Laserfiche WebLink
Security Policies and Procedures <br />C. Data durability and reliability <br />Virtru uses Amazon S3 to provide a highly durable storage infrastructure designed for <br />mission -critical and primary data storage. Amazon S3 redundantly stores data in <br />multiple facilities and on multiple devices within each facility. To increase durability, <br />Amazon S3 synchronously stores Virtru's data across multiple facilities before <br />confirming that the data has been successfully stored. In addition, Amazon S3 calculates <br />checksums on all network traffic to detect corruption of data packets when storing or <br />retrieving data. Amazon S3 performs regular, systematic data integrity checks and is <br />automatically self -healing. <br />D. Encryption <br />Virtru uses Server -side encryption to protect data at rest. Server -side encryption with <br />Amazon S3-managed encryption keys (SSE-S3) employs strong multi -factor encryption <br />by encrypting each object with a unique key. As an additional safeguard, it encrypts the <br />key itself with a master key that it regularly rotates. Amazon S3 server -side encryption <br />uses 256-bit Advanced Encryption Standard (AES-256) to encrypt Virtru's data. <br />E. Load balancing <br />Virtru uses Amazon Web Services' Elastic Load Balancing (ELB) to automatically <br />distribute incoming application traffic, to automatically route traffic across multiple <br />instances. and multiple Availability Zones. This is used to insure that only healthy <br />servers are receiving traffic. <br />F. Restoration of data <br />Restoration of production data is done on an as -needed basis. The following employees <br />are responsible for restoration of the application if it is needed: <br />1. Reuven Gonzales, Lead Developer, or <br />2. Conor Gilsenan, Developer Ops. <br />The needed backup data will not be restored "on top of" the current "bad" data. The <br />restores will be redirected to a new location, and first verified. Upon verification, the <br />"bad" data will be removed from the drive, and stored and relabeled as "old data." Then <br />the backup data will replace the "old data" on the drive. Once the restored data has <br />been verified once more, the "old data" will be destroyed. <br />G. Testing and revision of plan <br />Once every quarter, after doing a full backup, Virtru will recover the saved data. During <br />hours when the business is closed, we will operate the application using this recovered <br />data in a test mode. The tests will consist of a set of tasks that are designed to exercise <br />the main system functions to confirm that the data is usable and as up-to-date as we <br />expected given the backups that were used to do the recovery. This testing process <br />Rev.2015.8.6 <br />59 <br />