easy to adopt, easy to use, easy to leave service description Cross Domain Security Zone IaaS version 6.0 Open Contents Highlights .............................................................................................................................. 3 Overview ............................................................................................................................... 3 Example use cases ............................................................................................................... 5 Information assurance........................................................................................................... 5 Product features.................................................................................................................... 6 Technical features................................................................................................................. 6 Backup / Recovery & Disaster Recovery ............................................................................... 7 Service levels ........................................................................................................................ 7 Roles & Responsibilities ........................................................................................................ 8 Pricing ................................................................................................................................... 8 Trial service ........................................................................................................................ 10 Appendix ............................................................................................................................. 11 Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 2 of 14 Open Highlights Cloud ready Cross Domain Guard option, managed by Skyscape provides a quick and easy way to use structured and inspectable HTTP based data flows between security domains A DIY option, comprising a secure environment enabling consumers to implement application specific cross domain solutions to provide secure and controlled access between security domains Optimised for OFFICIAL – hosted in the UK & operated by SC cleared staff, the service benefits from extensive independent validation (including CESG Design Review and CHECK tests) and alignment with CESG Cloud Security Principles making it the ideal service for systems classified at OFFICIAL (including OFFICIAL-SENSITIVE) Enables and facilitate the Government Digital Strategy by providing a mechanism for selected components of secure, PSN facing applications to be made available via the Internet Supports application specific cross-domain requirements such as complex data types, code migration, browse-down remote administration, centralised logging, and so on Reduced risk of contamination as Skyscape apply governance and assurance that each deployed solution meets the Skyscape Acceptable Use Policy and System Interconnect Security Policy (i.e. code of connection) Overview The Skyscape Cross Domain Security Zone enables consumers to securely transfer data between the Skyscape Assured OFFICIAL (PGA IL2) cloud platform and the Skyscape Elevated OFFICIAL (PGA IL3) cloud platform using CESG approved cross domain security patterns. The Cross Domain Security Zone is designed to enable consumers to achieve the goals of the Government Digital Strategy, specifically enabling PSN facing applications to be made available to citizens and Industry via the Internet. This service is available in two options: 1. Skyscape-managed Cross Domain Guard Skyscape provide a secure and scalable managed Cross Domain Guard which supports structured and inspectable HTTP based data flows. This option provides an immediately available multi-tenant Cross Domain Guard to support simple use-cases. 2. Self-managed Cross Domain Solution Skyscape provide self-service access to the Cross Domain Security Zone which enables consumers to create their own Cross Domain Solution using technology and application services of their choice. Skyscape provide an assurance wrap by managing firewalls between the security zones and ensuring consumers use appropriate risk management to understand and mitigate identified risks. Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 3 of 14 Open The two options are shown in figure 1 (below), PSN Protected Service Internet Internet Servers PSN Servers Structured & Inspectable HTTP App Data Copy Structured & Inspectable HTTP App Skyscape-managed Cross Domain Guard Complex & Varied data flow Complex & Varied data flow Master Data Self-managed Cross Domain Solution Assured OFFICIAL Cloud Platform Cross Domain Security Zone Elevated OFFICIAL Cloud Platform Figure 1 - Cross Domain Security Zone The service leverages the proven Skyscape Assured Cloud platform which provides the following benefits: UK Sovereign cloud platform delivered from two secure UK data centres by a UK company with SC cleared UK staff Extensive assurance through independent validation and alignment with the CESG Cloud Security Principles Accredited PSN Service enabling secure, compliant access via government community networks including N3, PSN Assured & PSN Protected networks The Skyscape Cross Domain Security Zone provides high levels of assurance appropriate for data classified as OFFICIAL or OFFICIAL-SENSITIVE. Skyscape’s service has been designed specifically of for the UK public sector and is available only to the UK public sector. The service supports and complies with all relevant areas of the Government ICT Strategy and Information Principles for the UK Public Sector. Skyscape’s datacentres are some of the most energy efficient in the world and as such support the Green Government ICT Strategy in full. Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 4 of 14 Open Example use cases Simpler Better Cheaper The Cross Domain Security Zone enables consumers to use the multi-tenant Skyscape Cross Domain Guard for requirements where applications can be designed to make inspectable web services calls between the security domains. Consumers who require more control and flexibility over what is passed between security domains can now design, implement and manage their own cross domain security solution hosted in the Skyscape managed Cross Domain Security Zone. This enables support for a wider range of use-cases. The Skyscape Cross Domain Security Zone provides consumers with a flexible and cost-effective mechanism to support the aims of the Government Digital Strategy. The service enables consumers to avoid the costs associated with manual cross domain transfers such as the ‘swivel chair’ method Information assurance The Skyscape assured cloud platform is designed and optimised to meet the unique information assurance needs of UK public sector organisations. UK Sovereign cloud platform delivered from two secure UK data centres by a UK company with SC cleared UK staff Suitable for all data classified at OFFICIAL, including OFFICIAL-SENSITIVE data under the Government Security Classification Policy (GSCP) Suitable for legacy IL2, IL3 and IL4 (by aggregation) systems under the Government Protective Marking Scheme (GPMS) Extensive independent validation of alignment with the CESG Cloud Security Principles Enables access between workloads hosted on IaaS services which are CESG Pan Government Accredited at both IL2 & IL3 and are accredited PSN Services which have secure, compliant access via both PSN Assured & PSN Protected networks Independently certified against ISO27001, Cyber Essentials Plus and members of the Cloud Security Alliance (CSA) Secure (List X) and resilient (Tier 3) UK data centres facilities capable of hosting data classified at SECRET Protective Monitoring (aligned with GPG13) across all Skyscape platforms Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 5 of 14 Open Product features The Skyscape Cross Domain Security Zone provides a secure and flexible method of transferring data between your workloads hosted on the Skyscape Assured OFFICIAL (PGA IL2) cloud platform and the Skyscape Elevated OFFICIAL (PGA IL3) cloud platform. The service provides the following features: Assured – hosted in the UK & operated by SC cleared staff, the service benefits from extensive independent validation (including CESG design reviews) that it is properly aligned with CESG Cloud Security Principles making it the ideal service for all data classified at OFFICIAL (including OFFICIAL-SENSITIVE) Flexible – enables choice between ready-to-use Skyscape managed Cross Domain Guard (Multi-Tenant) and bespoke self managed Single-Tenant Cross Domain Security solutions Cross Domain Guard – the Skyscape managed Cross Domain Guard supports wellstructured HTTP based data transfer such as XML Cost-effective – the Skyscape Cross Domain Guard option is delivered as a cloud service via a shared multi-tenant solution and benefits from usage based billing. Control – the self-managed single-tenant option enables consumers to apply bespoke controls to support a wider range of use-cases and traffic flows Green – the Skyscape service is based in UK data centres which offer market leading efficiency around power and cooling. A Skyscape solution will generate less Carbon than many other solutions Technical features The Skyscape Cross Domain Security Zone provides the following technical features: Based on CESG architectural patterns for cross domain security Skyscape manage the firewalls on both the high side and low side of the Cross Domain Security Zone to mitigate the risk of contamination Skyscape require design reviews and agreement to Acceptable Use Policies to provide assurance that the Elevated OFFICIAL (PGA IL3) cloud platform is sufficiently protected from the Internet in line with CESG Cloud Security Principles The Skyscape-managed Cross Domain Guard provides: o An immediately available solution based on technology from DeepSecure o A scalable and highly available solution distributed across multiple instances o Support for structured and inspectable content such as XML data o Support for both Low-to-High and High-to-Low data flows The Self-managed single-tenant Cross Domain Solution provides: o An implementation of a ‘walled garden’ architecture for consumers to deploy their own choice of gateway technology o The capability for consumers to design cross domain solutions to meet a wider variety of use-cases and data flows Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 6 of 14 Open o Support for unstructured and un-inspectable content (subject to sufficient additional mitigation) such as browse down Remote Desktop Protocol, code transfer between security domains, import/export of complex data types (e.g. video, images, etc) o Support for both Low-to-High and High-to-Low data flows A highly available and disaster tolerant solution spanning two UK data centres separated by over 100km Integrated with the Skyscape Protective Monitoring solution (aligned with