CipherCloud for Salesforce - Solution Overview


Published on

Enable Salesforce Security by extending data privacy compliance controls to the cloud with the CipherCloud solution for Salesforce:

-Discover what your users are doing in the cloud and prevent data loss with detailed and precise visibility over all activity in Salesforce.
-Protect your cloud data with strong encryption (FIPS 140-2 validated), tokenization, and malware protection to ensure that no unauthorized users can access sensitive information.
-Monitor cloud usage with complete visibility over user activity and alerting on user behavior anomalies

Published in: Technology
  • Be the first to comment

  • Be the first to like this

No Downloads
Total views
On SlideShare
From Embeds
Number of Embeds
Embeds 0
No embeds

No notes for slide
  • Privacy regulations and corporate data governance issues continue to block many enterprises from realizing the full business benefits of Salesforce. CipherCloud helps remove these barriers by providing tools to detect compliance violations, provide strong protection for sensitive data, and monitor your Salesforce user activity for anomalous behavior.
  • With CipherCloud for Salesforce you can:
    Discover what your users are doing in the cloud and prevent data loss with detailed and precise visibility over all activity in Salesforce.
    Protect your cloud data with strong encryption (FIPS 140-2 validated), tokenization, and malware protection to ensure that no unauthorized users can access sensitive information.
    Monitor cloud usage with complete visibility over user activity and alerting on user behavior anomalies
  • The Cloud Data Loss Prevention (DLP) module enables you to extend your corporate data security policies to the cloud, providing detailed visibility over sensitive business data in Salesforce and Salesforce Chatter. The solution is tightly integrated with the entire Salesforce platform and understands all types of objects and data stored in the cloud. With a single click, you can scan your Salesforce Orgs and Salesforce Chatter content to quickly spot violations of your content policies.
    CipherCloud provides out-of-the-box DLP controls and policies that can detect compliance violations of HIPAA/HITECH, GLBA, PCI, ABA, SWIFT, and NDC codes. The module can also integrate enterprise DLP systems, such as Symantec, RSA, or Intel Security (McAfee).
    Results are delivered in clear, intuitive, and configurable dashboards. Easy drill-downs let you view specific user information and spot the exact source of policy violations directly in Salesforce. Any information captured by CipherCloud can be easily exported to a range of report formats.
  • CipherCloud gives you a control point for corporate data going to and from the cloud. All your users—internal, remote, or mobile—can seamlessly access Salesforce and Salesforce Chatter, while enabling you to enforce your company’s security policies.
    CipherCloud Data Protection provides FIPS 140-2 validated encryption or tokenization for data before the data goes to the cloud.
    Malware detection is also available as an added safeguard, scanning your data for threats before it goes into Salesforce. High-performance scanning engines detect the latest threats (viruses, spyware, network worms, Trojans, bots, rootkits, and more) and clean or quarantine infected content on-the-fly, without adding noticeable latency.
  • CipherCloud also provides tokenization to meet the most stringent data residency requirements. With tokenization, randomly generated values are substituted for the original data, which does not leave the enterprise. The original data and mappings for the tokens are stored locally in a JDBC-compliant database.
  • Only your authorized users have access to protected data in Salesforce. Unauthorized users will only see indecipherable codes.
  • Granular controls let you select protection options on a field-by-field basis for structured or free-form Salesforce data. CipherCloud offers multiple strong encryption options that preserve formats, partial field encryption, and Searchable Strong Encryption (SSE). You can mix and match encryption or tokenization methods to meet your specific data protection requirements.
  • CipherCloud’s patented technology enables you to retain the format and functioning of Salesforce, even when data is encrypted or tokenized. This enables your Salesforce users to search, sort, and report on protected data in Salesforce.
  • No protection solution is complete without ongoing usage and activity monitoring. The Activity Monitoring and Anomaly Detection modules provide you with the tools to quickly and effectively respond to security events or policy violations.
    The interactive dashboard provides complete visibility into ongoing user activity, along with anomaly detection that can help you identify system misuse in real-time. Events are monitored against historic usage patterns, identifying anomalous behaviors that could be a sign of malicious use or an account breach.
    You can easily configure thresholds and dashboard alerts on any unusual user activity that might indicate problems. This includes activity such as excessive downloads, after-hours activity, or unauthorized access to sensitive content. Thresholds can be automatically or manually configured to minimize false positives.
  • CipherCloud for Salesforce includes deep integration with Chatter, providing Cloud DLP, encryption, tokenization, and activity monitoring for unstructured Chatter posts and file attachments. The solution provides seamless support for Chatter # tags and @ mentions, maintaining the searchability of encrypted Chatter posts.
  • CipherCloud works with the entire Salesforce Platform, providing deep integration with popular Salesforce products including Sales Cloud, Service Cloud, Marketing Cloud and Chatter. In addition, the CipherCloud Extensible Platform can support any type of custom application built on the Salesforce1 Platform, as well as a wide range of third-party applications available on the AppExchange ecosystem.
  • CipherCloud for Salesforce is typically deployed as an in-line solution between users and Salesforce. Acting as a gateway, CipherCloud for Salesforce is positioned to transparently inspect data and apply data protection policies before the data goes to Salesforce. Designed for high-performance and availability, the CipherCloud for Salesforce gateway adds virtually zero latency, maintaining the normal Salesforce user experience. CipherCloud for Salesforce integrates with your existing single sign-on tools and, with only a simple URL redirect required, your users can access Salesforce as usual and without change to the user experience.
    Because of the in-line architecture, CipherCloud for Salesforce is able to monitor and analyze Salesforce content and all user activity. Deeply integrated with Salesforce, the solution is aware of all your Salesforce data fields, enabling it to scan and analyze data entered into Salesforce, both through the CipherCloud gateway and out of band.
  • CipherCloud for Salesforce - Solution Overview

