Security
Defense contractors trust CyberIllumination™ with their supply chain data, and this responsibility is something we take seriously. We combine enterprise-class security features with extensive logging and auditing of our infrastructure, access, and data to ensure customer data is always protected.
FedRAMP High Authorization
CyberIllumination™ is FedRAMP High Authorized (Class D). The platform is hosted on AWS GovCloud, and is architected to be ported into even more secure government environments. All client data is stored, processed, and retained on U.S.-based infrastructure.
Classified and export controlled information notification
Although CyberIllumination™ is designed to meet or exceed the security requirements in NIST SP 800-171, CyberIllumination™ may not be used to store or process classified information. All clients are responsible for ensuring that information submitted to CyberIllumination™ meets these requirements.
Zero-trust access controls and audit trails
Sharing on CyberIllumination™ is deny-by-default. A subcontractor controls who sees its data and for how long, and every view of shared data is written to an access log that the data owner can review at any time.
Data center and network security
Facilities
CyberIllumination™ hosts service data on AWS GovCloud. AWS GovCloud infrastructure services include back-up power, HVAC systems, and fire suppression equipment to help protect servers and ultimately your data.
Dedicated security team
Our security team is on call 24/7 to respond to security alerts and events.
Protection
Our network is protected through the use of key AWS security services, integration with edge protection networks, regular audits, and network intelligence technologies which monitor and/or block malicious traffic and network attacks.
Architecture
Our network security architecture consists of multiple security zones. More sensitive systems, like database servers, are protected in our most trusted zones. DMZs are utilized between the Internet and internally between the different zones of trust.
Network vulnerability scanning
Network security scanning gives us deep insight for quick identification of out-of-compliance or potentially vulnerable systems.
Security incident event management (SIEM)
Our SIEM system gathers extensive logs from important network devices and host systems, and alerts the security team based on correlated events for investigation and response.
Intrusion detection and prevention
Service ingress and egress points are instrumented and monitored to detect anomalous behavior, with 24/7 system monitoring and regularly updated signatures based on new threats.
Threat intelligence program
We participate in several threat intelligence sharing programs and take action based on our risk and exposure.
DDoS mitigation
We have architected a multi-layer approach to DDoS mitigation, combining network edge defenses with AWS scaling and protection tools and AWS DDoS-specific services.
Logical access
Access to the production network is restricted on an explicit need-to-know basis, utilizes least privilege, is frequently audited and monitored, and requires multiple factors of authentication.
Security incident response
In case of a system alert, events are escalated to our 24/7 teams providing operations, network engineering, and security coverage. Employees are trained on security incident response processes, including communication channels and escalation paths.
Encryption
Encryption in transit
All communications with CyberIllumination™ servers are encrypted using industry standard HTTPS and Transport Layer Security (TLS) over public networks. TLS is also supported for encryption of emails.
Encryption at rest
Service data is encrypted at rest in AWS using AES-256 key encryption.
Availability and continuity
Redundancy
We employ service clustering and network redundancies to eliminate single points of failure. Our strict backup regime allows us to deliver a high level of service availability.
Disaster recovery
Our disaster recovery program ensures that our services remain available or are easily recoverable in the case of a disaster, through a robust technical environment, disaster recovery plans, and testing activities.
Application security
Secure development practices
We apply development best practices for our development languages and frameworks to mitigate known vulnerability types such as those on the OWASP Top 10 Web Application Security Risks. We employ third-party security experts to perform detailed penetration tests on the platform.
Authentication
Multi-factor authentication is required for all platform accounts. Strong passphrases are used for infrastructure accounts and SSH keys, which are stored securely and replaced if lost or disclosed.
U.S.-based data processing and support
To help troubleshoot problems within a client account, we may access client data. All such access is logged and initiated by background-checked, U.S. citizen support representatives. Screenshare sessions occur only when initiated by the client, clearly identify the remote session, and are logged.
Best practices for your account
- Never give out usernames, email addresses, or passwords.
- Limit the number of users with administrator access.
- Use multi-factor authentication to secure your account.
To report a vulnerability, see our Responsible Disclosure program.