Dropbox for Business. Secure file sharing, collaboration and cloud storage. G-Cloud Service Description



Similar documents
Dropbox for Business security A Dropbox whitepaper

Box: Redefining Security for the Cloud

Ensuring Enterprise Data Security with Secure Mobile File Sharing.

Security Overview Enterprise-Class Secure Mobile File Sharing

White Paper. Anywhere, Any Device File Access with IT in Control. Enterprise File Serving 2.0

Dropbox for Business security A Dropbox whitepaper

ShareSync from LR Associates Inc. A business-grade file sync and share service that meets the needs of BOTH users and administrators.

Dropbox Business security A Dropbox whitepaper

Access All Your Files on All Your Devices

Google Identity Services for work

Using Dropbox with Amicus Attorney. (Presentation Notes) Full Presentation & Video using-amicus-attorney-with-dropbox

MAXIMUM DATA SECURITY with ideals TM Virtual Data Room

Shafiq Khan. An Introduction to. Cloud Computing 13/12/2012

Enterprise Private Cloud Storage

Egnyte Cloud File Server. White Paper

Powered by. FSS Buyer s Guide Why a File Sync & Sharing Solution is Critical for Your Business

E-Guide SIX ENTERPRISE CLOUD STORAGE AND FILE-SHARING SERVICES TO CONSIDER

Security Information & Policies

Cloud Computing for Education Workshop

An Enterprise Approach to Mobile File Access and Sharing

ShareFile Security Overview

Cloud Store & Share Frequently Ask Questions

SCOPE OF SERVICE Hosted Cloud Storage Service: Scope of Service

Virtual Data Room. From Deal Making to Due Diligence

FilesAnywhere Feature List

Data Storage That Looks at Business the Way You Do. Up. cloud

Nasuni Management Console Guide

Welcome to Sookasa. Getting Started Guide for SafeMonk users

An Enterprise Approach to Mobile File Access and Sharing

owncloud Architecture Overview

Mobile App User's Guide

2013 USER GROUP CONFERENCE

Overview. Timeline Cloud Features and Technology

ONLINE ACCOUNTABILITY FOR EVERY DEVICE. Quick Reference Guide V1.0

Symantec Enterprise Vault.cloud Overview

Securing Content: The Core Currency of Your Business. Brian Davis President, Net Generation

Dell World Software User Forum 2013

Administration Guide. WatchDox Server. Version 4.8.0

For example some Bookkeepers are using Dropbox to share the accounting files between them and their client.

Secure file sharing and collaborative working solution

Utilizing Dropbox to Share Files

This paper introduces the security policies, practices, and procedures at Smartsheet.

DroboAccess User Manual

Get Started Guide for Admins

Increase the Security of Your Box Account With Single Sign-On

USER GUIDE CLOUDME FOR WD SENTINEL

This white paper from Stylusinc describes how enterprises benefits by migrating to Microsoft Office 365 and how it is bringing about a sea change in

Top. Reasons Federal Government Agencies Select kiteworks by Accellion

Features of AnyShare

ACCESSING MICROSOFT OFFICE 365 FREE STUDENT RESOURCES

Cloud storage buyer s guide

Storage Made Easy. Cloud File Server Overview

Data Storage that Looks at Business the Way You Do. Up. cloud

UNCLASSIFIED. UK Archiving powered by Mimecast Service Description

Symantec Enterprise Vault.cloud Overview

G-Cloud Service Definition. Canopy Remote Backup for Cloud SaaS

Microsoft Windows Intune: Cloud-based solution

Tableau Online Security in the Cloud

Personal Cloud. Support Guide for Mac Computers. Storing and sharing your content 2

Business and enterprise cloud sync, backup and sharing solutions

How To Use Attix5 Pro For A Fraction Of The Cost Of A Backup

How To Use Egnyte

Top Five Ways Any Business Can Benefit from Box

Security Considerations

Soonr Workplace Enterprise Plan Overview

Autodesk Streamline Achieve maximum project visibility.

