From 82c457edf1a507035a34d08ddb151baabddbe767 Mon Sep 17 00:00:00 2001 From: PJ Hyett Date: Mon, 28 Jun 2010 13:42:41 -0700 Subject: update security page with rackspace info --- _posts/2009-06-23-security.markdown | 35 ++++++++++++++++++++++++++++++----- 1 file changed, 30 insertions(+), 5 deletions(-) diff --git a/_posts/2009-06-23-security.markdown b/_posts/2009-06-23-security.markdown index 08f7f4e..9c58758 100644 --- a/_posts/2009-06-23-security.markdown +++ b/_posts/2009-06-23-security.markdown @@ -6,13 +6,38 @@ categories: "Site Policy" We know your code is extremely important to you and your business and we're very protective of it. After all, GitHub's code is hosted on GitHub, too! -Physical security measures --------------------------- +Physical Security +----------------- -GitHub's infrastructure is hosted on [Rackspace](http://rackspace.com), a publicly-traded company that's committed to keeping your data secure. They provide us with state-of-the-art servers protected by biometric locks and round-the-clock interior and exterior surveillance monitoring. Only authorized personnel have access to the data center. 24/7/365 onsite staff also provides additional protection against unauthorized entry and security breaches. +* Data center access limited to Rackspace data center technicians +* Biometric scanning for controlled data center access +* Security camera monitoring at all data center locations +* 24x7 onsite staff provides additional protection against unauthorized entry +* Unmarked facilities to help maintain low profile +* Physical security audited by an independent firm -Software security measures --------------------------- +System Security +--------------- + +* System installation using hardened, patched OS +* System patching configured by Rackspace to provide ongoing protection from exploits +* Dedicated firewall and VPN services to help block unauthorized system access +* Data protection with Rackspace managed backup solutions +* Dedicated intrusion detection devices to provide an additional layer of protection against unauthorized system access +* Distributed Denial of Service (DDoS) mitigation services based on Rackspace PrevenTier system +* Risk assessment and security consultation by Rackspace professional services teams + +Operational Security +-------------------- + +* ISO17799-based policies and procedures, regularly reviewed as part of the Rackspace SAS70 Type II audit process +* Systems access logged and tracked for auditing purposes +* Secure document-destruction policies for all sensitive information +* Fully documented change-management procedures +* Independently audited disaster recovery and business continuity plans in place for Rackspace headquarters and support services + +Software Security +----------------- In addition to Rackspace's system monitoring, we also employ a team of 24/7/365 server specialists at [Anchor Hosting](http://www.anchor.com.au/dedicated-hosting/dedicated-support.py) to keep our software and its dependencies up to date eliminating potential security vulnerabilities. They have also setup a wide range of monitoring solutions for preventing and eliminating attacks to the site. -- cgit v1.3.1