Regulations and IT Compliances Requirements
How CoreVault Addresses Compliance Requirements
The IT compliance requirements for most of regulations / standards can be categorized into four key sections. The Table below shows how CoreVault addresses each one of them.
| Category of compliance | How CoreVault addresses |
| • Privacy / confidentiality of information - Protect data from unauthorized disclosure - Implies technologies such as encryption and access control to restrict access to data |
• Data is encrypted AES 256-bit before being transmitted over the WAN • Data stored Online and/or Archive is encrypted • Encryption is FIPS 140-2 certified • Access control to data with full audit trail and reporting logs |
| • Availability of information - Ensure that information is available when needed through business and service uptime assurance - Data protection - Business Continuity and Disaster Recovery technologies and plans |
• N+1 and grid architecture ensures high availability through failover in case of system disruptions • Disk based retention for fastest recovery • Automated and verifiable backup/recovery process with built-in SLA module for reporting and auditing purposes • Built-in data replication capability for Online and Archive storage enables emergency plans for business continuity • CoreVault's architecture implements fast and reliable backup/recoveries at off-site location for DR purposes • CoreVault's Value Beyond Software provides best practices and support for Business Continuity plans and Disaster Recovery Drills implementation and auditing purposes |
| • Integrity of data - Protecting data from unauthorized modification ensuring its accuracy - Implies technologies such as encryption and access control (authentication) - Integrity checks - Audit trails (logging system events and physical access) |
• Data is encrypted AES 256-bit before being transmitted over the WAN • Data is stored encrypted • Encryption is FIPS 140-2 certified • Access control to data with full audit trail and reporting logs • Data integrity validation through Autonomic Healing and Restore Validation |
| • Retention - Preservation of information in an unalterable form for specified periods of time - With or without requirements for data destruction - Ability to set policies and manage the lifecycle of data |
• CoreVault's Archive provides long term disk based retention with data destruction certificate • Intuitive GUI makes it easy to implement and manage retention rules and policies • Long term data is stored encrypted |