Anchor End-User Guide

Mobile Mobile Security COPYRIGHT 2014 INTUITION ALL RIGHTS RESERVED. Copyright 2014 Intuition

Hosted SharePoint. OneDrive for Business. OneDrive for Business with Hosted SharePoint. Secure UK Cloud Document Management from Your Office Anywhere

getting started with box 1. What is box? 2. Creating an account 3. box functions

activecho Driving Secure Enterprise File Sharing and Syncing

activecho Frequently Asked Questions

Comparing Alternatives for Business-Grade File Sharing. intermedia.net CALL US US ON THE WEB

SAP Cloud Identity Service Document Version: SAP Cloud Identity Service

Legalesign Service Definition Electronic signature and contract management service

Mobile App User's Guide

Investor Newsletter. SMEStorage Open Cloud File Server Unify, Govern, and Manage your files. Cloud File Server Overview

User Guide. Version R91. English

Evaluation criteria for Google Apps backup

HOW HOSTED EXCHANGE COMPARES WITH GOOGLE APPS

BUILT FOR YOU. Contents. Cloudmore Exchange

User Management Tool 1.5

Top. Reasons Legal Firms Select kiteworks by Accellion

WHITE PAPER NEXSAN TRANSPORTER PRODUCT SECURITY AN IN-DEPTH REVIEW

eztechdirect Backup Service Features

WatchDox Administrator's Guide. Application Version 3.7.5

YOUR SECURE ONLINE VAULT. DSWISS AG BADENERSTRASSE 281 CH-8003 ZURICH

SHARPCLOUD SECURITY STATEMENT

Comparing Box and Egnyte. White Paper

Back it up. Get it back. Simple.Secure.Affordable.

Directory Integration with Okta. An Architectural Overview. Okta Inc. 301 Brannan Street San Francisco, CA

Service Overview CloudCare Online Backup

Azeus Convene Paperless Board and EXECUTIVE Meetings

Harnessing the power of Google Apps

What is OneDrive for Business?

MassTransit vs. FTP Comparison

BYOD File Sharing Go Private Cloud to Mitigate Data Risks

A. The Treeno Data Center maintains audited advanced security systems equal to the most sophisticated systems of large corporations.

IDrive, is a service offered by Pro Softnet Corporation, an ASP and Internet Solutions Provider, based in Woodland Hills, CA.

RSS Cloud Solution COMMON QUESTIONS

Transcription:

Dropbox for Business Secure file sharing, collaboration and cloud storage G-Cloud Service Description

Table of contents Introduction to Dropbox for Business 3 Security 7 Infrastructure 7 Getting Started 9 Service Management 11 Ordering & Invoicing 12 2

Introduction Dropbox is a service millions of users trust to easily and reliably store, sync, and share documents, photos, and videos across any device or platform. With Dropbox for Business, we ve brought that same simplicity to the workplace, with advanced features that help teams share instantly across their organizations and that enable employees to collaborate quickly and efficiently. But more than just an easy-to-use tool, we ve designed Dropbox for Business to keep your important work files secure and to provide administrators with the control and visibility they need. To do this, we ve created a sophisticated infrastructure onto which account administrators can layer and customise policies of their own. The secure home for all your work Dropbox for Business lets your team bring work anywhere, syncing their important files across all their devices. Powerful admin tools help you stay on top of your organisation s information. Shared folders and links help keep everyone up to date, effortlessly. With Dropbox, team members can work together like they re sitting right next to each other even when they re halfway around the world. 3

Get up and running Manage your organisation s accounts centrally with Dropbox for Business, and transfer files to co-workers when people leave. Centralise administration Let your team focus on work the admin console gives you one place to easily add or remove members, change team settings, and centralise billing. Member sign-ins Third-party Apps Admin actions Attempted sign-ins Linked Devices Team members Password changes Sharing events Gain visibility Keep tabs on how your team s using Dropbox for Business and what s being shared. Filter by specific actions and generate activity reports from the admin console. Simplify provisioning Dropbox has partnered with trusted identity providers so you can use your existing onboarding and authentication processes. 4

Better collaboration and productivity Share with just a click Forget zipping a large file to send as an email attachment. When you link to the file in Dropbox, clients can view or download the latest version in seconds. You can also create groups* to make sharing with the multiple people at the same time even easier. Give the right people the right access Dropbox for Business gives you control over permissions to shared folders and links, and lets you restrict members from sharing outside your team. You can also set limits on who can view or edit files within a shared folder, and protect shared links with passwords and expirations. Simplify your workflow Don t waste time tracking down the right files. Full-text search lets you quickly find what you need by typing any word contained in a file. And with Project Harmony*, see who s working on a shared Microsoft Office file and more from within the document. Safeguard company data We store your file data using 256-bit AES encryption, and SSL/ TLS creates a secure tunnel to transfer file data between you and us. Protect business data If a device is lost or someone leaves your team, remotely delete the Dropbox folder to keep your business s most important data safe. Further protect data with the ability to disable shared links from the admin console. Manage compliance Dropbox, our data centres, and our managed service provider undergo regular third-party audits. Reports are available for our ISO 27001 certificate as are our SOC 1, SOC 2, and SOC 3 audits. Dropbox is also a member of CSA s Security, Trust & Assurance Registry (STAR). Guard user accounts Put a trusted identity provider in charge of authentication with single sign-on (SSO), and add an additional layer of protection via twostep verification. Please note: Project Harmony and Groups are beta features. Timing and exact functionality may change from what's shared here and Dropbox does not provide warranties on the performance of these features. 5

