Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionLast revisionBoth sides next revision | ||
security [2018_01_30 19:15] – [3 Data Security] steven | security [2024_03_19 21:09] – [See Also] steven | ||
---|---|---|---|
Line 1: | Line 1: | ||
+ | # Nasuni Access Anywhere Security | ||
+ | #### Updated on Mar 19, 2024 | ||
+ | Access Anywhere provides content collaboration, | ||
+ | ### See Also | ||
+ | * [[governance|]] | ||
+ | * [[compliance|Compliance Standards]] | ||
+ | * [[cloudappliance/ | ||
+ | * [[organisationcloud/ | ||
+ | * [[advisories/ | ||
- | ====== | + | Security |
+ | * [[: | ||
+ | * [[:2fa]] | ||
+ | * [[: | ||
+ | * [[: | ||
+ | * [[:geoip]] | ||
+ | * [[: | ||
+ | * [[: | ||
+ | * [[: | ||
+ | * [[: | ||
+ | * [[: | ||
+ | * [[: | ||
+ | * [[fips]] | ||
- | SME provides a SaaS and hybrid on-premise Cloud solution which provides unique Cloud federation, governance and management features. This section of the Wiki outlines the security that is inherent within the SME hosted and on-premise appliance. | + | ## Encryption |
- | ===== 1 Data Center ===== | + | HTTPS is configured by default for all users. |
+ | A commercial server that uses HTTPS must have a public key certificate issued that verifies the entity. The end-user can verify the entity by clicking on the HTTPS icon from the browser. | ||
+ | Clients should connect to the server using a URL that starts with HTTPS. (This is the default). | ||
- | {{:/ | + | Administrators should also connect to storage providers using HTTPS. For storage providers with a fixed endpoint including AWS S3, Azure, Google Cloud Storage the Access Anywhere server always uses HTTPS. |
- | For the hosted SaaS service SME uses multiple data centres in USA and Europe. All data centres are Tier IV facilities and are:\\ \\ USA: SSAE16 SOC1/2 compliant, have 24x7 armed security, facility surveillance, | + | ## Encryption - Data at Rest |
+ | Customer data is stored on storage services controlled by you. It is not stored on the appliance. | ||
- | ===== 2 On the wire security ===== | ||
+ | ## Encryption Algorithm | ||
+ | The Access Anywhere server can be used to encrypt data transmitted to any storage provider that is under management by the solution. The plarform uses [[http:// | ||
+ | * an initial Round Key addition | ||
+ | * Nr-1Rounds | ||
+ | * a final round. | ||
- | {{:/ | + | The chaining variable goes into the input and the message block goes into the Cipher Key. The likelihood of recovering a file that has been encrypted using our encryption is fairly remote. The most efficient key-recovery attack for Rijndael is exhaustive key search. The expected effort of exhaustive key search depends on the length of the Cipher Key and for a 16-byte key, 2127 applications of Rijndael; |
- | HTTPS can be configured for all users of the Cloud File Server Saas users and Appliance. HTTPS is an acronym | + | Any AES-256 decryption tool that supports the Rijndael cipher with 16 byte blocksizes |
+ | [[https:// | ||
- | ===== 3 Data Security ===== | + | See also [[https:// |
+ | ## Identity Authentication | ||
+ | Clients can be authenticated against the internal user database or any directory service. Nasuni Access Anywhere includes out of the box support for Microsoft Active Directory, and services that support LDAP and SAML. Once authenticated clients use the authentication token for the remainder of the session. | ||
+ | [[2fa| Two-factor authentication]] may also be required with the options of Google Authentication, | ||
- | {{:/ | + | Our staff has no way to access a password as it is stored encrypted. There is a means to access meta-data in the logs and database related to an account if a user requests help with a problem, and this is only ever used if a user requests us to look at a problem or issue with an account. Even so, this still requires an Administrator to authorise access, and it still does not grant any access to any encrypted passwords. |
- | Storage Made Easy can be used to encrypt data transmitted to any cloud that is mapped to a user personal, Cloud File Server, or Appliance account. SME uses [[http://en.wikipedia.org/wiki/ | + | If a storage provider supports |
- | * an initial Round Key addition | + | |
- | * Nr-1Rounds | + | |
- | * a final round. | + | |
- | The chaining variable goes into the input and the message block goes into the âCipher Key. The likelihood of recovering a file that has been encrypted using our encryption is fairly remote. The most efficient key-recovery attack for Rijndael is exhaustive key search. The expected effort of exhaustive key search depends on the length of the Cipher Key and for a 16-byte key, 2127 applications of Rijndael; | + | For more information see [[iam]]. |
- | Any AES-256 decryption tool that supports the Rijndael cipher with 16 byte blocksizes can be used to un-encrypt files. We also provide free desktop decryption tools for [[https:// | ||
- | The Wiki entry on encryption has further details. | + | ## Data Loss Protection |
