Certifications and Compliance - Skyhigh Security (2024)

Certifications and Compliance - Skyhigh Security (1)

DoD Impact Level 
(IL2 and IL4)

Cloud computing security requirements for the US Department of Defense for Impact Level 2 and Impact Level 4

DoD Impact Level 
(IL2 and IL4)

Cloud computing security requirements for the US Department of Defense for Impact Level 2 and Impact Level 4

The U.S. Department of Defense (DoD) has unique information protection requirements that extend beyond the common set of requirements established by the Federal Risk and Authorization Management Program (FedRAMP) program. Using FedRAMP requirements as a foundation, the U.S. DoD specifically has defined additional cloud computing security and compliance requirements in their DoD Cloud Computing Security Requirements Guide (SRG). Cloud Service Providers (CSPs) supporting U.S. DoD customers are required to comply with these requirements.

Skyhigh Security has been granted a DoD Impact Level 2 (IL2) Provisional Authorization (PA) from Defense Information Systems Agency (DISA) leveraging Skyhigh Security's FedRAMP Moderate ATO. DoD IL2 is for non-Controlled Unclassified Information (non-CUI), which includes all data cleared for public release, as well as some DoD private unclassified information not designated as CUI or critical mission data that requires some minimal level of access control.

Skyhigh Security is actively pursuing DoD Impact Level 4 with multiple customers.

DoD IL4 is for Controlled Unclassified Information(CUI) which includes protection of data from unauthorized disclosure established by Executive Order 13556( Nov 2010); Education, Training, PII, PHI, SSN, Credit Card Information, Export Controls, FOUO and Law Enforcement Sensitive material and email.

FedRAMP

U.S. government program providing a standard approach to security, authorization and monitoring

The Federal Risk and Authorization Management Program (FedRAMP) is a U.S Federal Government Program that provides a standardized approach to security assessment, authorization, and continuous monitoring for Cloud Service Providers (CSP). The FedRAMP program has helped accelerate the adoption of secure cloud solutions, through the reuse of assessment and authorizations across other government agencies. FedRAMP leverages a standardized set of requirements established in accordance with the Federal Information Security Management Act (FISMA), and utilizing the Security Assessment Framework (SAF) and NIST Risk Management Framework (RMF) to continuously monitor, and improve the confidence and process maturity with the various baselines of security controls implemented by the Cloud Service Providers. In-order to support on-going operations with U.S Government customers to process, store or transmit U.S Government data; they are responsible for complying with the requirements established by the FedRAMP Program.

Skyhigh Security (CASB)

Skyhigh Cloud Access Security Broker (CASB) received FedRAMP High Authorization in 2020. The FedRAMP authorizations will allow these organizations to implement Skyhigh CASB, part of the Skyhigh Security Service Edge portfolio, to provide continuous, secure access for users anywhere, protect vital government information, and protect against today’s advanced threats.

Certifications and Compliance - Skyhigh Security (3)

General Data Protection Regulation (GDPR)

GDPR is a European Union (EU) regulation designed to provide individuals more control over their personal data

General Data Protection Regulation (GDPR)

GDPR is a European Union (EU) regulation designed to provide individuals more control over their personal data

The General Data Protection Regulation (GDPR) came into force on May 25, 2018 and is an EU regulation which provides individuals more control over their personal data. The GDPR was designed to harmonize data protection rules across the European Union. It provides rules relating to the protection of individuals with regard to the processing of personal data and rules relating to the free movement of personal data of data subjects in the European Union. The GDPR requires companies to implement appropriate technical and organizational measure to protect personal data.

For more information visit:General Data Protection Regulation (GDPR) Individual Data Request Form

Certifications and Compliance - Skyhigh Security (4)

SOC 2

Developed by the American Institute of CPAs (AICPA), SOC 2 defines criteria for managing customer data based on five "trust service principles"-security, availability, processing integrity, confidentiality and privacy

SOC 2

Developed by the American Institute of CPAs (AICPA), SOC 2 defines criteria for managing customer data based on five "trust service principles"-security, availability, processing integrity, confidentiality and privacy

SOC 2 Type II report is an attestation for the management of Skyhigh Security organization assertion that certain controls are in place to meet the AICPA's SOC 2 Trust Services Criteria (TSC).

The Trust Services Criteria are noted below:

  • Security - The system is protected against unauthorized access (both physical and logical).
  • Availability - The system is available for operation and use as committed or agreed.
  • Processing Integrity - System processing is complete, accurate, and authorized.
  • Confidentiality - Information that is designated "confidential" is protected according to policy or agreement.
  • Privacy - Personal information is collected, used, retained, disclosed, and disposed of in conformity with the commitments in the entity's privacy notice and with criteria set forth in Generally Accepted Privacy Principles issued by the AICPA.

The report contains an opinion from a CPA firm that states whether the CPA firm agrees with management's assertion. The opinion states that the appropriate controls are in place to address the selected TSCs and the controls are designed (Type I report) or designed and operating effectively (Type II report).

