we make security & compliance easier stuff trusted it & security solutions & services ...

74
we make Security & Compliance easier stuff Trusted IT & Security Solutions & Services www.acruxnet.net [email protected]

Upload: omarion-bel

Post on 14-Jan-2016

218 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

we make Security & Compliance easier stuff

Trusted IT & Security Solutions & Services

www.acruxnet.net [email protected]

Page 2: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Managed File TransferSecuring Data at REST & TRANSIT

August 2014

Page 3: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

3

ACRUX Co. WLL (acruxnet) is a Bahraini company founded in 2012 Provides Trusted IT & Security Solutions & Services in the GCC region

Mission To proficiently assist our clients build and maintain information security as a

system that consists of people, data, process and technology that comply with the IT security industry standards cost effectively.

Our Promise: We commit to provide our clients with smart, trusted, affordable and

reliable solutions and services to build and maintain information security system and achieve compliance with the well known security standards

Our Partners:

  

Overview of acruxnet

Page 4: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

4

Our Solutions: 

1. DeepNet - DualShield - Dual or Multi Factor Authentication2. Trustwave – mainly DbProtect Database Security – other Solution solutions and services3. GoAnyWhere - (MFT) Automated & Secured File Transfer to Secure DATA at REST & TRANSIT  4. NNT - Integrated SIEM, FIM & CCM ( alternative with more features to the expensive tripwire/IBM)5. Airtight - Wireless Security & PCI-DSS Compliance Solution6. BankCube Data Masking & Sanitization Solution 

Our Services:

1. Consultancy - PCI-DSS/IT/Security/Card Industry (acquiring & issuing )2. Project Management – focus on IT & Banks Projects (emv, EFT, ATMs, PCI-DSS, Bank applications)3. IT or Security Cost Review & Optimization 4. Security Assessment ( Gap Assessment, Vulnerability Scanning & Penetration Testing  & QSA)5. Risk Assessment (i.e. annual for the PCI-DSS Certification)6. Solution Evaluation & Selection7. Documentation - Policies/Procedures/PCI-DSS Documentation 8. Resource Lease9. Security Code Review (SAST & DAST)

What we do

Page 5: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

5

Founded in 1994 - based in Nebraska USA Private company with no debt or outside funding Dedicated to Research and Development  Focused on Data Automation and Security Responsive technical support; Toll-free, Chat, Email, Web Regional Partner in the Middle East (ACRUXNET) IBM Advanced Business Partner, Microsoft Silver Partner Other Partnerships: Oracle, Sun, Novell, RedHat, Apple, VMware and PCI Security 

Standards Council

Overview of Linoma Software

Page 6: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

6

Why GoAnywhere MFT Solution ?

GoAnywhere Managed File Transfer (MFT) solution provide bunch of services around data transfer services that make data exchange internally and externally with your business partners secured at transit & at rest, automated, controlled, monitored, audited in reliably smarter and easier way. Conventional file transfer tools will probably fails you in some of the below :

Security: Addresses the CIA ( Confidentiality, Integrity & Availability) concernsAutomation of data transfer, storage, retention, disposal, job scheduling, triggers & status alertingMonitor operation, system and user activities.Simplicity of use ( no programming or scripting expertise require – intuitive GUI) Logging , Auditing, Alerting and Reporting Administration – Intuitive GUI & Advanced Role Based access Control Less helpdesk overhead - Self-Service “Forgot Password” features – disable inactive usersCentralized Control – Integrates with your business, IT & Security processLogging, Auditing & Controlling who/where/how/what/when something has been done.Data Translation: from almost any source of data (files/db) to any destination  Availability – Clustering – alerting – ad-hoc secure file sharing via emailKeep latest & most secured technology (i.e. encryption algorithms & key management) at low costKeep data flows well structured, controlled  and gain visibility to better manage your risksSaves storage space by reducing duplicated files Compliance with Security Standards NIST, PCI-DSS, HIPPA & Internal Bank InfoSec PoliciesCost Effective Licensing & TCO – Cost Saving Operationally through the automation & ease of use

Page 7: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

7

GoAnywhere MFT Solution

Page 8: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

8

Product Summary

GoAnywhere Director™  is  a  managed  file  transfer  solution  that automates  and  secures  the  exchange  of  data  with  your  customers, trading partners and enterprise servers.  GoAnywhere Director connects to almost any server or data source using a wide variety of standard and secure protocols.

