Science Interactive Group Knowledgebase

Useful Pre-Adoption IT Questions

Updated on

Below are answers to common questions that arise while an institution is in negotiations to adopt our platform.

Questions not covered here should be directed towards the IT department.

Data Security and Access

Expand or collapse content Do you conduct network penetration tests of your cloud service infrastructure regularly as prescribed by industry best practices and guidance? Do you contract an expert third party company to provide this service?

NO.

Expand or collapse content What information security protections\technologies and procedures do you have in production to protect the Confidentiality, Integrity and Availability of customer data that is stored and processed by your solution?

IN PROGRESS: FIREWALLS, ROUTINE PATCH MANAGEMENT, SECURITY POLICIES.

Expand or collapse content Do you have capability to recover data for a specific customer in the case of a failure or data loss? What is your customer data retention and restore policy?

IN DEVELOPMENT. RELEASE PLANNED FOR Q2  TO INCLUDE DAILY BACKUPS AND REDUNDANT STORAGE

Expand or collapse content Please describe any access controls and/or ways in which you will limit or restrict unauthorized changes (such as additions or deletions) to personal information. For example: use of firewalls, document encryption, or user access profiles assigned on a need-to-know basis.

SONICWALL FIREWALL APPLIANCES PROVIDE PERIMETER PROTECTION.

Expand or collapse content Please describe how you track who has access to the personal information. For example:  audit trails or physical sign-in and sign-out of files.

OUR CRM AND ERP HAVE USER TRACKING IF NEEDED. WE DON’T DO THIS AS A STANDARD PROCESS BUT THE INFORMATION CAN BE MADE AVAILABLE.

Expand or collapse content Do you encrypt customer data at rest (on disk/storage/database)?

NO.

Expand or collapse content Is customer data encrypted in transit within your environment? Please explain your customer data encryption technologies.

HTTPS FROM CLOUD TO ERP. INFORMATION IS NOT EXCHANGED OUTSIDE OF THE ERP.

Expand or collapse content Do you use, sell or commoditize any customer data stored in its tenant or customer profile metadata?

NO.

Expand or collapse content Do you outsource to any downstream vendor partners to host your solution?

AWS AND GOOGLE.

Expand or collapse content Do you select and monitor outsourced providers in compliance with laws in the country where the data is processed, stored and transmitted?

NO.

Expand or collapse content Upon contract expiry how will the institution obtain a copy of all owned data and identity records in the original format that is stored and processed by your solution. If the institution does not require any data to be exported, please explain your customer data sanitation procedures.

TBD AS PART OF CONTRACT NEGOTIATION.

Expand or collapse content Are all of the servers, databases and connected services\applications hosted on AWS, Google Cloud Platform, or local behind firewalls and HTTPS services?

YES.

Expand or collapse content Do employees, contractors or authorized third-parties access these systems or customer data? If so why?

YES, FOR NETWORK SUPPORT AND MAINTENANCE.

Expand or collapse content Do you have a dedicated information security group or function in your organization that is responsible for the oversight and implementation of information security?

YES, WE HAVE AN INTERNAL IT DEPARTMENT WHO MANAGES OUR FIREWALLS AND ONSITE SYSTEMS, AS WELL AS AN OUTSIDE CONSULTANT WHO MANAGES OUR D.R.

Expand or collapse content Are background checks conducted on employees that have access to customer systems/data when they begin employment or on a recurring basis?

YES.

Expand or collapse content Do you have an information security incident response team or formal process for identifying and reporting potential or actual incidents?

NO, TBD Q3 2020.

Expand or collapse content Do you use student information in any way not connected with the service/integration?

NO.

Expand or collapse content Do you have a patch management process for servers?

NO, TO BE DEPLOYED IN 2020.

Expand or collapse content Are patches tested prior to deployment?

YES.

Expand or collapse content Do you employ any server performance monitoring?

NO, TO BE DEPLOYED IN 2020.

Expand or collapse content Is logging turned on for transactions and configuration changes to servers/systems?

YES.

Expand or collapse content Are the infrastructure and systems that [INSTITUTION] will be using segmented from other customers’ data? (i.e. Are router ACLs and/or firewall policies implemented for network segmentation?)

