State of Wisconsin DET File Transfer Protocol Service Offering Definition (FTP & SFTP)
Document Revision History Date Version Creator Notes File Transfer Protocol Service Page 2 7/7/2011
Table of Contents Introduction... 4 What Is Included... 4 What Is Not Included... 4 Benefits... 5 Service Description... 5 Service Period... 6 Roles and Responsibilities... 6 Business Continuity... 6 Performance Metrics (Monitoring & Alerting)... 6 How Services Are Charged... 6 File Transfer Protocol Service 3 7/7/2011
Introduction Enterprise File Transfer Protocol (FTP) Service File Transfer Protocol (FTP) is a standard network protocol used to copy files from one host to another over a TCP/IP based network. FTP is built on a client-server architecture and utilizes separate control and data connections between server and client. FTP can provide anonymous file access or can limit file access with user-based password authentication. The FTP file transfer protocol can be used to augment email attachments when file size exceeds attachment limits. This service consists of a secure, centralized server to send and receive files between state agencies, county and local governments, other business partners, and the public. The Division of Enterprise Technology (DET) manages software installation and configuration, provisioning IAM accounts for FTP access, creating and managing certificates and key pairs, support for the FTP environment, assisting agencies with SSL or SSH issues, managing the OS directory structure and system level performance, and establishing and maintaining the first three levels of folder structure. What Is Included FTP transfer services Server hardware and software to enable file transfers using the customer s FTP client software. Establishing agency folder structure. User account management and support. Server hardware and OS support server support as defined by the Agency Managed Application Service (AMAS) Service Offering Definition (SOD). Ability to enforce encrypted access and transfer via Secure File Transfer Protocol (SFTP) or File Transfer Protocol Secure Socket Layer (FTPS). Standard backup and recovery of the server operating system (OS), and FTP server application using DET s standard backup/recovery software. Maintenance and installation of infrastructure components depending upon the selected configuration. This includes the operating system, software patching, product upgrades, and security fixes. Monitoring of the servers (up/down status and other system services). What Is Not Included Shared password or group IDs. Management or support of FTP client software. Notification of FTP activity or batch job completion (available by request and additional fees might apply). Customer product user training. Management, backup, recovery, or archive of customer data files. File Transfer Protocol Service 4 7/7/2011
Benefits Secure transfers over an internal network or the Internet. Ability to handle files larger than email attachment limitations. Open or secure file access for state agencies, county and local governments, business partners, and the public. Encrypted file transfer options. Service Description The Enterprise FTP service provides state agencies, county and local governments, and other business partners the ability to securely transfer and share files. DET manages software installation and configuration, provisioning IAM accounts for FTP access, creating and managing certificates and key pairs, support for the FTP environment, assisting agencies with SSL or SSH issues, managing the OS directory structure and system level performance, and establishing and maintaining the first three levels of folder structure. Agency Security Officers are responsible for managing appropriate use of assigned FTP resources, notifying DET of any necessary account deletions, and security breaches involving the use and storage of account credentials, by following the normal support process notifying the Enterprise Service Desk and creating a service request or problem ticket. The installation, management, documentation, training, and use of FTP client software are the responsibility of each agency. Account Types There are four types of accounts that users may have set up, depending on access and/or security requirements for the files: 1. Anonymous access account. 2. Semi-anonymous access (requires user name). 3. Secure access on the state network using specific account credentials. 4. Secure access from the Internet using account credentials, stored in the FTP server software. Encrypted Transfer Customers may require the files they transfer be further secured using encryption to ensure that sensitive information is not compromised. The File Transfer Protocol provides two formats for encryption, SFTP (preferred) or FTPS. To use these encryption formats, the customer must have FTP client software with encryption capability. File Types and Sizes Any file type or format can be transferred via FTP. File Transfer Protocol Service 5 7/7/2011
While there is no file size limit, very large files sizes may exceed the system s timeout restriction. The current default transfer timeout is 10 minutes; however can be increased if necessary. There are factors that can impact the speed of the file transfer, including network traffic, individual computer throughput, connection speed, etc. Service Offering Review The FTP SOD will be reviewed annually to determine if any modifications are required. Roles and Responsibilities Roles and Responsibilities for the Enterprise FTP service can be found here Business Continuity The Enterprise FTP server is a single server and there is no provision for fail over at this time. Performance Metrics (Monitoring & Alerting) The FTP servers are monitored by DET s Enterprise monitoring tool for events such as server disk space, CPU, and memory use. There is also monitoring for the up/down status and selected services that run on this server. Should a problem arise with the FTP system, or server, the DET Enterprise monitoring tool sends an alert when an event s condition or threshold is near or has been met. This alert (either an email or auto generated problem ticket using DET s incident management tool) is used to engage DET technical staff so they can begin troubleshooting and resolution. How Services Are Charged FTP Services are billed monthly through the Enterprise Billing System (EBS) based on accounts authorized or created for access to the service for a particular agency. A Point of Fiscal Responsibility (PFR) use code will be billed for the agency and is required at the time the service is initiated through the service request process. File Transfer Protocol Service 6 7/7/2011