GoAnywhere Services™ allows trading partners (e.g. customers, vendors, remote employees) to securely connect to your system and exchange files within a fully managed and audited solution.    It  includes the popular file transfer server protocols of FTP, FTPS, SFTP, HTTPS, Secure Mail and AS2.

GoAnywhere Gateway™  is  both  a  reverse  and  forward  proxy  that provides  an  additional  layer  of  security.  It  allows  you  to  exchange data with trading partners without having to open incoming ports into your private network or store sensitive information in the DMZ.

Page 9: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Product Summary

Page 10: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net
Page 11: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

GoAnywhere Director Diagram

Page 12: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Automates data movement throughout the Enterprise 

Streamlines data transmissions with Trading Partners

Eliminates:1.Custom programming and scripts2.Manual processes3.PC file transfer tools4.VANs & Dial-Ups

Secures transmissions to comply with PCI DSS, HIPAA, HITECH, SOX and state privacy laws.

Decreases transmission times through compression 

Supports concurrent large file transfers with auto-resume and integrity checks

Provides centralized point-of-control and administration

Includes detailed logging and message alerts 

Implements industry standards

GoAnywhere Director Benefit

Page 13: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

For compliance with PCI-DSS, HIPAA, FIPS 140-2, Sarbanes Oxley, GLBA and State Privacy Laws

Secure Protocols •SFTP – FTP over SSH•FTPS – FTP over SSL/TLS•SCP – Secure Copy•HTTPS – HTTP over SSL•OpenPGP / GPG•ZIP with password protection•Encrypted email (SMIME)•AS2 

AES encryption (key lengths of 128, 192, 256) – NIST standardTwo Factor AuthenticationKey Management tools for OpenPGP Keys, SSL X.509 certificates and SSH KeysRole-based AdministrationSSL protected console

GoAnywhere Director Security

Page 14: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Installs to AIX, HP-UX, IBM System i, IBM System p, IBM System z, Linux, Mac OS, Microsoft Windows, Sun Solaris and UNIX

Customer installable – Less than 30 minutes typically

Includes dozens of  business processes (Tasks)

Project-based design allows “chaining” of multiple Tasks together

Automate Projects with built-in scheduler

Launch Projects from other platforms, applications and programming languages

GoAnywhere Director Setup

Page 15: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

File Systems - Network Shares (SMB/CIFS) - Local File System

FTP - Standard FTP - SFTP (FTP over SSH) - FTPS (FTP over SSL) - SCP (Secure Copy)

Web Sites - HTTP - HTTPS (HTTP over SSL) - Web Services - AS2

Email - POP3 - IMAP - SMTP

Database - DB2 - Oracle - Microsoft SQL Server - Sybase - MySQL - PostgreSQL - Informix

Enterprise Messaging (JMS) - Websphere MQ - SonicMQ - ActiveMQ

- SwiftMQ

GoAnywhere Director Connectivity

Page 16: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Automated Transfers – Outgoing

Page 17: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Automated Transfer - Incoming

Page 18: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Browser based front-end for configuring GoAnwhere Projects

Intuitive screens and wizards - AJAX enabled

All definitions stored on server

Graphical dashboard - Define Resources and Projects - Schedule and execute Projects - Monitor active Jobs - View Job Logs - Configure User Authority - View statistics

GoAnywhere Administrator

Page 19: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Predefine Resources in GoAnywhere Administrator

Each Resource has a unique name

Only authorized administrators can maintain Resources

Stored in GoAnywhere central database

Use Resources from within Projects

GoAnywhere Resources Setup

Page 20: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Project defines the Business Processes to perform

