|
The UK Government's Code of Connection (CoCo) is a set of official IT Security "basline" standards which must be met for Local Authorities to keep access to the Government Connect Secure Extranet (GCSx).
GCSx is a secure private Wide-Area Network (WAN) that enables communication between local authorities and Government departments such as Work and Pensions and Children Schools and Families.
Several of Softek's solutions assist LA's to achieve CoCo compliance. Such solutions are also useful for Police Forces in the United Kingdom who are connected to the Police National Network (PNN).
- Restricting Email / Enforcing Classification of Email and Documents
CoCo compliance requires you to enforce a policy whereby users are unable to forward, or systems are unable to AUTO-forward emails which may be classified or sensitive.
By enforcing the policy requirement to "Protective Mark" all emails AND documents using software such as JanuSEAL or Overtis Vigilance Pro, you are able to totally secure email communications using a gateway email filtering solution such as MailSecure.
janusSEAL for Outlook Safe Domain Extension
To assist with GCSX Code of Connection (CoCo) compliance, janusSEAL for Outlook Safe Domain extension warns and/or prohibits users from sending messages to domains where the delivery channel does not have a high enough security rating for the message.
- can warn them when sending sensitive messages to a large number of recipients
- can prevent them from sending sensitive messages to a large number of recipients
- can remove recipients from sensitive messages if there is no secure network to send it safely to them
- can correct (promote) email addresses when the sender accidently uses a recipient's public email address for a sensitive message when they should have used their private network address
- Read more.
- Two Factor Authentication
A key element of CoCo is that users working remotely must use secure two-factor authentication instead of simple passwords.
Two-factor authentication requires a user to present two different factors (or proof) of identity – something you know and something you have. These factors are usually a secret PIN (something you know) and a tangible "token", which can be a key fob device, a USB device (such as SafeStick), or a mobile device such as a mobile phone, iPhone or BlackBerry (something you have).
Read more on Deepnet Security Authentication solutions
- Removable Device Security
BlockMaster has a well-established, world wide and successful track record when providing fully encrypted, tamperproof and managable USB memory sticks to Government and other local authorities.
In 2009 the UK NHS made SafeStick and SafeConsole their solution of choice when looking for removable media security.
Read more on SafeStick and SafeConsole USB Encryption and management solution
- Insider Threat Management / Data Leakage Prevention
Overtis Vigilance Pro gives you total control over your environment - control who has access to what, when, how and for what purpose.
A complete Insider Threat Management and Data Leakage Prevention solution, policies can prevent dissemination of information via any exit point - email, webmail, IM, FTP, Skype, social networking sites, screen grabs etc. etc. Even printing of sensitive documents can be restricted on the fly.
Vigilance Pro has the UK Government CESG / CCTM claims tested approval mark. This mark confirms the suitability of VigilancePro for use by Government, Military, UK Public and also commercial sectors
- USB / Removable Device Control
It is a requirement that not only do you need to encrypt all data held on portable devices, but you also restrict their use.
DeviceLock provides total control over all removable device use.
CryptShare enables you to securely and easily transfer encrypted data files without the limits, resource consumption and insecurity FTP or Email brings.
- Encryption of Data at Rest - PCI DSS and CoCo.
HDD [hiddn] technology, provides a range of top of the line security solutions which meet the very highest military grade encryption standards - EAL4+, FIPS 140-3 and NATO restricted. <more>
|