NO.

Expand or collapse content Is administration of the systems and infrastructure by your staff conducted over a dedicated management network?

YES.

Expand or collapse content Are system administrators required to use unique credentials when conducting administrative functions?

YES.

Expand or collapse content Are administrative credentials shared between administrators?

NO.

Expand or collapse content Is multi‐factor authentication used by anyone for access to systems/data?

NO.

Expand or collapse content Is there a process for requesting, approving, denying and removing access for your staff?

YES.

Expand or collapse content Are there ID/password or access requirements for Minnesota State users such as; unique ID, password length and strength, password change frequency, lockout after a specified number of failed attempts, etc.?

YES, IF USING LTI, UNIQUE IDS AND KEYS ARE USED TO ACCESS, IF USING STANDARD ACCOUNT CREATION, PASSWORD MUST CONTAIN AT LEAST 1 UPPERCASE LETTER AND 1 DIGIT OR SYMBOL ( ~ ! @ # $ % ^ * & ; ? . + _ ) AND BE AT LEAST 8 CHARACTERS LONG.

Expand or collapse content Is access to data by your staff and the institution granted based on least privilege?

YES.

Expand or collapse content Have your developers received any security training?

YES, DEVELOPERS RECEIVE SECURITY TRAINING IN A MONTH-LONG TRAINING PROCESS.

Expand or collapse content Explain where security fits in with your SDLC process (i.e. security touch‐points/controls, etc.).

SECURITY RISKS ARE ANALYZED DURING THE CODE REVIEW AND TESTING PHASE.

Expand or collapse content Has a static or dynamic scan been run on the application(s)?

YES, STATIC ANALYSIS IS RUN ON A CONTINUOUS BASIS.

Expand or collapse content Are industry standards used to identify vulnerabilities in application code (e.g. OWASP Top‐Ten, SANS Top‐25, etc.)?

YES, OWASP TOP-TEN.

Expand or collapse content Have vulnerabilities that have been identified as high‐risk been remediated?

YES.

Expand or collapse content Is logging configured/turned on for the application? If ‘Yes’, explain what is being logged.

YES, NO STUDENT IDENTIFIABLE INFORMATION IS LOGGED.

Expand or collapse content If 3rd party applications/libraries/modules are implemented, are they checked for patches and patched on a recurring basis? Explain.

YES, LIBRARIES ARE UPDATED ON A QUARTERLY BASIS.

Expand or collapse content Have any other security controls been used or implemented for the application(s) (i.e. penetration test, threat modeling, manual code review, etc.)? Explain.

YES, CODE REVIEWS.

Expand or collapse content How does institutional data flow within the business process of Cloud?

Institutional data is entered by institution admin users. Any text content is stored in an encrypted relational database on a private subnet on AWS, and any image/video/audio data is stored in a private Amazon S3 bucket.

Lesson content may also be created by institution admins, which again is stored in a relational database on our private subnet (in the case of text content), or in a private Amazon S3 bucket (in the case of video, audio, and image content).

This content is then served to users of the platform. Institution data such as institution name and image logos are served to students on the landing page when they log in. Lesson content is served to students as they navigate through and complete lessons in the application.

Access to resources stored in Amazon S3 is granted using temporary expiring URLs.

Data Center Security

Expand or collapse content What country is your data center that hosts your solution located?

ERP IS ON PREM  UNITED STATES FOR AWS AND GCP.

Expand or collapse content What are the physical access requirements for your data center?

WE RELY ON KNOWN MAINSTREAM CLOUD COMPUTING ENVIRONMENTS (GOOGLE, AWS, AZURE). WE DO NOT HAVE PHYSICAL ACCESS TO ANY DATA CENTER WHERE OUR DATA MIGHT BE STORED. DATA CENTER POLICIES INCLUDE: 