Maintain privacy Our privacy policy is designed to safeguard the collection, use, and disclosure of your business information, and we comply with the U.S. E.U. and U.S. Swiss Safe Harbor frameworks. Put data in its place Let every employee access both a personal and a work Dropbox, while keeping them separate on all their devices. Get reliable access Keep your work available with storage designed for 99.999999999% durability. Enterprise solutions With the Dropbox for Business API, customers can extend the power of the Dropbox Platform with their existing enterprise applications. The API allows for powerful Security & Administration solutions to integrate directly with Dropbox for Business to allow for additional capabilities around: Identity Management Security Information and Event Management Data Loss Prevention Content Protection & DRM ediscovery & Legal hold Data Migration Build your own custom workflow 6

Security Dropbox s easy-to-use interfaces are backed by an infrastructure working behind the scenes to ensure fast, reliable uploads and downloads. To make this happen, we re continually evolving our product and architecture to speed data transfer, improve reliability, and adjust to changes in the environment. Dropbox is designed with multiple layers of protection, covering data transfer, encryption, network configuration, and application-level controls, all distributed across a scalable, secure infrastructure. Dropbox users can access files and folders at any time from the desktop, web, and mobile clients, or through third-party applications connected to Dropbox. All of these clients connect to secure servers to provide access to files, allow file sharing with others, and update linked devices when files are added, changed or deleted. 7

The components of our architecture include: Encryption and application service This service handles all processing for the Dropbox applications. Each file is split into blocks, and each block is hashed and encrypted using a strong cipher. Only blocks that have been modified are synced. When a change is made, new or modified blocks are processed and transferred to the storage service. Storage service The actual contents of users files are stored in encrypted blocks with this service. Each individual encrypted file block is retrieved based on its hash value, and an additional layer of encryption is provided for all file blocks at rest using a strong cipher. Metadata service Basic information about user data (including file names and types), called metadata, is kept in its own discrete storage service separate from file blocks. This metadata acts as an index for data in users accounts, and is sharded and replicated as needed to meet performance and high availability requirements. Notification service This is a separate service dedicated to monitoring if changes have been made to Dropbox accounts. No file data or metadata is stored or transferred here. Instead, clients establish a long poll connection to this service and wait for a change, which then signals a change to the relevant clients. Compliance. Dropbox, our data centres, and our managed service provider undergo regular third-party audits (e.g., ISAE 3402 - SOC 1 Type II, SOC 2 Type II, and ISO 27001 - ISO/IEC 27001:2013 standard), and our SOC 1, 2 and 3 reports are available for review. As merchants, Dropbox and our payment providers are PCI DSS compliant. Dropbox is also certified and complies with the US-EU and US-Swiss Safe Harbor frameworks. 8

Reliability A storage system is only as good as it is reliable, and to that end, we ve developed Dropbox with multiple layers of redundancy to guard against data loss and ensure availability. Redundant copies of metadata are distributed across independent devices within a data centre in an N+2 availability model. Hourly incremental and daily full backups are performed on all metadata. Dropbox file block storage uses systems including third-party providers that are designed to provide 99.9999999999% durability. In the event of a failed connection to Dropbox s service, a client will gracefully resume operation when a connection is re-established. Files will only be updated on the local client if they have synchronized completely and successfully validated with the Dropbox service. Load balancing across multiple servers ensures redundancy and a consistent synchronization experience for the end user. Getting started Users can be provisioned, managed and de-provisioned in a number of different ways: Email invitation. A tool in the Dropbox for Business admin console allows administrators to manually generate email invitations. Active Directory. Dropbox for Business administrators can automate the creation and removal of accounts from an existing Active Directory system. Once integrated, Active Directory can be used to manage membership. Single sign-on (SSO). Dropbox for Business can be configured to allow team members access by signing into a central identity provider. Our SSO implementation, which uses Security Assertion Markup Language version 2.0 (SAML 2.0), makes life easier and more secure by placing a trusted identity provider in charge of authentication and giving team members access to Dropbox without an additional password to manage. Sharing permissions. Dropbox for Business account administrators can control whether team members are able to share items with people outside the team, and set different rules for shared folders and shared links. If sharing outside the team is enabled, members will still be able to make individual folders or links team only as needed. 9