Each Project contains one or more Modules

Each Module contains one or more Tasks

Project can contain variables that may be overridden at runtime

Define Projects through graphical wizards or XML

project name=“TestProject" mainModule=“Module B" version="1.0"><variable name=“FileName" value=“employees.xls" /><module name=“Module B">

<sql label=“Fetch from Database" resourceId="Production 400">

<query outputVariable="data"><statement>select * from

LNMXDEMO.EMP</statement></query>

</sql>

<writeExcel label=“Convert to Excel" inputRowSetVariable="${data}" outputFile=“${FileName}" sheetName="Employees"

includeHeadings="true"><data trim="both"/>

</writeExcel></module>

</project>

GoAnywhere Project Tasks

Page 21: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Define Projects through graphical interface

Organize Projects under folders and control access rights to the folders

GoAnywhere Project Designer

Page 22: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Connect to DB2, Oracle, SQL Server, Sybase, MySQL, PostgreSQL and InformixDo not need to load additional software on database server - connects via JDBC 2.0 driversRun any SQL statement supported by the database (e.g. Select, Insert, Update, Delete,

Call, Create…)

Example uses of SQL in GoAnywhere: - Import files (text, Excel, XML) into database tables - Export records from a database table into a file (text, Excel, XML) - Copy records between tables - Call stored procedures on a database server - Create and Alter tables

Database

Page 23: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

FTP command support - Get files - Put files - Delete files - Move files - Make Directory - Change Directory - Rename Directory - Execute Custom Commands

Connection retry attempts with file auto-resume

Auto-detect Binary and ASCII modes

Include or Exclude files based on - Wildcards (i.e. “trans*.txt” or “*.xls”) - Date/time range - Size range

Auto suffix or prefix file names with    timestamps, values or variables

Configurable ports

Example of FTP Get:

GoAnywhere FTP - Insecure

Page 24: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

   SFTP = FTP over SSH   SSH 2.0 is latest standard   SFTP encrypts the entire connection including data,     users ids, passwords and commands

   Authenticate with a User id and•  Password•  Key•  Password and Key (Dual Factor)

   Connection retry attempts with file auto-resume   Wildcard file filters, auto prefix/suffix file names, etc.   Configurable ports

TERMS

SSH is an abbreviation for Secure Shell.  SSH is both a computer program and an associated network protocol designed for encrypting communications between two untrusted hosts over a network.   It utilizes Public keys to provide asymmetric cryptology. 

GoAnywhere SFTP Server

GoAnywhere SFTP

Page 25: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

   FTPS = FTP over SSL/TLS

   Encrypts entire connection including data, user ids,     passwords and commands

   Explicit and Implicit FTPS are both supported

   Supports dual-factor authentication using a     combination of certificates and user/passwords

   Certificates can be self-signed or signed by a certificate authority (CA) like Verisign

   Connection retry attempts with file auto-resume

   Wildcard file filters, auto prefix/suffix file names, etc.

   Configurable port ranges

TERMS

SSL is an abbreviation for Secure Sockets Layer.  SSL is a security protocol for encrypting communications between two hosts over a network. SSL utilizes certificates to establish trust between the two hosts.  

TLS is the abbreviation for Transport Layer Security and is the successor to SSL.

GoAnywhere FTPS Server

GoAnywhere FTPS

Page 26: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Send email - Supports multiple To, CC and BCC addresses - Specify SMTP server, subject, message, reply to - Multiple attachments allowed - Support for international characters - SMIME support for encrypted emails

Retrieve email - Filter incoming emails based on From, To, Subject and Message - Store attachments for further processing - Can retrieve email from POP-3 and IMAP servers - SSL support

e-mails

Page 27: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

HTTP and HTTPS (SSL)

Supports Cookies and HTTP Redirects

Perform requests with Parameters

HTTP Get       - Download multiple files in one session       - Filter files based on last modified date/time

HTTP Post       - Upload multiple files in one session

GoAnywhere HTTP

Page 28: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Read and Write popular data formats - Database - Excel - Fixed-Width text - Delimited text (CSV) - XML

