Sennheiser Communications A S Industriparken 27, DK-2750 Ballerup, Denmark

Similar documents
HeadSetup Pro Manager

Riverbed Xirrus Cloud Processes and Data Privacy June 19, 2018

END-USER MANUAL. Sennheiser HeadSetup Pro

Using Cohesity with Amazon Web Services (AWS)

Document Sub Title. Yotpo. Technical Overview 07/18/ Yotpo

Projectplace: A Secure Project Collaboration Solution

Technical Brief SUPPORTPOINT TECHNICAL BRIEF MARCH

WEBSCALE CONVERGED APPLICATION DELIVERY PLATFORM

A10 HARMONY CONTROLLER

Security Fundamentals for your Privileged Account Security Deployment

SECURE CLOUD BACKUP AND RECOVERY

HCX SERVER PRODUCT BRIEF & TECHNICAL FEATURES SUMMARY

SECURITY PRACTICES OVERVIEW

Data Security & Operating Environment

Oracle WebLogic Server 12c: Administration I

In this unit we are going to look at cloud computing. Cloud computing, also known as 'on-demand computing', is a kind of Internet-based computing,

Hardware: An USB connection must be available and a Sennheiser device must be connected to it.

Deploy. A step-by-step guide to successfully deploying your new app with the FileMaker Platform

Developing Enterprise Cloud Solutions with Azure

Course AZ-100T01-A: Manage Subscriptions and Resources

SRM University, Kattankulathur Department of Information Technology IT1019 Information Storage and Management Model Examination

SHAREPOINT 2016 ADMINISTRATOR BOOTCAMP 5 DAYS

OFFICE 365 GOVERNANCE: Top FAQ s & Best Practices. Internal Audit, Risk, Business & Technology Consulting

RICOH Unified Communication System. Security White Paper (Ver. 3.5) RICOH Co., Ltd.

Azure Webinar. Resilient Solutions March Sander van den Hoven Principal Technical Evangelist Microsoft

ticrypt DEPLOYMENT OVERVIEW AND TIMELINE Information about hardware, deployment, and on-boarding

20533B: Implementing Microsoft Azure Infrastructure Solutions

Security Overview of the BGI Online Platform

BeBanjo Infrastructure and Security Overview

For USA & Europe January 2018

AUTOTASK ENDPOINT BACKUP (AEB) SECURITY ARCHITECTURE GUIDE

Cloud Computing and Its Impact on Software Licensing

Sennheiser Softphone. Compatibility. Guide

Layer Security White Paper

Security and Compliance at Mavenlink

Launching a Highly-regulated Startup in the Cloud

Cloud Customer Architecture for Securing Workloads on Cloud Services

ENDNOTE SECURITY OVERVIEW INCLUDING ENDNOTE DESKTOP AND ONLINE

Storage Made Easy. Mirantis

Cloud Essentials for Architects using OpenStack

Storage Made Easy. SoftLayer

Web and API Apps in Azure

MD-100: Modern Desktop Administrator Part 1

Securing VMware NSX-T J U N E 2018

Architecting Microsoft Azure Solutions (proposed exam 535)

Oracle Database Cloud for Oracle DBAs Ed 3

CogniFit Technical Security Details

MigrationWiz Security Overview

CompTIA Mobility+ Certification

Microsoft Azure Course Content

Dell EMC Isilon with Cohesity DataProtect

Developing Microsoft Azure Solutions: Course Agenda

Course Outline. Lesson 2, Azure Portals, describes the two current portals that are available for managing Azure subscriptions and services.

Risk Intelligence. Quick Start Guide - Data Breach Risk

Developing Microsoft Azure Solutions

Javier Villegas. Azure SQL Server Managed Instance

ADMIN GUIDE. Sennheiser HeadSetup Pro Manager On Premises

Document Title: IT Security Assessment Questionnaire

Designing Database Solutions for Microsoft SQL Server 2012

Data Protection Modernization: Meeting the Challenges of a Changing IT Landscape

PCI DSS Compliance. White Paper Parallels Remote Application Server

Randy Pagels Sr. Developer Technology Specialist DX US Team AZURE PRIMED

The Nasuni Security Model

8x8 Virtual Office Government

Windows Server The operating system

Index. Pranab Mazumdar, Sourabh Agarwal, Amit Banerjee 2016 P. Mazumdar et al., Pro SQL Server on Microsoft Azure, DOI /

CIS Controls Measures and Metrics for Version 7

Designing Database Solutions for Microsoft SQL Server 2012

Version v November 2015

P a g e 1. Teknologisk Institut. Online kursus k SysAdmin & DevOps Collection

Installation Guide & User Manual Sennheiser HeadSetup for MAC

Request for Proposal

CIS Controls Measures and Metrics for Version 7

Commvault Backup to Cloudian Hyperstore CONFIGURATION GUIDE TO USE HYPERSTORE AS A STORAGE LIBRARY

Kenna Platform Security. A technical overview of the comprehensive security measures Kenna uses to protect your data

Exam : Implementing Microsoft Azure Infrastructure Solutions

Modernize Your Backup and DR Using Actifio in AWS

Azure-persistence MARTIN MUDRA

Information Security Policy

Implementing a Software-Defined DataCenter (20745)

COURSE OUTLINE: A Advanced Technologies of SharePoint 2016

Microsoft 365. A complete, intelligent, secure solution to empower employees. Integrated for simplicity. Built for teamwork. Unlocks creativity

Providing an Enterprise File Share and Sync Solution for

Application Lifecycle Management on Softwareas-a-Service

Libelium Cloud Hive. Technical Guide

Data safety for digital business. Veritas Backup Exec WHITE PAPER. One solution for hybrid, physical, and virtual environments.

