Policies and Procedures: Information Security

Prev Next

The purpose of the Information Security Policy is to state the various ways in which Ripple Treasury maintains the security and privacy of sensitive and confidential information for both Clients and Ripple Treasury.  Ripple Treasury uses state-of-the-art software and other technologies to prevent unauthorized users from accessing Ripple Treasury systems, especially those accessible from the Internet.

Security Standards

Ripple Treasury recognizes the importance of installing and maintaining required security standards. 

These standards are:

  1. Install and maintain a firewall configuration to protect data

  2. Do not use vendor supplied defaults for system passwords and other security parameters

  3. Protect stored data

  4. Encrypt transmission of cardholder data and sensitive information across public networks

  5. Use and regularly update anti-virus software

  6. Develop and maintain secure systems and applications

  7. Restrict access to data by business need-to-know

  8. Assign a unique ID to each person with computer access

  9. Restrict physical access to cardholder data

  10. Track and monitor all access to network resources and cardholder data

  11. Regularly test security systems and processes

  12. Maintain a policy that addresses information security

User Access

  • All individuals have their own unique IDs and usernames on all systems and devices.

  • All accounts require a password or other authentication control for usage.

  • Remote access and administration require at least two-factor authentication.

  • Vendor accounts must be disabled when not in use and access to such accounts is monitored when they are enabled.

  • Generic, default and built-in accounts are removed or disabled.

  • Shared accounts, including shared administrator accounts, must not be used in favor of individual accounts.

Technology

The layers of technology Ripple Treasury employs to help ensure the confidentiality of all transactions:

Ripple Treasury Security Protocols

  • Alert Logic, Inc. provides scanning services to detect and/or prevent system intrusions. These scans are performed on all Ripple Treasury systems including those systems devoted to credit card data / PCI.  These scans are performed weekly.

  • External and Internal Network Vulnerability & Penetration Tests will be conducted at least once annually. Customers may conduct their own penetration tests which will be allowed with proper documentation and permission.  Client penetration tests must be coordinated with Ripple Treasury and results of penetration tests must be shared with Ripple Treasury at the conclusion of the test. 

  • Incidents escalated by Alert Logic will be reviewed by the Security and Compliance team. If the incident is serious in the opinion of these reviewers, it will be escalated in order to follow the Security Incident Protocol.

  • Web traffic uses https with TLS 1.2.

  • Database backup encryption uses AES 256.

  • Certificates must use at least 2048-bit keys.

  • Certificates and keys should expire within 2 years.

  • It is required that all employees lock their computers when stepping away from their workstations.

  • To ensure the privacy of customer information, all employees are always required to maintain a Clean Desk. Any documents of a sensitive nature should be placed in a secure location. 

  • IT monitors servers and provides anti-virus updates when appropriate.

  • Anti-virus protection should be installed on client computers.

  • Once a secure browser connection is established, client users need to provide a business ID, username, and a password to enter the application (unless using SSO). Users should follow password policy best practices. 

  • After a period of inactivity, a user’s current session on the Ripple Treasury application will automatically time-out. To restart a session, a user will have to re-enter their username and password.

  • Initial passwords within the Ripple Treasury system must meet a 14-character minimum by default. This option is configurable by the client to meet their password rules. 

  • Ripple Treasury recommends the use of multi-factor authentication via RSA SecurID or Symantec VIP to provide another level of access security to safeguard confidential information and secure the initiation and approval of payments and other sensitive transactions.