Can convert between formats. Examples: - Database to CSV - CSV to Excel - XML to Database

GoAnywhere Translation

Page 29: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Multiple sources (database, CSV, fixed-width, Excel)

Create multi-level XML documents 

Header/Detail support

Custom XML tag names and attribute names

Format numbers and dates

Specify null substitute values

Data trim options

Indention / whitespace formatting

Schema or DTD validation

GoAnywhere XML

Page 30: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Parse complex multi-level XML documents 

Schema or DTD validation

Header/Detail support

Data trim options

Supports multiple date and number formats

Skip invalid records

XML data can be inserted into database tables

XML data can be converted to other formats      (i.e. Excel or CSV)

GoAnywhere XML Read

Page 31: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Supports Excel 95, 97, 2000(XP), 2003, 2007 and    2010 spreadsheets 

Support for Excel Templates

Write to Multiple sheets

Custom titles, page headers, column headings and page footers

Control fonts, font sizes, colors, alignment, etc. (by sheet or column)

Format dates and numbers using formatting options supported by Excel

Append or Replace

GoAnywhere Excel Write

Page 32: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Supports Excel 95, 97, 2000(XP), 2003,      2007 and 2010 spreadsheets 

Indicate the sheet name to read

Specify the starting row number

Specify column types/sizes

Trim options

Format options for dates/numbers

Null substitute values

Import into database or convert     to another format (i.e. CSV or XML)

GoAnywhere Excel Read

Page 33: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Read and write text documents

Fixed-width and Delimited text (CSV)

Supports multiple date and number formats

Record delimiters (CR, LF, CR/LF, LF/CR)

Text qualifiers

Null substitute values

Read - Data can be inserted into a database table - Data can be converted to other formats (i.e. Excel or XML)

Write - Append or Replace - Specify type of delimiter (commas, tabs, pipes, etc.) - Include/exclude column headings

Fixed Width & Delimited

Page 34: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

  Symmetric Form of Encryption – Password based

Can encrypt and compress multiple files at once (packaging)

Password protection: Standard, AES128, AES192 or AES256

Compresses typical data to 1/10th of original size

Compatible with PKZIP, WinZip and other ZIP tools

ZIP Compression & Encryption

Page 35: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

“A transfer can be defined in just five steps”

TERMS

OpenPGP standard is a non-proprietary and industry-accepted protocol which defines the standard format for encrypted messages, signatures and keys. This standard is managed by the IETF (Internet Engineering Task Force).  Key Pair is a combination of a Private key and its corresponding Public key.   Key Pairs are used within Asymmetric Cryptology systems, such as OpenPGP, SSH and SSL.

Private Key  is the portion of a Key Pair which is used by the owner to decrypt information and to encode digital signatures.  The Private key, typically protected by a password, should be kept secret by the owner and NOT shared with trading partners.  Also known as a Secret Key.

Public Key is the portion of the Key Pair which is used to encrypt information bound for its owner and to verify signatures made by its owner.  The owner’s Public key should be shared with its trading partners.

   Widely used for exchanging sensitive files over the internet. 

Uses combination of Asymmetric-key and Symmetric-key cryptology to provide high level of protection and speed

Encrypt with Public Key -- Decrypt with Private Key (Secret Key)

Encrypted files can be sent over standard FTP connections or Email

Provides compression to reduce file sizes

OpenPGP Encryption

Page 36: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

OpenPGP Screen Examples

Page 37: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

  GoAnywhere integrated OpenPGP key management

  Create, Change, Delete, Import and Export Keys

OpenPGP Key Management

Page 38: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

  A Digital Signature is used to authenticate the Sender

Sign with Private Key

Verify with Public Key

TERMS

Digital Signature is an electronic signature which is encoded into a document using the sender’s Private key.   This signature can be authenticated by the recipient using the sender’s Public key.  An authenticated signature will ensure the original content of the document has not been altered by an unauthorized party.

