
Security
Security is a core element of the ESS-Databridge™ eDocs Exchange. Security features include, for example:
- Multi-tiered application environment, providing isolated tiers for web, application and data protected by dedicated firewalls
- Enterprise wide risk management strategy at data centers including anti-virus, managed firewalls, secure VPN, network and host based intrusion detection
- Hardened operating system and system components
- HTTPS 128bit secure socket level (SSL) encryption/decryption
- Extended validation (EV) digital certificates
- Redundant, geographically disparate data centers
The ESS-Databridge™ is subject to annual IT audits focused on external penetration testing and internal vulnerability assessments. PriceWaterhouseCoopers has been appointed by the DDG Executive Committee as the security auditor since 2009. Copies of the Auditor’s reports are available to DDG members.
ESS's data centers are PCI DSS, SAS70 and CICA 5970 (Type II) audited. ESS is also working towards obtaining ISO 27001 and 27002 approvals. An overview of each of these certifications is outlined below:
- PCI DSS - the PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures.
- SAS70 - the Statement on Auditing Standards No. 70 defines the standards an auditor must employ in order to assess the contracted internal controls of a service organization.
- ISO/IEC 27001 - formally specifies a management system that is intended to bring information security under explicit management control. ISO/IEC 27001 requires that management: (i) systematically examine the organization's information security risks, taking account of the threats, vulnerabilities and impacts; (ii) design and implement a coherent and comprehensive suite of information security controls and/or other forms of risk treatment (such as risk avoidance or risk transfer) to address those risks that are deemed unacceptable; and (iii) adopt an overarching management process to ensure that the information security controls continue to meet the organization's information security needs on an ongoing basis.
- ISO/IEC 27002 - provides best practice recommendations on information security management for use by those responsible for initiating, implementing or maintaining Information Security Management Systems.
