Show Menu
Cheatography

BE Cheat Sheet (DRAFT) by

This is a draft cheat sheet. It is a work in progress and is not finished yet.

Types of Reports

SOC2
Service Organi­zation Controls. BE does not have our own. Relevant specif­ically for data centers. Send Rackspaces & Bridge Letter in DD folder. NDA Required.
SOC1
Financial Controls. Rackspace has one. BE does not. Located in DD Folder. NDA Required.
PenTest
Third-­party Penetr­ation Test Report. Validates applic­ations free from common web attacks. Full report available. Located in DD folder. NDA Required.

Applic­ation Security

Is data encrypted?
Yes, data is encrypted both AT REST and IN TRANSIT using AES256 with unique keys per uploaded file.
Can we customize password security?
Yes, we offer password complexity config­ura­tion, as well as expira­tion, lockout, timeout, force changes, first-time login change, etc.
What types of access controls are there?
You can create custom resource permis­sions, book section restri­ctions, workroom restri­ctions and more. Admini­str­ators use the same interface as board members so its easy to understand the end user experi­ence.
 

Data Center / Physical Security

Rackspace (US, AU, EU) or Peer1 (Canada)
SOC2 Compliant
ISO 27001 Compliant
Biometric authen­tic­ation
24/7/365 monitoring
Disaster protection and multiple ISP connec­tivity

Infras­tru­cture

WAF
DEDICATED Web applic­ation firewall. Protects against malicious attacks. 0-day signature monitoring act as a front line of defense.
IDS
DEDICATED Intrusion Detection System to monitor for anomolous traffic in the network.
 
Most low-cost compet­itors use Shared devices. This signif­icantly impacts the effect­iveness of the device. We manage and monitor our own.
Private Cloud
We virtualize on our own hardware. Low cost providors likely use shared resources which have both security and reliab­ility impacts. We monitor the entire stack from the host, each server instance, and our network devices.
Managed Antivirus
SOPHOS AV runs on all of our servers and host machines.