OpenPGP Signatures

Page 39: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Copy, Move, Rename and Delete FilesCreate DirectoriesTimestampCreate and delete workspaces Call native programs and scripts on Windows, Linux, etc.Call IBM i (iSeries) programs and commands

Other Tasks

Page 40: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Define what should be done when a task errors out       - Abort (default)       - Continue      - Set a value for a variable      - Call a specific module

Error handling can be defined on a project, a module or a task 

GoAnywhere Error Handling

Page 41: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Execute immediately or in Batch

Place in GoAnywhere Scheduler

Use existing Scheduler

Execute from OS command line

Execute from within your applications

Executing Projects

Page 42: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Flexible scheduling: - One Time - Minutely - Hourly - Daily - Weekly - Monthly

Set login user and password, queue priorities, etc.

Email notification (when fails and when successful)

GoAnywhere Scheduler

Page 43: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Run projects in GoAnywhere using the RUNPROJECT command and APIs

RUNPROJECT available for IBM i (iSeries), Windows, Linux and UNIX

Requests sent to GoAnywhere over HTTP/S requests

Override Variables

Run interactive or batch

Specify Job Queue priority

Trap for errors

The RUNPROJECT command and APIs are provided at no additional charge in GoAnywhere.

RUNPROJECT Command

Page 44: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

44

Page 45: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Monitor for message ids

Any errors are placed in job log

Retrieve any errors with RCVMSG command

RUNPROJECT Example

Page 46: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Every execution of a Project is considered a “Job”

Each Job is assigned its own Job Number and Job Log

Starts in a Job Queue

Can override Job Queue priority and Execution priority

Multi-threading (to allow the concurrent execution of multiple projects)

Monitor active Jobs (hold, release, cancel)

Project Execution Flow

Page 47: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Global Log

Job Log per execution of Project

Log Level can be defined on a project, module or a task

Log Level controls what should be logged: - SILENT - INFO - VERBOSE - DEBUG

Search Completed Jobs  - Date/time range - User - Project Name - Job Number - Status

Logging

Page 48: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

1/21/08 9:38:07AM INFO Start Date and Time: 1/21/08 9:38:07 AM1/21/08 9:38:07AM INFO Job Number: 1200325835858 1/21/08 9:38:07AM INFO Project Name: /Demo/DB to Excel to Zip and FTP1/21/08 9:38:07AM INFO Submitted By: administrator

1/21/08 9:38:07AM INFO Executing task 'Retrieve Records‘1/21/08 9:38:07AM INFO Executing statement select * from LIBRARY.EMP1/21/08 9:38:08AM INFO Query execution produced a rowset1/21/08 9:38:08AM INFO Finished task 'Retrieve Records‘

1/21/08 9:38:08AM INFO Executing task 'Create Excel File‘1/21/08 9:38:09AM INFO 8 record(s) were written1/21/08 9:38:09AM INFO Finished task 'Create Excel File'

1/21/08 9:38:09AM INFO Executing task 'Create ZIP File‘1/21/08 9:38:09AM INFO Compressing file '/files/employees.xls‘1/21/08 9:38:09AM INFO Number of files compressed: 11/21/08 9:38:09AM INFO Finished task 'Create ZIP File‘

1/21/08 9:38:09AM INFO Executing task 'FTP the ZIP File‘1/21/08 9:38:09AM INFO Connecting to '192.168.1.2' at port '21' 1/21/08 9:38:10AM INFO Executing sub-task 'put‘1/21/08 9:38:10AM INFO Setting the data type to AUTO1/21/08 9:38:10AM INFO Uploading ‘/files/employees.zip’1/21/08 9:38:12AM INFO 1 file(s) were uploaded successfully1/21/08 9:38:12AM INFO Finished sub-task 'put‘1/21/08 9:38:12AM INFO Closed the FTP connection1/21/08 9:38:12AM INFO Finished task 'FTP the ZIP File'

1/21/08 9:38:12AM INFO Finished module 'main‘1/21/08 9:38:12AM INFO Finished project 'DB to Excel to Zip and FTP‘1/21/08 9:38:12AM INFO End Date and Time: 1/21/08 9:38:12 AM