    1. 1. © 2013 CipherCloud | All rights reserved. 1© 2013 CipherCloud | All rights reserved. CipherCloud for Salesforce DISCOVER ● PROTECT ● MONITOR
    2. 2. © 2014 CipherCloud | All rights reserved. 2 HowCipherCloud EnhancesSalesforce Protecting sensitive data from leaks Extending corporate DLP to the cloud Preventing unauthorized access to data Maintaining application functionality Monitoring user and data activity Detecting anomalies in user behavior Data Loss Prevention Data Protection Activity Monitoring
    3. 3. © 2014 CipherCloud | All rights reserved. 3 Protecting Sensitive Data in theCloud Ground breaking security controls Protect sensitive information in real time, before it is sent to the cloud while preserving application usability. Searchable Strong Encryption Key Management Tokenization Malware Detection Data Loss Prevention
    4. 4. © 2014 CipherCloud | All rights reserved. 4 CipherCloud for Salesforce – Features & Benefits
    5. 5. © 2014 CipherCloud | All rights reserved. 5 Direct drill down to source of DLP violations in Salesforce Comprehensive dashboard views of all policies violationsOn-demand scanning of any Salesforce Org Cloud Data Loss Prevention
    6. 6. © 2014 CipherCloud | All rights reserved. 6© 2014 CipherCloud | All rights reserved.6 Encrypted data is indecipherable to unauthorized users Transparent to users Preserves application functionality Encryption keys never leave the enterprise • Encryption or tokenization at the enterprise gateway • Minimal latency • Integrated malware detection CipherCloud Encryption Process
    7. 7. © 2014 CipherCloud | All rights reserved. 7© 2014 CipherCloud | All rights reserved.7 Tokenized data is indecipherable Complete visibility for all user cloud activity • Sensitive data remains in the organization • Only random tokens go to the cloud • Real-time tokenization • Near-zero latency • Malware detection • Transparent to users • Preserves usability and functionality CipherCloudTokenization Process Secure Internal Database
    8. 8. © 2014 CipherCloud | All rights reserved. 8© 2014 CipherCloud | All rights reserved.8 Unauthorized User Authorized User Outsiders going directly to Salesforce can’t access encrypted fields Users going through the CipherCloud gateway have full access to Salesforce NoAccess toUnauthorizedUsers
    9. 9. © 2014 CipherCloud | All rights reserved. 9© 2014 CipherCloud | All rights reserved.9 Data is encrypted field-by-field basis, based on your security policies Credit card numbers fully encrypted with AES 256 Fields can be partially encrypted Authorized User Unauthorized UserUnited Oil & Gas Encryption on a field-by-field Basis
    10. 10. © 2014 CipherCloud | All rights reserved. 10© 2014 CipherCloud | All rights reserved.10 Encryption can be conditional, based on a field setting Conditional Encryption