+ | Documents can be securely shared in a number of ways: | ||
+ | * Documents can be encrypted on upload using 256 bit AES security. The private key is not stored on the platform and only known by the user. | ||
+ | * Private links can be created for documents and these can be combined with passwords to secure the document. | ||
+ | * Links can be set to be time expired and/or combined with private links and password for further additional document security. | ||
+ | * [[watermarking|Watermarks]] unique to each file preview or shared file download can be added to enable tracing back how a file was leaked. | ||
+ | * [[contentdiscovery|Content Discovery]] monitors documents for sensitive data which can generate an email, quarantine, or initiate a workflow. | ||
- | ===== 4 Authentication | + | ## Access Control |
+ | {{:/ | ||
+ | The platform supports Access Control Permissions at a Role, User, or folder level for shared folders. The Permissions can be taken from Active Directory / LDAP if single sign-on is being used. | ||
- | {{:/ | + | ## Restrict by IP Address |
- | Storage Made Easy username and passwords are stored in an encrypted fashion. User login is required in order to obtain a token for a session, which allows a user to access a specific Storage Made Easy resource without using a username and password each time. Once the token has been obtained, the user uses the token, that offers access | + | The platform supports |
+ | For more information see [[geoip]]. | ||
- | ===== 5 Document | + | ## Audit Security |
+ | {{:/ | ||
+ | All file events that occur when using Access Anywhere are recorded. | ||
- | {{:/security: | + | Reports can be accessed online, archived, and also exported as .cvs or excel files or the audit events can be configured to be output in syslog format so that log aggregators such as Splunk can be used to monitor |
- | Documents can be securely shared using the SME platform in a number of ways: | ||
- | * Documents can be encrypted on upload using 256 bit AES security. The private key is not stored on the platform and only known by the user. | ||
- | * Private links can be created for documents and these can be combined with passwords to secure the document. | ||
- | * Links can be set to be time expired and/or combined with private links and password for further additional document security. | ||
+ | ## Governance Options | ||
- | ===== 6 Access Control Security ===== | + | {{ : |
+ | There are comprehensive governance / compliance / security options which can be configured by an Administrator. | ||
+ | ## Acceptable Use Policies | ||
- | {{:/ | + | Acceptable use policies allow organizations to present policies and optionally required acceptance for access to the system. Policy acceptance is logged and can also be required by users downloading shared files and folders. |
- | SME supports Access Control Permissions at a Role, User, or folder level for shared folders. The Permissions can be taken from Active Directory if single sign-on is being used. | + | {{: |
+ | See [[cloudappliance/ | ||
- | ===== 7 Audit Security ===== | + | ## Bring your own Device security |
+ | The Administrator controls which devices and access clients that each user can connect from. By default all devices and access clients are enabled. | ||
- | {{:/ | + | The Admin can entirely disable a user or just choose to disable |
- | + | ||
- | SME Cloud File Server SaaS or Appliance users have access | + | |
- | ===== 8 Governance Options ===== | + | ## Compliance Report |
+ | The compliance report recommends settings that could be changed to enhance security. The user can jump from the online report directly to where the setting can be changed. | ||
+ | {{ : | ||
- | {{:/ | + | ## Data Security |
- | Cloud File Server Saas and Appliance users can set governance options | + | In addition to encryption the solution includes a number of features |
+ | * **Trash** - Folders and files that are updated or deleted are saved in trash and can be restored. | ||
- | ===== 9 Bring your own Device security ===== | + | * **Versions** - Unlimited or limited versions of files can be saved. |
+ | * **Disaster Recovery** - The [[foreverfile|ForeverFile™ archive]] is a backup, disaster recovery and ransomware protection feature that continuously protects data, wherever it is stored. For each primary storage provider that is being protected, a separate secondary or Backup provider is configured. For maximum availability the backup cloud should be located in another data center. It could also be with different cloud vendor, storage technology or tier. | ||
+ | * **Antivirus** - See [[antivirus]]. | ||
- | {{:/ | + | ## Product Design and Testing |
- | The Cloud File Server (CFS) Admin controls which devices and access clients that each user of the Cloud File Server can connect from. By default all devices | + | The platform is developed using the OWASP principle |
+ | Our own hosted service, which features the latest iteration of bug fixes and features, is security tested daily. | ||