Certifications and Compliance - Skyhigh Security (5)

ISO/IEC 27001

ISO/IEC 27001 provides the best-known standard for information security management systems (ISMS) and their requirements

ISO/IEC 27001

The international standard for information security

It sets out the specification for an information security management system (ISMS). ISO 27001's best-practice approach helps organizations manage their information security by addressing people, processes, and technology.

Skyhigh Security was the first Cloud Access Security Broker to attain ISO 27001 Certification.

The certification also reflects the maturity of controls and practices that Skyhigh Security has in place.

Certifications and Compliance - Skyhigh Security (6)

Information Security Registered Assessors Program (IRAP)

IRAP is an Australian Signals Directorate (ASD) to ensure entities can access high-quality security assessment services

Information Security Registered Assessors Program (IRAP)

IRAP endorses individuals from the private and public sectors to provide security assessment services.

The Information Security Registered Assessor Program (IRAP) is a security compliance framework comprised of security assessment processes, and a security assessor program. It was developed by the Australia Signals Directorate (ASD), and the Australian Cyber Security Centre (ACSC), within the Australian government. IRAP supports Australian commonwealth government entities in maintaining their security assurance and risk management, as well as assessing cloud service providers and their cloud services’ security controls against the Australian government security policies and guidelines.

Skyhigh Security Service Edge (SSE) completed an IRAP assessment at the PROTECTED security classification level in 2023, and Skyhigh Cloud Access Security Broker (CASB) was assessed at the IRAP PROTECTED level in 2020. The IRAP assessment provides assurance to public sector organizations that Skyhigh Security’s powerful suite of data-aware cloud security technology has appropriate and effective security controls in place to manage highly sensitive data and infrastructures for Australian government agencies.

For more information visit:https://www.cyber.gov.au/acsc/view-all-content/programs/irap

Disclaimer: Not all certificates are applicable to all Skyhigh Security products. Contact Skyhigh Security for more details.

Certifications and Compliance - Skyhigh Security (2024)
Top Articles
The Most Difficult Crops to Grow and Why
How To Block Cryptomining Scripts In Your Web Browser
Bj 사슴이 분수
Somboun Asian Market
Online Reading Resources for Students & Teachers | Raz-Kids
Craigslist Kennewick Pasco Richland
Craigslist Mexico Cancun
What's Wrong with the Chevrolet Tahoe?
Mylife Cvs Login
Craigslist Phoenix Cars By Owner Only
LA Times Studios Partners With ABC News on Randall Emmett Doc Amid #Scandoval Controversy
Erin Kate Dolan Twitter
What Was D-Day Weegy
18443168434
Indiana Immediate Care.webpay.md
Uc Santa Cruz Events
Who called you from +19192464227 (9192464227): 5 reviews
Craigslist Free Stuff Merced Ca
Vintage Stock Edmond Ok
Bridge.trihealth
Teacup Yorkie For Sale Up To $400 In South Carolina
Gayla Glenn Harris County Texas Update
Dwc Qme Database
Winco Employee Handbook 2022
Evil Dead Rise Showtimes Near Pelican Cinemas
Knock At The Cabin Showtimes Near Alamo Drafthouse Raleigh
Weathervane Broken Monorail
Harbor Freight Tax Exempt Portal
Dr Seuss Star Bellied Sneetches Pdf
CVS Health’s MinuteClinic Introduces New Virtual Care Offering
Delete Verizon Cloud
San Jac Email Log In
Ihs Hockey Systems
Die wichtigsten E-Nummern
Ryujinx Firmware 15
Pfcu Chestnut Street
The Menu Showtimes Near Amc Classic Pekin 14
Metro 72 Hour Extension 2022
Why Gas Prices Are So High (Published 2022)
2008 DODGE RAM diesel for sale - Gladstone, OR - craigslist
Nearest Ups Office To Me
PruittHealth hiring Certified Nursing Assistant - Third Shift in Augusta, GA | LinkedIn
Best Restaurants West Bend
888-822-3743
ACTUALIZACIÓN #8.1.0 DE BATTLEFIELD 2042
Az Unblocked Games: Complete with ease | airSlate SignNow
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Stitch And Angel Tattoo Black And White
Fresno Craglist
Craigslist Pets Lewiston Idaho
Cbs Scores Mlb
Latest Posts
Article information

Author: Mrs. Angelic Larkin

Last Updated:

Views: 6120

Rating: 4.7 / 5 (67 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Mrs. Angelic Larkin

Birthday: 1992-06-28

Address: Apt. 413 8275 Mueller Overpass, South Magnolia, IA 99527-6023

Phone: +6824704719725

Job: District Real-Estate Facilitator

Hobby: Letterboxing, Vacation, Poi, Homebrewing, Mountain biking, Slacklining, Cabaret

Introduction: My name is Mrs. Angelic Larkin, I am a cute, charming, funny, determined, inexpensive, joyous, cheerful person who loves writing and wants to share my knowledge and understanding with you.