GPG13) Enables solution to leverage multiple connectivity options including the Internet, government community networks such as PSN Assured, PSN Protected, Legacy GCF networks (e.g. GSI, GSE, PNN, etc) or N3 Backup / Recovery & Disaster Recovery The Skyscape Cross Domain Security Zone is hosted across two UK data centres (separated by over 100km). The Skyscape-managed Cross Domain Guard is available within each UK data centre and enables consumers to create highly available and disaster tolerant solutions. Consumers can design self-managed Cross Domain Solutions to work across the Cross Domain Security Zone in each UK data centre to provide a highly available and disaster tolerant solution. Service levels Skyscape provide both an Availability SLA and Response Time SLA for the Cross Domain Security Zone as per the following table. STANDARD Availability (monthly*) Incident response Service credits 99.90% P1 – within 15 minutes P2 – within 4 hours P3 – within 24 hours P4 – within 72 hours 10% of monthly spend on the Cross Domain Security Zone * Availability indication based on an average 730hrs per month. Excludes planned & emergency maintenance. Unavailability applies to the Skyscape Managed Cross Domain Guard or the underlying Cross Domain Security Zone infrastructure due to a fault recognised at the IaaS layer or lower: i.e. fault is not within the Consumers control (VM configuration, customer networks, application logic, etc) fault is within Skyscape controlled components such as the Cross Domain Security Zone hardware, Cross Domain Guard service, data centre facilities, physical firewalls & routers etc. Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 7 of 14 Open External connectivity providers (e.g. internet, PSN, N3) are also not included in the availability calculation. In addition, Skyscape also provide an Availability Service Level Target on the Skyscape Portal i.e. the ability to log into the portal to create support tickets and use other functions. Target Availability (monthly*) Client Portal Availability (monthly) 99.90% Roles & Responsibilities Self Managed Cross Domain Solution Skyscape Managed Cross Domain Guard Provision of physical Cross Domain Security Zone environment (network, servers, storage & hypervisor) Skyscape Skyscape Configuration and Management of interzone firewalls (e.g. whitelists) Skyscape Skyscape Provision of security gateway solution Consumer Skyscape Configuration and Management of security gateway solution (e.g. DeepSecure WebGuard) Consumer Skyscape Assurance of underlying Cross Domain Security Zone Skyscape Skyscape Assurance of security gateway solution Consumer Skyscape Documented requirements and associated solution design Consumer Consumer Assurance wrap including design review and SIRO approval Skyscape & Consumer Skyscape & Consumer Pricing The Skyscape Cross Domain Security Zone is available in two options: 1. Skyscape-managed Cross Domain Guard The Cross Domain Guard is a multi-tenant solution designed to support structured and inspectable HTTP based data such as XML. It is priced as follows: Data Volume Monthly Price Starter Pack (1TB) £500 Next 4000GB £0.50 per GB 5001GB+ £0.10 per GB Upgrade options: Dual Site: £500 per month Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 8 of 14 Open Worked Example: Consumer requires a Skyscape-managed Cross Domain Guard and will transfer 2500GB per month Consumer buys: 1 x First 1000GB @ £500 per month 1500GB @ £0.50 per GB = £750 per month Total = £1,250 per month 2. Self-managed Cross Domain Solution The self-managed Cross Domain Solution enables consumers to create their own (single-tenant) solutions. It is priced as follows: On-boarding / Setup Fee: £2,500 (Managed Firewall configuration and validation of Assurance Plan) Baseline Monthly Fee: £500 Plus VM fees as follows: vCPU (2GHz) RAM (GB) STANDARD (per month) Tiny 1 2 £150.00 Small 2 4 £250.00 Medium 4 8 £350.00 Medium High Memory 4 16 Large 8 16 Large High Memory 8 32 Tier 1 Apps Small 8 48 Tier 1 Apps Medium 8 64 Tier 1 Apps Large 8 96 £500.00 £750.00 £1,000.00 £1,500.00 £2,000.00 £3,000.00 Worked Example: Consumer requires a self-managed Cross Domain Solution comprising of 4 x Medium VMs Consumer buys: 1 x Setup / On-boarding fee @ £2,500 one-off 1 x Baseline Fee @ £500 per month 4 x Medium VM @ £1,400 per month Total = £2,500 one-off plus £1,900 per month Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 9 of 14 Open Ancillary Options The Skyscape Pricing Guide provides a comprehensive catalogue of pricing; including all ancillary service options available to consumers when used in conjunction with the Skyscape Cross Domain Security Zone. Ancillary options include: Connectivity options including HybridConnect, PSN, N3, Internet, data centre interconnect, etc. SFIA rate card for ad-hoc services. Other ancillary options are available and can be found in the Skyscape Pricing Guide. Trial service Due to complex assurance requirements related to this service, a trial service is not available. Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 10 of 14 Open Appendix On-boarding and off-boarding Evidence that the consumer will implement and maintain a suitable & ongoing Assurance Process and Governance regime to ensure that Risks are regularly reviewed and controls are regularly audited for effectiveness Agreement that the consumer will perform a suitably scoped IT Security Health Check against the application using the Cross Domain Guard solution Confirmation by HMG customer and associated industry partners of agreement to Skyscape Acceptable Use Policy (AUP) and System Interconnect Security Policy (SISP) On-boarding Due to the nature of this service, on acceptance of an order, Skyscape will work with the consumer to create an Assurance Plan for the Cross Domain Security Zone to that states the consumer’s responsibilities including: For Skyscape-managed Cross Domain Guard: Validation of clear business requirement by the HMG customer (e.g. Department SIRO) Confirmation that the application uses a structured and inspectable HTTP based data transfer (e.g. XML) Agreement of policy definition (e.g. whitelist source & destination addresses, content types to allow, content size limits, XML schema, etc) Evidence that the consumer will implement and maintain suitable technology controls in both the low-side domain and high-side domain (e.g. Protective Monitoring, AntiMalware, Security Patches, etc) Agreement that the consumer will perform a suitably scoped IT Security Health Check against the application using the Cross Domain Guard solution Skyscape will create the consumer’s Primary Administrator account and send the consumer a Welcome Pack which includes the URL for the Skyscape Portal for access to the knowledge centre and service management function. For Self-managed Cross Domain Solution (single-tenant): Once enabled, the consumer’s Primary Administrator can create additional administrator users and configure the Cross Domain Security Zone virtual data centre (i.e. virtual networks, virtual firewalls, virtual machines, OS provisioning, application configuration, etc) as required. For Self-managed Cross Domain Solution (single-tenant): Off-boarding Validation of clear business requirement by the HMG customer (e.g. Department SIRO) On termination of the Cross Domain Security Zone, Skyscape will: Creation of Data Flow Document to understand how the application will use the Cross Domain Security Zone Agreement of the Skyscape managed firewall configuration required between the low-side domain & the Cross Domain Security Zone and between the high-side domain & the Cross Domain Security Zone (e.g. Firewall Access Control List) For Skyscape-managed Cross Domain Guard: Consumer’s Risk Assessment of enabling this gateway between their security domains Consumer’s Risk Treatment plan detailing the controls that they will implement to mitigate the identified risks Evidence that the consumer will implement and maintain suitable technology controls in both the low-side domain and high-side domain (e.g. Protective Monitoring, AntiMalware, Security Patches, etc) Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Remove Access Control Lists from Skyscape managed firewalls around the Cross Domain Security Zone (removal of whitelists) Remove the policy definition on the Skyscape managed Cross Domain Guard For Self-managed Cross Domain Solution (single-tenant): Open Delete the consumer’s virtual data centre within the Cross Domain Security Zone Cross Domain Secure Zone Page 11 of 14 Open Service constraints Training The Skyscape Cross Domain Security Zone service can only be used for connectivity between Skyscape services such as Compute-as-aService, Hadoop-in-the-Cloud, etc. Skyscape have created a number of videos, help guides, manuals and FAQs to help train and instruct users so that are up and running quickly and easily. The service is designed to operate only when the following constrains are met: Skyscape also have a number of Partners who are able to deliver additional services such as training, support and managed services. Skyscape would be pleased to introduce you to such partners where appropriate. Configuration and management of application services in both the low and high security domain must be hardened with regular security patches applied Application services must use appropriate antimalware software which is regularly updated Only specified traffic types will be allowed via a Skyscape managed whitelist The customer SIRO must understand and accept the residual risks associated with this solution Skyscape will adhere to the following in terms of maintenance windows; “Planned Maintenance” means any pre-planned maintenance of any infrastructure relating to the Services. Skyscape shall provide the Client with at least twenty four (24) hours’ advance notice of any such planned maintenance: Ordering and invoicing Billing for the service is monthly in arrears based on either the amount of traffic sent through the Cross Domain Guard or the maximum number of virtual machines configured (running or not) at any time during the month for the Cross Domain Solution. Payment can be via Purchase Order and Direct Debit. Skyscape are preparing to be able to accept Debit/Credit Card payments (e.g. Government Procurement Card) – please enquire at time of order to check whether this is available. Planned maintenance of Skyscape’s infrastructure relating to the Services shall happen between the hours of 00:00 and 06:00 (UK local time) Monday to Sunday and/or between the hours of 08:00 and 12:00 (UK local time) on a Saturday and/or Sunday. No planned maintenance will take place on a Saturday unless agreed in advance by both parties; Service lead time Planned Maintenance shall be excluded from any availability calculation in regard to service credits but shall be included in the monthly service reporting; Due to the variable nature of this service, full onboarding of the consuming organisation including enrolment of all users and end-user devices will take an indeterminate amount of time. “Emergency Maintenance” means any emergency maintenance of any of the infrastructure relating to the Services. Whenever possible, Skyscape shall provide the Client with at least six (6) hours’ advance notice: Termination Whenever possible Emergency Maintenance of Skyscape’s infrastructure will happen between the hours of 00:00 and 06:00 (UK local time) Monday to Sunday and/or between the hours of 08:00 and 12:00 (UK local time)on Saturday and/or Sunday unless there is an identified and demonstrable immediate risk to a Clients environment; Emergency Maintenance shall be excluded from any availability calculation in regard to service credits but shall be included in the monthly service reporting. Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Setting up a new consumer within the Skyscape Portal will typically be completed within 4 hours from acceptance of order. Resources to validate the Assurance Plan activity will be assigned within 10 days from acceptance of order. Terms The Cross Domain Guard option is subject to a minimum term of one month. The Cross Domain Solution option is subject to a minimum term of three months. Consumers are required to provide notice of termination of not less than 10 working days. At the point of termination, consumers must ensure that they have extracted any required data from the ‘Cross Domain Solution’ virtual data centre as Skyscape will ensure all consumer data, accounts and access will be permanently deleted, Open Cross Domain Secure Zone Page 12 of 14 Open and will not be able to be subsequently recovered or restored. Costs An Early Exit charge will be payable if the contract is terminated within the minimum term. The Early Exit charge will be equal to the cost of 3 months service less payments already made. Consumers are responsible for extracting their own data from the platform if required. Skyscape may make an additional charge for transferring data out of the service. Consumer responsibilities The control and management of access and responsibilities for end users including appropriate connectivity, security and assurance/accreditation if required. Where access is required over Government Secure Networks such as N3, legacy GCF networks or PSN, the consumer is responsible for adhering to the Code of Connection. Data restoration / service migration For service migration, Skyscape allows existing data to be migrated to and from the ‘Cross Domain Solution’ virtual data centre. In many circumstances, Skyscape can help facilitate a bulk migration to the platform using offline data ingest and extraction – please ask Skyscape for details. Financial recompense model If the service level falls below the stated availability percentage (excluding Planned and Emergency maintenance periods), consumers will be eligible for service credits on affected storage only. Service credits will be calculated as a percentage of the fees for the affected services for the monthly billing period during which the failure occurred (to be applied at the end of the billing cycle). Service Credit Cross Domain Security Zone 10% of monthly spend on the Cross Domain Security Zone Providing evidence that suitable technology controls in both the low-side domain and high-side domain (e.g. Protective Monitoring, Anti-Malware, Security Patches, etc) will be implemented and maintained Client Portal 1% of monthly spend per 1% below service level target or part thereof Ensuring a suitably scoped IT Security Health Check against the application using the Cross Domain Security Zone is performed Technical requirements Providing a clear business justification of the requirement for a Cross Domain Security solution. Providing evidence that suitable & ongoing Assurance Process and Governance regime is implemented and maintained to ensure that Risks are regularly reviewed and controls are regularly audited for effectiveness Providing access requirements between the ‘Cross Domain Security Zone’ and consumer solutions (e.g. firewall ports) Consumers must ensure that systems in both security domains meet the requirements of this service: Recommended use of a CPA approved data at rest encryption solution Mandatory use of anti-malware software (regularly updated) to reduce risk of malicious code execution on the servers Recommended use of an enterprise audit and monitoring service by the consuming organisation to ensure security events are centrally logged and reviewed. Mandatory implementation of a Incident Response plan by the consuming organisation to respond to security incidents such as loss of data confidentiality Manage security incidents related to the use of this service (e.g. data breach) The consumer is also responsible for ensuring only appropriate data (e.g. OFFICIAL or OFFICIAL-SENSITIVE) is stored and processed by applications on this environment and that they comply with the Skyscape Security Operating Procedures (SyOps) and other information assurance requirements as specified in Skyscape System Interconnect and Security Policy (SISP) and associated accreditation documentation sets. Service description SC-SVC-06, version 6.0 © Skyscape Cloud Services Limited, 2014 Open Cross Domain Secure Zone Page 13 of 14 Skyscape Cloud Services Limited A8 Cody Technology Park Ively Road Farnborough Hampshire GU14 0LX +44 (0)1252 303300 info@skyscapecloud.com www.skyscapecloud.com @skyscapecloud © Skyscape Cloud Services Limited. All Rights Reserved. SC-SVC-06