Security Information & Policies

Microsoft Azure for AWS Experts

Implementing Microsoft Azure Infrastructure Solutions (20533)

Dynamic Object Routing

GateHouse Logistics. GateHouse Logistics A/S Security Statement. Document Data. Release date: 7 August Number of pages: Version: 3.

RSA pro VMware. David Matějů. RSA, The Security Division of EMC

MODIFYING TRADITIONAL APPLICATIONS FOR MORE COST EFFECTIVE DEPLOYMENT

2018 WTA Spring Meeting Are You Ready for a Breach? Troy Hawes, Senior Manager

M20742-Identity with Windows Server 2016

Version v November 2015

Single-Tenant vs. Multi-Tenant Enterprise Software

Acronis Hybrid Cloud Architecture Unified Centralized Data Protection Web-based User Interface Deployed On-premises or in the Cloud.

Citrix Workspace. Lausanne Laurent Strauss Christophe Beaugrand

THE HYBRID CLOUD. Private and Public Clouds Better Together

Transcription:

Sennheiser Communications A S Industriparken 27, DK-2750 Ballerup, Denmark www.sennheiser.com 1396 01-2019

Technical FAQ Paper HeadSetup Pro Manager Hosting, security, data storage and business continuity

HeadSetup Pro Manager Cloud End-User HeadSetup Pro IT Admin Introduction Sennheiser HeadSetup Pro Manager is a cloud-based enterprise SaaS (Software as a service) from Sennheiser Communications A/S. It provides asset, update and configu ration management as well as reporting capabilities for Sennheiser headsets and speakerphones. Solution Overview The solution consists of two versions: HeadSetup Pro The client application installed locally on each computer managing the enduser s headsets or speakerphones. HeadSetup Pro Manager The IT administrator version hosted in Microsoft Azure.

Hosting Provider, Location & Scalability Who is the hosting provider? Microsoft Azure cloud. Where is the solution hosted? The solution is hosted and the data is stored in 1 of the 17 Microsoft Azure regions. This region is Northern Europe (Ireland). What type of infrastructure is used? HeadSetup Pro Manager is a SaaS (Software as a service) solution. It uses Microsoft Azure cloud services and Microsoft Azure SQL/NoSQL databases, with Microsoft operating all infrastructure, nonapplication software, and all typical SaaS services, such as backup and encryption of stored data. Data Access, Encryption & Security How is the data segregated? Customer data is stored on a multitenant basis. This means that customers share databases with customer data logically segregated. How is the data encrypted? Data is encrypted both in transition and at rest (inactive data stored in databases). In transition All network traffic between the solution entities is secured through TLS1.2 with 256-bit AES encryption If enabled in browser. At rest - Encrypted with 256-bit AES using Azure Transparent Data Encryption. Sennheiser has no access to the underlying Microsoft Azure platform, either hardware or software. The Sennheiser solution is designed to fully leverage the capabilities of the existing Microsoft cloud platform. How is scalability of the solution achieved? The solution is scaled by using Microsoft Azure scale-in and scale-out capabilities for the Azure cloud service platform and Azure SQL/NoSQL databases.

How is the data backed up? The data is automatically backed up by Microsoft Azure and can be restored up to 14 days back. Who can access the data? Data can be accessed by the tenants after logging into HeadSetup Pro Manager. Sennheiser restricts internal access to the data on a need-to-know basis for operating, supporting, developing, and monitoring the solution. Has the security of the solution been reviewed by a 3rd party? Yes, the most recent review took place in April 2016. The solution was assessed against OWASP top 10, SANS top 25, and other security vulnerability rosters using commercial tools such as Acunetix and manual testing. All relevant issues were fixed before the release. What ports are used between HeadSetup Pro/ HeadSetup Pro Manager? Microsoft Azure Cloud Ports Comment 443 Network traffic - Default internet port for secure traffic https 443 Logging HeadSetup Pro & Frontend analytics. Default internet port https HeadSetup Pro authentication at HeadSetup Pro Manager. As part of distributing the end-user client to a user, an account-specific encrypted file is deployed and stored on the end-user PC. This allows the client to connect to the appropriate tenant account. Data Collection What data is collected? The data collected can be divided into the four main parts below (with examples). Auto-collected data for the solution to operate Device information, eg ID, FW version. Computer information, such as operating system and type, model. Call information, such as number of calls and duration. Softphone information such as softphone name, version and usage for reports. Personal identifying data Name Email Telephone number Ip Address Mac Address Machine name Company data Tenant data entered during registration e.g. email, company name and country User data retreived when available; Officename, country and city Error logging Unexpected behavior and usage of Sennheiser products to provide support and improve overall product line Timestamps Timestamps are collected on the system of the users and the devices. This is used to determine the usage of the system and create reports. These timestamps have an accouracy of 2 hours.

Reports & APIs What type of reports are provided? Sennheiser offers a number of prebuilt reports that are accessed via the HeadSetup Pro Manager web interface. Can a tenant access the data directly? No, this is currently not supported. Business Continuity & Disaster Recovery Does the solution offer disaster recovery? Solution and data can be recovered unless both the backup data and live data are destroyed simultaneously in the Microsoft data center. Microsoft Azure offers geo-replication that would mitigate this theoretical risk. Support For further information on Sennheiser HeadSetup Pro Manager or support questions, please contact Sennheiser Communications A/S at hsuphelp@senncom.com