Example of Job Log

Page 49: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Authorized users must have valid user id and password

Passwords can be authenticated against GoAnywhere database or System i

Users can be organized into User Groups

Roles can be assigned to Users and User Groups - Product Administrator - Security Officer - Resource Manager - Project Designer - Job Manager - User

Authorize Resources

Authorize Project Folders

GoAnywhere Security

Page 50: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Thread-safe - Controls whether or not a project can be executed simultaneously

Workspaces - Each execution of a project (or a job) can have its own workspace for storing temporary files

Import Projects and Resources

Promote Projects and Resources to other installations

GoAnywhere Advanced

Page 51: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net
Page 52: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

GoAnywhere Services - Summary

Page 53: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

GoAnywhere Product Diagram

Page 54: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Allows your trading partners and employees to securelyconnect to your organization and easily retrieve or upload files.   

Supports open transfer protocols of FTP, SFTP, FTPS, HTTPS and AS/2

Can secure transmissions with SSL/TLS or SSH encryption Provides a pure web client for simple file transfers Allows ad-hoc file transfers through Secure Mail Includes event triggers based on user-defined conditions Generates detailed audit logs and alert messages Provides trading partner account wizards and permission controls Intuitive browser-based interface for administration and monitoring  No programming or special skills needed Installs to Windows, Linux, IBM i (iSeries), IBM System p, HP-UX, Sun Solaris and UNIX

GoAnywhere Services Overview

Page 55: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Unlimited number of trading partners can be configured

Grant individual permissions or adopt permissions from groups

Restrict access based on the type of service (FTP, SFTP, FTPS, HTTP/s, AS2)

Restrict access to certain functions (e.g. upload, download, delete, rename, etc.)

Automatically send email with user id and password

Trading Partner Management

Page 56: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Allows your trading partners simple access to your system for exchanging files

Authenticate using user-ids/passwords/certificates with granular permission controls

Full audit trails and event triggers

Choose between basic and enhanced (applet) interfaces

Rebrand with your company logo

GoAnywhere Web Client

Page 57: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Audit logs stored for every transaction (login, upload, download, rename, etc.) for all services

Search using a wide variety of filter criteria

View on-line or export to CSV

GoAnywhere Audit Logs

Page 58: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

GoAnywhere Director can send/retrieve filesto/from GoAnywhere Services

GoAnywhere Services can call Projectsin GoAnywhere Director based on triggers

Triggers based on file upload, download,rename, etc.

Pass parameters, such as user and file name

Can run multiple triggers per event

Integration with GoAnywhere Director

Page 59: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

SECURE MAIL

Page 60: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Files transferred over a secure HTTPS connection

Your system keeps possession of the files until the recipient retrieves them (not hosted)

No file size limits (unlike traditional email)

Recipients don’t have to deal with keys or certificates (just click on the URL)

Customizable email templates (use your own logo, color schemes, fonts)

Licensed as an add-on module for GoAnywhere Servicestm   

Files Kept on Your System

Step 1 – Email Link

Step 2 – Get Files through browser

Your Employees

GoAnywhere Secure Mail

Page 61: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Sender:1. Enters the message2. Attaches the files3. Clicks Send

GoAnywhere Secure Mail

Page 62: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Recipient  gets an email with a link

GoAnywhere Ssecure Mail

Page 63: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Recipient provides the password

GoAnywhere Secure Mail

Page 64: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Recipient downloads the file attachments securely

Full Audit Trails… every step is recorded

GoAnywhere Secure Mail

Page 65: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net
Page 66: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

No incoming ports are opened into the private (internal) network 

No sensitive files are stored in the DMZ

User credentials and permissions are maintained/stored in the private network

Services configurations are maintained/stored in the private network

Supports FTP/s, SFTP, SCP and HTTP/s file transfer protocols

No special hardware components; software-only solution

Installs to Windows, Linux, AIX, UNIX and Solaris operating systems

GoAnywhere Gateway Introduction

Page 67: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

How it works ?

