Laserfiche WebLink
SOLICITATION # CH16012 <br />There is no comingling of any customer data between instances and there is no single shared <br />multi -tenant databases, with data from multiple customers stored therein. <br />QTS <br />QTS cloud employs security controls as needed to protect the confidentiality and integrity of the <br />information being transmitted by utilizing Cisco AnyConnect VPN Client with SSL (TLS and DTLS) <br />and IPSec (Internet Key Exchange Version 2 [IKEv2]). DTLS provides an optimized connection for <br />latency -sensitive traffic, such as VoIP traffic or TCPbased application access, TLS (HTTP over <br />TLS/SSL) ensures availability of network connectivity through locked down environments, <br />including those using web proxy servers. IPSec/IKEv2 provides an optimized connection for <br />latency -sensitive traffic when security policies require use of IPSec and complies with applicable <br />federal laws, executive orders, directives, policies, regulations, standards, and guidance. <br />The QTS Federal Cloud Infrastructure (QTS cloud) is divided into two separate, isolated firewalled <br />environments, each having its own security boundaries, which are physically and logically <br />separated. These are the QTS cloud Hypervisor Management Layer and the QTS cloud Service <br />Delivery Layer. <br />QTS cloud's Hypervisor Management Layer management is made available through dynamic <br />FIPS 140-2 validated L2TP/IPSEC or SSL 3.0/TLS 1. 0 encrypted VPN tunnels, which are <br />authenticated against the RSA SecurlD multi -factor authentication security appliances. Once fully <br />authenticated, only a limited RDP session to the physical bastion host (which is also protected by <br />the RSA SecurlD multi -factor authentication security appliances) via jump domains is allowed, <br />which prevents the presentation of information systems management related functionality at an <br />interface for general <br />users. <br />QTS cloud's Service Delivery Layer management is also made available through FIPS 140-2 <br />validated L2TP/IPSEC or SSL 3.0/TLS 1.0 encrypted VPN tunnels, which are authenticated <br />against the RSA SecurlD multi -factor authentication security appliances. Connection to the QTS <br />cloud Service Delivery Layer is only available through dedicated site -to -site 140-2 validated <br />L2TP/IPSEC or SSL 3.0/TLS 1. 0 encrypted VPN tunnels or Trusted Internet Connection (TIC) <br />monitored dedicated datelines to federal customer datacenters, which prevents the presentation of <br />information systems <br />management related functionality at an interface for general users. <br />QTS cloud's Hypervisor Management Layer management is made available through dynamic <br />FIPS 140-2 validated L2TP/IPSEC or SSL 3.O/TLS 1. 0 encrypted VPN tunnels, which are <br />authenticated a ainst the RSA SecurlD multi -factor authentication security appliances. <br />SAP <br />Ariba <br />The Cisco Secure ASA5555 Firewall is a dedicated firewall appliance that <br />delivers strong security and performance and creates almost no network <br />performance impact. The product enforces secure access between an internal <br />network and Internet, extranet, or intranet links. <br />Ariba uses Cisco Secure ASA5555 Firewall hardware and Cisco Router <br />access lists to control the traffic to and from the Internet, between Ariba <br />Corporate and the Ariba system, and between servers in Ariba. The firewall <br />servers are configured for Fail-Over/Hot Standby Setup. Additionally, Ariba <br />uses internally developed Ariba SafeGuard software to protect customer data <br />from unauthorized Ariba Corporate users, allowing only Ariba Operations <br />personnel access for limited periods of time. <br />Specifically, firewall servers are used in each level of data communication <br />within Ariba: <br />Between the Internet and web servers <br />Between the web servers and the application servers <br />Between the application servers and the database servers <br />carahsoft 86 carahsoft <br />