Technical: DQ Security
Please use this discussion thread to ask any technical questions about Data Quality (DQ) Security. Below are some frequently asked questions and resources to get you started.
Top Links
Data Deletion / Metadata Purging
Q: Can Files And Partitions Or Infrastructure Media Be Deleted?
A: Yes, The Postgres Database Can Be Deleted
#deletion
Q: Can The Solution Automatically Purge Data According To Configurable Rules / Settings?
A: Yes we have automatic purging as well as customizable time-based data retention
https://docs.owl-analytics.com/data-retention/time-based-data-retention
Q: Will You Erase / Delete / Destroy Media Containing Classified Data?
A: We Do Not Handle Physical Data Storage
Remote Access
Q: Remote Access To Application Or Service Must Be Done Through Secure Connection e.g. VPN, HTTPS?
A: Yes, HTTPs And SSL Can Be Enabled
Auditing
Q: Can We Audit Usage By User?
A: Yes, Customer Can Conduct Security Audit Of User Activity. User Creation Governed Through Register -> Request -> Granting Process
Q: Can You Review Authorizations On A Regular Basis?
A: Yes, A Security Audit Feature Is Built Into The Application. Roles And Access Levels Can Be Reviewed
System Access
Q: Can Default Accounts And Passwords Be Disabled On Each System And Application?
A: Yes, Application Does Not Need Root Access To Run
Passwords
Q: Can Passwords Be Made To Comply With Our Password Policy?
A: Yes, Passwords Can Be Customized To Adhere To Your Policies
Q: Can Passwords Be Stored In Encrypted, Salted, Hashed, With Cryptographic Best Practices e.g. Argon2, PBKDF2, scrypt, yescrypt, bcrypt, SSHA-256?
A: Yes, Passwords Are Stored, Encrypted, And Hashed In-Transit. Passwords Not Displayed On UI
Authentication
Q: Can We Re-Authenticate Users Prior To Access Information?
A: Yes, Authentication Required To View Data
Q: Can Users Authenticate Through Multi-Factor?
A: No, Not A Default Setting
Q: Can You Connect Our Federated Authentication WIth OAuth Or SAML V2 Protocol?
A: Yes SAML
Certificates
Q: Can We Ensure A Signed TLS Certificate Be Used To Provide HTTPS To Front-End WEb Servers?
A: Yes, You Can Use Your Own Certificate For HTTPs
Encryption
Q: Can Classified Data Be Stored Encrypted?
A: Yes, We Store AES-256 Encrypted
Q: Is Each Data Access Or Transfer e.g. API, FTP, mail Containing Data Encrypted?
A: HTTP for APIs
Q: Can Encryption Keys Be Managed By Customer?
A: Yes
Q: Are Admin Flows Encrypted e.g. TLS v1.2 Or Higher?
A: Yes
Backup Strategy
Q: Can A Backup Strategy Be Implemented? Can Backups Be Externalized Out Of Production Site?
A: Yes, This Would Be Your Standard HA / DR Strategy
Q: Do customers need a disaster recovery instance?
A: The DQ metastore is the crux of disaster recovery. Feel free to utilize a cloud Postgres or do a backup of your Postgres instance. There is no need to replicate the application.
Security Architecture
Q: Does Collibra DQ Respect Security Customer Security Architecture Principles Such As Using Reverse Proxy In Front Of Web App Exposed To Internet e.g. WAF?
A: We Do Not Expose Endpoints Outside Your On-Prem VPN Or Firewall
Penetration Tests
Q: Do You Perform Penetration Tests?
A: Yes
GDPR / Regulatory Compliance
Q: Does Your Application Comply With Applicable Laws And Regulations In EU?
A: Yes, We Install Within Your Infrastructure So Long As That Applies To EU Standards