{"id":6456,"date":"2020-07-30T17:02:26","date_gmt":"2020-07-30T16:02:26","guid":{"rendered":"https:\/\/www.solidapps.co.uk\/blog\/?p=6456"},"modified":"2020-07-30T17:02:26","modified_gmt":"2020-07-30T16:02:26","slug":"can-you-really-trust-your-data-in-the-cloud","status":"publish","type":"post","link":"https:\/\/www.solidapps.co.uk\/blog\/2020\/07\/can-you-really-trust-your-data-in-the-cloud\/","title":{"rendered":"Can You Really Trust Your Data in the Cloud?"},"content":{"rendered":"\n<p>As more and more software is deployed on the cloud, many might question how secure these cloud-based applications really are compared with traditional on-premise software. To some, \u201cthe cloud\u201d sounds like data is magically jettisoned to some nebulous place in the atmosphere\u2014and all that data is now floating out there (securely, somehow) in the sky.<\/p>\n\n\n\n<p>In actuality, the biggest difference in cloud computing is the physical location of servers. You still control access to all your data. You still control who has access and at what permission level. You still control what applications to use. And so on.<\/p>\n\n\n\n<p>But, let\u2019s face it: You can\u2019t <em>see <\/em>your servers, so it <em>feels<\/em> unsafe. However, the reality is quite different.<\/p>\n\n\n\n<p>Dassault Syst\u00e8mes SOLIDWORKS has placed security at the heart of its application development process whether for desktop or applications on the cloud-based the <strong>3D<\/strong>EXPERIENCE\u00ae platform. Let\u2019s take a look at some of the safeguards that have been put in place to keep you and your valuable IP safe.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/blogs.solidworks.com\/solidworksblog\/wp-content\/uploads\/sites\/2\/2015\/03\/cloudguy2.png\" alt=\"\" class=\"wp-image-24968\"\/><\/figure><\/div>\n\n\n\n<p><strong>Data Protection on the Platform<\/strong><\/p>\n\n\n\n<p>Safeguarding data is essential to ensuring availability, integrity, and confidentiality of the<strong> 3D<\/strong>EXPERIENCE platform. Dassault Syst\u00e8mes SOLIDWORKS deploys industry best practices for authentication, access control, encryption, injection detection and prevention, auditing, and server hardening. Standards include MITRE\u2019s Common Weakness Enumeration (CWE&#x2122;) and many approaches refined by the Open Web Application Security Project (<a href=\"https:\/\/owasp.org\/\" target=\"_blank\" rel=\"noreferrer noopener\">OWASP<\/a>).<\/p>\n\n\n\n<p><strong>Secure and More Inclusive Design Reviews<\/strong><\/p>\n\n\n\n<p>You can safely conduct real-time digital mock-up reviews accessible to everyone on your team, including those without CAD knowledge, which enables all non-engineers, such as marketing, sales, and management to easily participate in the product development cycle. No more managing tons of project emails and attachments, which can potentially open the door to serious security issues or expose IP to hackers.<\/p>\n\n\n\n<p>Disagreements among co-workers, managers, or clients are readily resolved by reviewing communication threads within the project community from a single secure platform. This makes it easy to solve differing recollections over what was communicated\u2014or not communicated\u2014in the past without the frustration of digging through countless emails. More importantly, you always have full control over who sees what data and when so valuable IP is always protected.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter\"><img decoding=\"async\" src=\"https:\/\/blogs.solidworks.com\/solidworksblog\/wp-content\/uploads\/sites\/2\/2020\/07\/AdobeStock_216253518-800x472-1.jpg\" alt=\"\" class=\"wp-image-44806\"\/><\/figure><\/div>\n\n\n\n<p><strong>Authentication<\/strong><\/p>\n\n\n\n<p><strong>3D<\/strong>Passport provides authentication and authorization services while supporting two-factor&nbsp;authentication and single sign-on (SSO) capabilities within the <strong>3D<\/strong>EXPERIENCE platform. Users&nbsp;are fully authenticated and assigned specific licenses and policies. Events and actions remain&nbsp;traceable. Certificates are managed by a certificate authority and key stores. A strong password&nbsp;policy and sound user policy for access control lists serve to protect the <strong>3D<\/strong>EXPERIENCE platform&nbsp;against brute force, privilege escalations, and session hijacking.<\/p>\n\n\n\n<p><strong>Confidentiality and Integrity<\/strong><\/p>\n\n\n\n<p>Access to data is restricted via access lists. Only the authorized roles, organizations, or collaborative&nbsp;spaces can access data stored in the <strong>3D<\/strong>EXPERIENCE platform. Authorization is implemented&nbsp;through business logic and database layers to ensure data integrity and strict confidentiality throughout the data lifecycle.<\/p>\n\n\n\n<p><strong>Encryption<\/strong><\/p>\n\n\n\n<p>Primary defenses are implemented to prevent attacks and control access. Robust encryption algorithms protect data in transit and strong access controls ensure data is stored securely (see Confidentiality and Integrity, above). File transfers on the cloud are secured via HTTPS\/TLS.<\/p>\n\n\n\n<p><strong>Injection, Scripting, and Parser Hardening<\/strong><\/p>\n\n\n\n<p>The <strong>3D<\/strong>EXPERIENCE platform was designed to be resilient to attacks like SQL, Parameter,&nbsp;Commands, and OS Injections. Protective measures employ several layers to guard against&nbsp;cross-site scripting (XSS). XML parsers are hardened using best practices to prevent XXE attacks.&nbsp;The software architecture embeds input validation and the use of a parameterized interface is&nbsp;encouraged and monitored for compliance.<\/p>\n\n\n\n<p><strong>Convenience <em>and<\/em> Security<\/strong><\/p>\n\n\n\n<p>Dassault Syst\u00e8mes SOLIDWORKS leverages industry-leading practices and is actively involved with the OWASP as a part of continuous efforts to minimize risk and protect customer data. Our security programs put particular emphasis on the secure software development life cycle (SDLC) approach used to build the <strong>3D<\/strong>EXPERIENCE platform and applications.<\/p>\n\n\n\n<p>Originally posted in the <a href=\"https:\/\/blogs.solidworks.com\/solidworksblog\/2020\/07\/can-you-really-trust-your-data-in-the-cloud.html\" target=\"_blank\" rel=\"noreferrer noopener\">SOLIDWORKS Blog<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>As more and more software is deployed on the cloud, many might question how secure these cloud-based applications really are compared with traditional on-premise software. To some, \u201cthe cloud\u201d sounds&hellip; <\/p>\n","protected":false},"author":1,"featured_media":6457,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[168,5],"tags":[169,25],"class_list":["post-6456","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-3dexperience","category-solidworks","tag-3dexperience","tag-solidworks-2"],"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/posts\/6456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=6456"}],"version-history":[{"count":1,"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/posts\/6456\/revisions"}],"predecessor-version":[{"id":6458,"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/posts\/6456\/revisions\/6458"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/media\/6457"}],"wp:attachment":[{"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=6456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=6456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.solidapps.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=6456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}