Laserfiche WebLink
SOLICITATION # CH16012 <br />All data in transit between Google's Data Centers traverses across Google's private fiber network <br />using a customized, proprietary encryption technology. <br />Google hard drives leverage technologies like FDE (full disk encryption) and drive locking, to <br />protect data at rest. <br />These methods of encryption are fully managed by Google and Google's Key Management <br />Servers based on 128-bit or stronger Advanced Encryption Standard (AES). <br />Encryption Keys and Ciphers Supported by Google <br />Protocols <br />TLS 1.2 <br />TLS 1.1 <br />TLS 1.0 <br />SSL 3.04 <br />QUIC <br />Cipher suites <br />ECDHE RSA with AES <br />ECDHE RSA with 3DES <br />ECDHE ECDSA <br />RSA with AES <br />RSA with 3DES <br />Signing keys <br />RSA 2048 <br />ECDSA P-256 <br />Hash functions <br />SHA384 <br />SHA256 <br />SHA1 <br />MD5 <br />Salesforce Government Cloud Encryption Capabilities: <br />As part of the Salesforce Government Cloud, Salesforce is capable of responding to FIPS 140-2 <br />cryptographic implementations for data being transferred between the State's web browser and <br />Salesforce. Data that resides within Salesforce's protected boundary does not use FIPS 140-2 <br />validated encryption as compensating/mitigating controls are in place to protect data. Additional <br />information is provided below. <br />Data In Motion: <br />Salesforce employs cryptographic mechanisms to protect information during transmission. All <br />transmissions between the user and Salesforce are encrypted by default with a 2048- bit Public <br />Key. Our service uses International/Global Step Up certificates. We support one- way TLS, in <br />which customers create secure connections before sharing private data. <br />Secure routing and traffic flow policies ensure that customer traffic is encrypted entering <br />Salesforce until the load balancer decrypts the traffic. The load balancers decrypting the traffic are <br />FIPS 140-2 compliant and are located inside of the Salesforce Government Cloud isolation <br />boundary. <br />Data At Rest: <br />NIST SP 800-53 Rev. 4 states in SC-28, "Information at rest refers to the state of information when <br />it is located on a secondary storage device (e.g., disk drive, tape drive) within an organizational <br />information system." SC-28 also states, "Organizations may choose to employ different <br />carahsoft 94 carahsoft <br />