Laserfiche WebLink
Security Policies and Procedures <br />Rotation of SSL Keys is done upon SSL Key expiration. They are set to expire at 1 <br />(one) year and rotated at that time. If there is an incident or the security keys are <br />thought to be compromised, the keys will be rotated immediately. <br />2. Secure Shell (SSH) Keys <br />The SSH keys provide a layer of authentication to get into the production servers. <br />SSH Keys are used as the authentication mechanism to remotely login to a server. <br />They are also used as the first factor of authentication to assume root access on the <br />production servers. Each developer has his/her own SSH key and is responsible for <br />keeping this key secure. <br />Rotation Policy <br />All SSH keys are rotated at a minimum of every three (3) months. If there is an <br />incident or the SSH keys are thought to be compromised, keys will be rotated <br />immediately. <br />3. Amazon Web Services (AWS) Access Keys <br />Unique AWS Access Keys are given to each developer with a unique AWS Login. <br />This allows the developer to make Application Protocol Interface (API) calls to AWS. <br />Currently, 1-2 AWS Access keys exist per developer. Where are these stored? How <br />do you know how many keys each developer has? <br />Rotation Policy <br />These keys are rotated at a minimum of every 90 days. If there is an incident or the <br />AWS keys are thought to be compromised, keys will be rotated immediately <br />4. Application Keys <br />Virtru uses these keys to encrypt sensitive key data stored in the CouchDB <br />database managed by IBM. There is only one copy of this key. <br />Rotation Policy <br />No rotation requirement. <br />Backup Policy <br />Backup of the key is kept with Virtru's Super Administrators. <br />The export of encryption technologies is restricted by the U.S. government. Residents of <br />countries other than the United States should make themselves aware of the encryption <br />technology laws of the country in which they reside. <br />Rev.2015.8.6 <br />40 <br />