA. C. Big Data, Cloud Computing and the New World Order for Health Care Privacy

Enterprise Security Management CIS 259

Implementing SQL Manage Quick Guide

Frequently Asked Questions: CMMI Data Collection

ViPNet VPN in Cisco Environment. Supplement to ViPNet Documentation

Business Intelligence represents a fundamental shift in the purpose, objective and use of information

WinFlex Web Single Sign-On (EbixLife XML Format) Version: 1.5

EA-POL-015 Enterprise Architecture - Encryption Policy

REQUEST FOR PROPOSAL FOR SHAREPOINT LEGISLATIVE MANAGEMENT SERVICES

UNIVERSAL MUSIC GROUP PRIVACY POLICY. Universal Music AB ("We") are committed to protecting and respecting your privacy.

Customer no.: enter customer no. Contract no.: enter contract no.

Using Shift4 with Magento

SaaS Listing CA Cloud Service Management

Corente Cloud Services Exchange (CSX) Corente Cloud Services Gateway Site Survey Form

Aladdin HASP SRM Key Problem Resolution

1.2 Supporting References For information relating to the Company Hardware Request project, see the SharePoint web site.

RedCloud Security Management Software 3.6 Release Notes

Software and Hardware Change Management Policy for CDes Computer Labs

Transcription:

WhiteCanyn Sftware U.S. Department f Veterans Affairs Office f Infrmatin and Technlgy Infrmatin Prtectin and Risk Management Field Security Operatins Enterprise Security Slutin Service Date f Meeting: May 30 th,2008 Meeting Lcatin: Attendees: U.S. Department f Veterans Affairs Central Office 810 Vermnt Ave. NW Washingtn, DC 20420 Perry Dllar & Kelly Yung

Requestr: Vendr/Address/Cntact Inf: Prduct r Slutin Name: WipeDrive Is this Hardware, Sftware, r Service? Hardware Slutin Descriptin: WipeDrive takes care f all cmpliance issues by prperly verwriting and fully dcumenting the secure deletin f all data frm cmputer systems and external media devices. WipeDrive is fully cmpliant with DD 5220.22-M, HIPAA, Sarbanes- Oxley, GLB and FACTA standards. What des this prduct d? WipeDrive 5 can wipe virtually every majr hardware architecture, including; x86 PPC SPARC AIX HPUX PwerPC Architecture WipeDrive creates detailed lgs f wipes perfrmed, including a hardware diagnstic, drive serial numbers, a descriptin f the wipe perfrmed, the data and time f the wipe, the length f the wipe, and mre. Lg frmats include.txt, cmma delimited, XML, and Certificate. WipeDrive is available in a Netwrk Versin, USB,.exe WipeDrive Enterprise is a netwrk-centric cncept that allws fr simultaneus sanitizing f multiple client machines. Platfrms include: 2

IDE SATA SCSI RAID FiberDrive NAS Hw will the prduct benefit the VA? WhiteCanyn Sftware ffers Federal, State, and Lcal gvernment agencies a standardized methd f sanitizing data frm strage media such as hard drives and external devices s that data recvery is impssible. WhiteCanyn Sftware realizes that strict gvernment regulatins apply t the dispsal r recycling f cmputer systems, s we develped an efficient, reliable, and cst effective tl t meet the needs f the Department f Veteran Affairs. We have a slid fundatin: WhiteCanyn prducts have been trusted by Federal, State, and Lcal Gvernment agencies since 1998. We cntinue t build scalable slutin fr secure data deletin. WhiteCanyn prduct design has been develped arund and custmized fr the needs f Gvernment Agencies. WhiteCanyn technlgy is accepted as a standard arund the wrld fr disk sanitizatin. WhiteCanyn has frensically tested its prducts fr validatin purpses making us the mst trusted sanitizatin tl n the market tday. Describe the Infrmatin Security Benefits/Needs f the Prduct/Slutin Our prducts are designed t meet the strict gvernment regulatins that apply t the dispsal f cmputer systems. Our gvernment apprved sftware takes the prper steps t eliminate the pssibility f data lss. WipeDrive takes care f all cmpliance issues t prperly verwrite and fully dcument the secure deletin f all data frm cmputers. Our tls are apprved and fully cmpliant with HIPAA, DD 5220.22M, Sarbanes-Oxley, GLB and FACTA standards. 3

Prduct Security Please describe the prcesses and plicies fr ensuring the security n yur prduct? We have extensive cntrls n the WipeDrive surce cde that has been independently evaluated by NIAP. Develpers have detailed backgrund checks prir t emplyment. Des yur prduct cllect r transmit sensitive infrmatin such as PII & PHI? Please describe/elabrate? N. N infrmatin is sent r transmitted t WhiteCanyn. Des yur prduct require changes t the firewall/security gateways? Please describe/elabrate? N. The lg files can be saved n the lcal netwrk. Des it meet FIPS 140-2? If Yes, what are the CERT Numbers? Cryptgraphy Our prducts are designed t meet the strict gvernment regulatins that apply t the dispsal f cmputer systems. Our gvernment apprved sftware takes the prper steps t eliminate the pssibility f data lss. WipeDrive takes care f all cmpliance issues t prperly verwrite and fully dcument the secure deletin f all data frm cmputers. Our tls are apprved and fully cmpliant with HIPAA, DD 5220.22M, Sarbanes-Oxley, GLB and FACTA standards. Is the NIST Certificatin Specific t the cmpany? If nt please describe the cert that is leveraged r licensed. Yes Is it HIPAA Cmpliant? Please describe/elabrate? Yes. WipeDrive is used thrughut the healthcare industry by cmpanies such as Humana, Merck, Pfizer, Blue Crss and thers, The sftware cmplies strictly with all HIPAA regulatins. 4

Des it meet SOX Requirements? Please describe/elabrate? Yes, WipeDrive meets all applicable SOX cmpliance standards. Des it meet FISMA Requirements? Please describe/elabrate? Yes, WipeDrive meets all applicable FISMA cmpliance standards. If the prduct des nt currently meet the described Security Standards, are there initiatives r plans t cmply? WipeDrive is and will cntinue t meet all applicable security standards where pssible. Please describe yur prduct using Keywrds r functinal categries. These Keywrds will be used fr prduct search criteria. Sanitize, dispsal, recycle, deletin, data remval, disk sanitizatin, wipe, clean, strage remval, sanitizatin Additinal Cmments: Our tls are apprved and fully cmpliant with HIPAA, DD 5220.22M, Sarbanes- Oxley, GLB and FACTA standards. WhiteCanyn is currently in the evaluatin prcess fr NIAP Certificatin. 5

The Next Sectin is t be cmpleted by the U.S. Gvernment/Veterans Affairs Prs: Supprts all types f hardware cnfiguratins and drive types. The sftware is simple t use and 100% effective. Cns: Cannt be used t wipe very ld Apple Systems. Recmmendatin: This prduct tested very well when cmpared t ther prducts. It was able t verwrite SAS RAID drives within a hst cmputer, wipe SATA, Laptp and ATA drives. The sftware was als set up as a PXE server and cleared the drive an any cmputer cnnected t the same netwrk. This prduct perfrmed withut errr n every test. Recmmend that it be placed n the apprved prducts list. Recmmender: P. Dllar Date: 6