    11. 11. © 2014 CipherCloud | All rights reserved. 11© 2014 CipherCloud | All rights reserved.11 CloudActivity Monitoring andAnomaly Detection Tracking of all user activity, downloads, logins, data access Extensive dashboard and drill- down capabilities Tracking Automated detection of anomalous user behavior
    12. 12. © 2014 CipherCloud | All rights reserved. 12© 2014 CipherCloud | All rights reserved.12 Full support for unstructured Chatter posts & attachments Support # tags and @ mentions CipherCloud forChatter
    13. 13. © 2014 CipherCloud | All rights reserved. 13 CipherCloud forSalesforce -At aGlance Protects  Salesforce Sales Cloud  Salesforce Service Cloud  Salesforce Marketing Cloud  Salesforce Chatter  Salesforce 1 Platform Capabilities  Cloud Data Loss Prevention (DLP)  AES 256-bit Encryption,  Key Management  Tokenization  Cloud Malware Detection  User Activity Monitoring  Anomaly Detection
    14. 14. © 2014 CipherCloud | All rights reserved. 14 Top 3 US Bank’s Consumer Self- Service Loan Origination Portal UK Education Organization Deploys Global Cloud-Based Portal Major European Telco Consolidates Call Centers for 25 Countries Largest Hospital Chain Meets HIPAA & HITECH in the Cloud Top Canadian Bank Safeguards Proprietary Information in the Cloud Major Wall Street Firm Adopts Cloud Applications with Confidence New Zealand Bank Collaborates in the Cloud and Meets Compliance Government-Owned Mortgage Backer Protect PII Data in the Cloud High-Profile Federal Office Moves Public CRM Data to the Cloud Australian Insurer Reaches Customers Through Cloud-Based Portal Investment Fund Giant Consolidates CRM While Assuring Compliance Global Enterprises usingCipherCloud forSalesforce Canadian Provincial Government Tokenizes Cloud data for Residency Requirements Cable & Media Giant Adds Collaboration with Content Controls Government-Owned Mortgage Backer Protects PII Data in the Cloud Top Australian Bank Tokenizes Sensitive Chatter Posts Health Insurance Provider Delivers Safe Cloud Portal to Patients Click on the image to read Case-study
    15. 15. © 2014 CipherCloud | All rights reserved. 15 CipherCloud forSalesforce - Product Resources CipherCloud forSalesforce Datasheet Online Demo of CipherCloud forSalesforce Online Demo of CipherCloud forChatter BestPractices forCloud Information Protection in Financial Services Cloud Information Protection Overview
    16. 16. © 2014 CipherCloud | All rights reserved. 16 AboutCipherCloud Awards Cool Vendor Solutions Cloud Discovery Cloud DLP Strong Encryption Tokenization Activity Monitoring Anomaly Detection 500+ Employees Company 3.0+ Million Active Users 13 Industries 25 Countries 7 Languages P 13 Patents
    17. 17. © 2014 CipherCloud | All rights reserved. 17 More Information For additional information : • Website: • Email: • Phone: +1 855-5CIPHER Check out our Global Compliance Center Connect with Us!