WhiteCanyn Sftware U.S. Department f Veterans Affairs Office f Infrmatin and Technlgy Infrmatin Prtectin and Risk Management Field Security Operatins Enterprise Security Slutin Service Date f Meeting: May 30 th,2008 Meeting Lcatin: Attendees: U.S. Department f Veterans Affairs Central Office 810 Vermnt Ave. NW Washingtn, DC 20420 Perry Dllar & Kelly Yung
Requestr: Vendr/Address/Cntact Inf: Prduct r Slutin Name: WipeDrive Is this Hardware, Sftware, r Service? Hardware Slutin Descriptin: WipeDrive takes care f all cmpliance issues by prperly verwriting and fully dcumenting the secure deletin f all data frm cmputer systems and external media devices. WipeDrive is fully cmpliant with DD 5220.22-M, HIPAA, Sarbanes- Oxley, GLB and FACTA standards. What des this prduct d? WipeDrive 5 can wipe virtually every majr hardware architecture, including; x86 PPC SPARC AIX HPUX PwerPC Architecture WipeDrive creates detailed lgs f wipes perfrmed, including a hardware diagnstic, drive serial numbers, a descriptin f the wipe perfrmed, the data and time f the wipe, the length f the wipe, and mre. Lg frmats include.txt, cmma delimited, XML, and Certificate. WipeDrive is available in a Netwrk Versin, USB,.exe WipeDrive Enterprise is a netwrk-centric cncept that allws fr simultaneus sanitizing f multiple client machines. Platfrms include: 2
IDE SATA SCSI RAID FiberDrive NAS Hw will the prduct benefit the VA? WhiteCanyn Sftware ffers Federal, State, and Lcal gvernment agencies a standardized methd f sanitizing data frm strage media such as hard drives and external devices s that data recvery is impssible. WhiteCanyn Sftware realizes that strict gvernment regulatins apply t the dispsal r recycling f cmputer systems, s we develped an efficient, reliable, and cst effective tl t meet the needs f the Department f Veteran Affairs. We have a slid fundatin: WhiteCanyn prducts have been trusted by Federal, State, and Lcal Gvernment agencies since 1998. We cntinue t build scalable slutin fr secure data deletin. WhiteCanyn prduct design has been develped arund and custmized fr the needs f Gvernment Agencies. WhiteCanyn technlgy is accepted as a standard arund the wrld fr disk sanitizatin. WhiteCanyn has frensically tested its prducts fr validatin purpses making us the mst trusted sanitizatin tl n the market tday. Describe the Infrmatin Security Benefits/Needs f the Prduct/Slutin Our prducts are designed t meet the strict gvernment regulatins that apply t the dispsal f cmputer systems. Our gvernment apprved sftware takes the prper steps t eliminate the pssibility f data lss. WipeDrive takes care f all cmpliance issues t prperly verwrite and fully dcument the secure deletin f all data frm cmputers. Our tls are apprved and fully cmpliant with HIPAA, DD 5220.22M, Sarbanes-Oxley, GLB and FACTA standards. 3
Prduct Security Please describe the prcesses and plicies fr ensuring the security n yur prduct? We have extensive cntrls n the WipeDrive surce cde that has been independently evaluated by NIAP. Develpers have detailed backgrund checks prir t emplyment. Des yur prduct cllect r transmit sensitive infrmatin such as PII & PHI? Please describe/elabrate? N. N infrmatin is sent r transmitted t WhiteCanyn. Des yur prduct require changes t the firewall/security gateways? Please describe/elabrate? N. The lg files can be saved n the lcal netwrk. Des it meet FIPS 140-2? If Yes, what are the CERT Numbers? Cryptgraphy Our prducts are designed t meet the strict gvernment regulatins that apply t the dispsal f cmputer systems. Our gvernment apprved sftware takes the prper steps t eliminate the pssibility f data lss. WipeDrive takes care f all cmpliance issues t prperly verwrite and fully dcument the secure deletin f all data frm cmputers. Our tls are apprved and fully cmpliant with HIPAA, DD 5220.22M, Sarbanes-Oxley, GLB and FACTA standards. Is the NIST Certificatin Specific t the cmpany? If nt please describe the cert that is leveraged r licensed. Yes Is it HIPAA Cmpliant? Please describe/elabrate? Yes. WipeDrive is used thrughut the healthcare industry by cmpanies such as Humana, Merck, Pfizer, Blue Crss and thers, The sftware cmplies strictly with all HIPAA regulatins. 4
Des it meet SOX Requirements? Please describe/elabrate? Yes, WipeDrive meets all applicable SOX cmpliance standards. Des it meet FISMA Requirements? Please describe/elabrate? Yes, WipeDrive meets all applicable FISMA cmpliance standards. If the prduct des nt currently meet the described Security Standards, are there initiatives r plans t cmply? WipeDrive is and will cntinue t meet all applicable security standards where pssible. Please describe yur prduct using Keywrds r functinal categries. These Keywrds will be used fr prduct search criteria. Sanitize, dispsal, recycle, deletin, data remval, disk sanitizatin, wipe, clean, strage remval, sanitizatin Additinal Cmments: Our tls are apprved and fully cmpliant with HIPAA, DD 5220.22M, Sarbanes- Oxley, GLB and FACTA standards. WhiteCanyn is currently in the evaluatin prcess fr NIAP Certificatin. 5
The Next Sectin is t be cmpleted by the U.S. Gvernment/Veterans Affairs Prs: Supprts all types f hardware cnfiguratins and drive types. The sftware is simple t use and 100% effective. Cns: Cannt be used t wipe very ld Apple Systems. Recmmendatin: This prduct tested very well when cmpared t ther prducts. It was able t verwrite SAS RAID drives within a hst cmputer, wipe SATA, Laptp and ATA drives. The sftware was als set up as a PXE server and cleared the drive an any cmputer cnnected t the same netwrk. This prduct perfrmed withut errr n every test. Recmmend that it be placed n the apprved prducts list. Recmmender: P. Dllar Date: 6