Upload
others
View
10
Download
0
Embed Size (px)
Citation preview
Secure Box PilotInformation Session
Jill Cozen-HarelErik Wieland
Secure Box: Background
1. Launched UCSF Box in February 2013
• Many requests to allow UCSF PHI on Box
2. Box signed a UCSF BAA in June 2014• Technical solution required to
protect UCSF PHI on Box
3. Technical solution: selected CipherCloud in December 2015
4. Secure Box architecture, build, internal testing in Spring 2016
5. Piloting Secure Box in Summer 2016
6. Launching Secure Box in Fall 2016
UCSF Box2013
Box BAA2014
Technical Solution
2015Secure Box
2016
8/12/16Secure Box – Info Session2
Technical Solution: CipherCloud
What is CipherCloud? CipherCloud is a security solution
for cloud applications, which allows us to apply UCSF’s minimum security standards (e.g., restrict access to and encrypt sensitive data) to files on UCSF Box. CipherCloud works with UCSF’s
existing data loss prevention (DLP) solution, which is already used to keep PHI from being emailed outside of UCSF.
How does CipherCloud work?1. Files are added to or changed on
UCSF Box2. CipherCloud sends the file to DLP3. DLP scans the file looking for PHI
and tells CipherCloud the result4. When PHI is found CipherCloud
takes action
8/12/16Secure Box – Info Session3
Secure Box: How It Works
1. Each user gets a Secure folder inside their UCSF Box folder• Folder named [email protected]• All files in this folder are encrypted, external collaborators are not allowed
2. Outside of the Secure folder, all changes are scanned in real time• CipherCloud sends new and changed files to DLP for scanning• If DLP detects UCSF PHI then CipherCloud encrypts the file in place,
leaves a marker file and sends email, and removes external collaborators• UCSF Box login and CipherCloud agent required to open encrypted files• If UCSF PHI is removed, the file is unencrypted and the marker file is
deleted
There are two pieces to Secure Box…
8/12/16Secure Box – Info Session4
Secure Box Pilot FAQsWhy am I in the pilot?
Either you or your manager asked to be part of the pilot, or we found matches to PHI in your UCSF Box account.What happens next?
First we will create your secure folder and scan your Box account for PHI. Then your Box account will have all of the Secure Box features. How long does the pilot last?
The pilot will last until we launch Secure Box this Fall.
How will I know what to test?We created a survey with test cases. You can complete some or all of the cases, and submit the survey as many times as you want. How do I get the agent, app?
We are pushing the agent to all computers managed by IT Field Services. You can also download the agent from software.ucsf.edu. The CipherCloud app for iOS (iPhone, iPad) is available on the iTunes App Store, and for Android on Google Play.
8/12/16Secure Box – Info Session15
Secure Box Demo
1. Getting the agent, apps2. Your secure folder3. Real-time scanning for UCSF PHI4. Notifications5. Test cases6. Providing feedback
8/12/16Secure Box – Info Session5
Secure Box Demo: Getting the Agent, Apps
Mac agent• CipherCloud for Box
Windows agent• CipherCloud for Box
iOS (iPhone, iPad) apps• Box app for iPhone and iPad• CipherCloud app
Android apps• Box app• CipherCloud for Box app
8/12/16Secure Box – Info Session6
Secure Box Demo: User Guide
http://tiny.ucsf.edu/securebox
8/12/16Secure Box – Info Session7
Secure Box Demo: Using the Mac Desktop Agent
8/12/16Secure Box – Info Session8
Secure Box Demo: Using the iOS Mobile App
8/12/16Secure Box – Info Session9
Secure Box Demo: Using the Android Mobile App
8/12/16Secure Box – Info Session10
Secure Box Demo: Your Secure Folder
8/12/16Secure Box – Info Session11
Secure Box Demo: Real-time Scanning
Trigger word to simulate UCSF PHI: CipherCloudTesting12345!
8/12/16Secure Box – Info Session12
Secure Box Demo: Notifications
8/12/16Secure Box – Info Session13
Secure Box Demo: Test Cases
http://tiny.ucsf.edu/secureboxpilot
8/12/16Secure Box – Info Session14
Secure Box Pilot ResourcesPeople Project Manager: Byron DeSoto Service Managers: Jill Cozen-
Harel, Erik Wieland
Documentation Secure Box Project website Secure Box Pilot Testing survey UCSF CipherCloud Agent Install
and User Guide
Downloads Mac agent: CipherCloud for BoxWindows agent: CipherCloud for
Box iOS (iPhone, iPad)
• Box app for iPhone and iPad• CipherCloud app
Android• Box app• CipherCloud for Box app
8/12/16Secure Box – Info Session16