PHYSICAL SECURITY FEATURES A LAYERED SECURITY MODEL, INCLUDING SAFEGUARDS LIKE CUSTOM-DESIGNED ELECTRONIC ACCESS CARDS, ALARMS, VEHICLE ACCESS BARRIERS, PERIMETER FENCING, METAL DETECTORS, AND BIOMETRICS, AND THE DATA CENTER FLOOR FEATURES LASER BEAM INTRUSION DETECTION. OUR DATA CENTERS ARE MONITORED 24/7 BY HIGH-RESOLUTION INTERIOR AND EXTERIOR CAMERAS THAT CAN DETECT AND TRACK INTRUDERS. ACCESS LOGS, ACTIVITY RECORDS, AND CAMERA FOOTAGE ARE AVAILABLE IN CASE AN INCIDENT OCCURS. DATA CENTERS ARE ALSO ROUTINELY PATROLLED BY EXPERIENCED SECURITY GUARDS WHO HAVE UNDERGONE RIGOROUS BACKGROUND CHECKS AND TRAINING.

Expand or collapse content How is your data center access list maintained and controlled?

BY GOOGLE AND AMAZON.

Expand or collapse content Is the data center physically monitored?

YES.

Expand or collapse content Is physical protection against damage (e.g., natural causes, natural disasters, deliberate attacks) anticipated and designed with countermeasures applied?

YES.

Expand or collapse content Do you have a second/redundant data center for failover?

NOT PRESENTLY.

Expand or collapse content Do you have a documented Disaster Recovery Plan? If so, is that plan tested on a recurring basis?

TO BE DEPLOYED IN Q2.

Expand or collapse content Do you have network security controls implemented (e.g. firewalls, intrusion detection/prevention, etc.)?

SONIC FIREWALL APPLIANCES PROVIDE PERIMETER PROTECTION.

Expand or collapse content Have you conducted a vulnerability assessment on network and server/data infrastructure?

TO BE DEPLOYED IN Q3.

Expand or collapse content Do you have a patch management process for network and infrastructure?

NO, TO BE DEPLOYED IN 2020.

Expand or collapse content Do you have a change management process?

 NO, TO BE DEPLOYED IN 2020.

Expand or collapse content Do you have any network performance monitoring?

NO, TO BE DEPLOYED IN 2020.

Expand or collapse content Is infrastructure monitored 7x24, 8x5, etc.?

YES, WE HAVE BOTH ON SITE AND OUTSIDE CONSULTANTS SUPPORTING OUR INTERNAL NETWORKS. CUSTOMER FACING PLATFORMS ARE SUPPORTED BY AWS AND GCP.

Learning Management Systems

Expand or collapse content Is the LTI integration IMS global certified?

NO, IT IS NOT CERTIFIED.

Expand or collapse content How are tokens or keys stored?

WE PROVIDE AN ITI KEY AND SECRET WHICH IS AVAILABLE INSIDE THE INSTRUCTOR'S PORTAL. WE DO NOT STORE ANY TOKENS OR KEYS, ONLY IDs ASSOCIATED WITH STUDENTS AND LESSONS IN OUR ENCRYPT-AT-REST DATABASE.

Policies and Compliance

Expand or collapse content Does your organization have documented security policies? Can you share those?

TO BE DEPLOYED IN 2020.

Expand or collapse content Does your organization have a Privacy Policy? Can we see it?

PUBLISHED ON ALL OF OUR APPLICATION PLATFORMS. SEE AS APPLICABLE.

Expand or collapse content Do you have a policy or procedure for breach notification? Can we see it?

TO BE RELEASED IN 2020.

Expand or collapse content Explain how Minnesota State would be notified in the event of a security incident or breach.

THIS IS BASED ON CONTRACT TERMS. GENERALLY, THE HEAD OF SIG IT WOULD COMMUNICATE THE CAUSE, AND EXTENT OF THE BREACH TO THE APPROPRIATE POC.

Expand or collapse content Has an independent third-party security audit been conducted over the past 2 years? Can you share results – details or Executive Summary?

SOC2 COMPLIANCE AUDIT BEGAN IN EARLY 2019 BUT WAS NOT COMPLETED. A NEW AUDIT IS SCHEDULED FOR Q2, 3 2020.

Expand or collapse content Are independent third-party security audits conducted on a recurring basis?

NOT CURRENTLY BUT PLANS INCLUDE ANNUAL SOC2 AUDITS BEGINNING 2021.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Previous Article Adding the Kit Inventory Lesson to Existing Courses
Next Article How to Provide LTI Information to Institutions