Page 68: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

Linux (32-bit and 64-bit):  - Distributions Red Hat, SUSE, Ubuntu, CentOS (not inclusive)  - Disk space               150 MB per product (not including user data)  - Memory         256 MB minimum per product (1 GB preferred)

Windows (32-bit and 64-bit):  - Operating System  Windows 2000, 2003, 2008 R2, XP, Vista, 7  - Disk space               150 MB per product (not including user data)  - Memory         256 MB minimum per product (1 GB preferred)

IBM i (iSeries): - Operating System V5R3 or higher  - Disk space requirements 100 MB per product (not including user data) - Memory requirements 256 MB minimum per product (512 MB preferred) - JRE  1.5 or later (1.6 preferred)

UNIX / AIX / Solaris / HP-UX:   - Disk space requirements  100 MB per product (not including user data)  - Memory requirements  256 MB minimum per product (1 GB preferred)  - JRE  1.5 or later (1.6 preferred)

GoAnywhere Installation

Page 69: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

69

Appendix

Page 70: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

70

Asymmetric Encryption AlgorithmsDiffie-HellmanDSARSAThe key sizes supported are 512, 1024, 2048 and 4096 bits.

Ciphers (Symmetric Encryption Algorithms)AES-128AES-192AES-256 (default)BlowfishCAST5DESIDEATriple DES (DES ede)Twofish

Hash AlgorithmsMD2MD5RIPEMD-160SHA1 (default)SHA-256SHA-384SHA-512

Compression AlgorithmsZIPZLIB

GoAnywhere Director is compliant with the Open PGP standard. The  Open PGP  standard  is  a  non-proprietary  and  industry-accepted  protocol  which  defines  the standard format for encrypted messages, signatures and keys. This standard is managed by the IETF (Internet Engineering Task Force). 

Encryption – Hashing - Compression

Page 71: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

71

Encrypted  Folders  protect  files  at  rest  (on  disk)  using  AES-256 encryption.  When  the Encrypted Folders feature is enabled, GoAnywhere will automatically encrypt the data as it is written  (streamed)  to  files  within  the  designated  folders.  This  is  important  for  compliance with  security  standards  (e.g. PCI DSS, HIPAA, etc) which  require  that  sensitive data  is never stored "in the clear" on disk at any time.

When  a  Project  accesses  the  files  from  an  encrypted  folder,  the  files will  be  automatically decrypted  on  the  fly.  Encrypted  folders  can  also  be  accessed  by  authorized  users  (admin cannot decrypt it) through the GoAnywhere File Manager screen.

Encrypted Folder Wizard Screen

Encrypted Folders

Page 72: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

72

Security  Requirements  for  Cryptographic  Modules  are  formalized  in  the  Federal Information  Processing  Standard  (FIPS publication 140-2),  developed  by  the  US National Institute of Standards and Technology (NIST) and Canadian Communication Security Establishment (CSE).

GoAnywhere Director provides a FIPS 140-2 Compliance Mode and when enabled, it only  permits  the  use  of  FIPS  140-2  compliant  ciphers  (e.g.  AES,  Triple  DES)  for encryption processes.

FIPS 140-2 Compliance

Page 73: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

73

PGP Encryption

Page 74: We make Security & Compliance easier stuff Trusted IT & Security Solutions & Services  info@acruxnet.net

74

Reason for RatingBBB rating is based on 16 factors. Get the details about the factors considered.

Factors that raised Linoma Software's rating include:1. Length of time business has been operating.2. No complaints filed with BBB.3. BBB has sufficient background information on this business.

 See more at: http://www.bbb.org/nebraska/business-reviews/computers-software-and-services/linoma-software-in-ashland-ne-104006361#reasonrating

Complaint Type Total Closed Complaints

Advertising / Sales Issues 0

Billing / Collection Issues 0

Problems with Product / Service 0

Delivery Issues 0

Guarantee / Warranty Issues 0

Total Closed Complaints 0

BBB accredited Business