Password reset. As a proactive security measure, admins can reset passwords for the entire team or on a per-user basis. Web sessions. Active browser sessions can be tracked and terminated from both the admin console and individual users account settings. App access. Admins have the ability to view and revoke third-party app access to user accounts. Remote wipe + Device unlinking. Computers and mobile devices connected to user accounts can be unlinked by the admin, through the admin console or the user through individual account security settings. On computers, unlinking removes authentication data and provides the option to delete local copies of files the next time the computer comes online. On mobile devices, unlinking removes files marked as favourites, cached data, and login information. If two-step verification is enabled, users must re-authenticate any device upon relinking. Additionally, users account settings provide the option to send a notification email automatically when any devices are linked. Account transfer. After de-provisioning a user (either manually or via directory services), admins can transfer files from that user s account to another user on the team. Two Dropboxes. Each user can choose to connect a personal and a work Dropbox across all devices to enable clear separation of personal and business data. Admins can enable or block desktop client access to this feature for team members. Version History. Dropbox for Business users have unlimited version history and can access any deleted and previous file versions. Training. All Dropbox for Business users have access to our user and administrator guides, priority support, and extensive Account team coverage. In addition, users can access our community forum for additional product assistance. 14-day free trial. All customers evaluating Dropbox for Business can sign up for a free 14-day trial by visiting www.dropbox.com/business/try 10

Service migration. As part of onboarding, existing basic or Pro Dropbox users are asked to specify if pre-existing data should move to a new personal account or work Dropbox account. The Dropbox for Business API also allows administrators to import existing data from files servers and other cloud storage providers or perform on-site backups. System Requirements. Dropbox is available on: Windows, Mac OSX, and Linux operating systems Internet Explorer, Google Chrome, Safari, Firefox, and Opera iphone, Android, and Blackberry Please refer to www.dropbox.com/help to find the most up-to-date list of recommended system requirements. Service Management Service Constraints. Dropbox strives for 100% uptime and availability. Rest assured that even if the Dropbox service is down, you could still access your files from the Dropbox folder on your computer. Any Dropbox service downtime only affects syncing and online access. When Dropbox syncs, it copies files stored on your hard drive so that your files will always be accessible even when Dropbox is down or when you are offline. If you would like to receive Dropbox service announcements by email ahead of any scheduled downtime, administrators can choose to opt in from their account settings page. Additionally, we always keep users updated about possible bouts of downtime through the Dropbox forums and our Twitter feed. 11

Customization. Customers who are interested in developing their own applications and custom workflows can do so via the Dropbox for Business API, which allows applications to both manage the user lifecycle for a Dropbox for Business account and perform Core API (information access, auditing, file access) actions on all members of a team. We provide programmatic access to Dropbox for Business administrator functionality, specifically the Dropbox for Business audit log and team usage statistics. Additionally, there are 300,000+ existing third-party applications to integrate and customize the Dropbox experience. Service Level Agreements. Dropbox provides specific SLAs in custom business agreements. Please inquire with the appropriate Dropbox contact to see if your team meets the minimum requirements for a custom business agreement. Ordering and invoicing Ordering Process. To sign up for Dropbox for Business, administrators should go to our website or contact an Account Executive. We will work with your team to complete the invoicing process. Customers are invoiced either on a monthly basis via credit / debit card or on an annual basis via credit / debit card or bank wire with net 30 payment terms. Service Pricing. Dropbox for Business requires a minimum of 5 users and costs 77.00 per user per year or 7.70 per user per month. This allows for as much storage space as you need and all business features outlined above. Termination terms. If for any reason you need to downgrade or cancel your subscription please contact us using the information on your Business account page, and we ll take care of this for you. Business accounts are provided a 30-day refund policy (if on an annual plan). Downgrading to a smaller Dropbox won't delete any of the files already there. Please be aware that Dropbox will not delete any of your files when your subscription is downgraded. If downgrading causes your account to go over quota, all that should happen is that your file syncing between connected devices will stop. You will not be able to add any new files to your Dropbox or restore any files removed from your Dropbox until there is enough free space in your available quota to do so. 12