This indicates that a vendor successfully recognizes a particular standard and encompass most, if not all, of that key standard.
Complying with Data Security Requirements
Organizations of all sizes work to adhere to industry security standards and emerging personal data protection requirements, but without the right solutions and policies, manually gathering the required data and creating audit reports can add hundreds of hours to the IT workload.
Some of the most-discussed data security compliance requirements and regulations include:
- GDPR
- GLBA
- HIPAA and HITECH
- PCI DSS
- SOX
Discover how to comply with these and other data security compliance requirements.
How GoAnywhere MFT Helps with Compliance
GoAnywhere MFT can help you meet a variety of security standards by providing file transfer encryption technologies, file transfer monitoring, detailed audit logs and reporting, granular user permissions, and flexible options for sending files securely.
Compliance & Cybersecurity
Security regulations are in place for a reason. Misunderstanding or failing to meet current data security standards can — and do — lead to costly data breaches. Following regulations and enforcing compliance keeps your organization on track to safeguard data and detect violations. The importance of compliance in an organization can be tied back to cybersecurity. Compliance requirements often outline the minimum conditions to be considered secure — a compliance blueprint that organizations can follow to achieve a strong cybersecurity stance.
Common Data Security Compliance Standards
This collection of resources is designed to help you stay on top of the latest compliance information so you can strengthen security in your organization and face compliance audits with confidence.
Jump to a specific data security regulation page:
PCI DSS
What is PCI DSS?
PCI DSS (Payment Card Industry Data Security Standard) works to ensure credit card data is stored, processed, and transmitted in a secure way. Learn more about how GoAnywhere helps achieve PCI compliant file transfer.
HIPAA & HITECH
What is HIPAA and HITECH?
HIPAA (Health Insurance Portability and Accountability Act) serves to safeguard medical information with a series of data privacy and security provisions. Learn how GoAnywhere helps with HIPAA compliant file transfer and file sharing.
GDPR
What is GDPR?
The General Data Protection Regulation (GDPR) was designed to protect the personal data of EU-based individuals, while harmonizing data privacy laws throughout the EU. Learn more about how GoAnywhere assists with GDPR compliant file transfer.
FISMA
What is FISMA?
The Federal Information Security Management Act (FISMA) establishes a set of security guidelines that help to reduce the security risk to federal data. Learn more about how GoAnywhere helps with FISMA compliant file transfer.
What is Data Security Compliance?
Data security compliance rests on the idea that there are steps organizations can take to safeguard the data they collect and process to ensure it is secure. Different organizations – governments, governing bodies, and industry-related groups – establish basic guidelines that businesses should follow to safeguard the data they collect. Complying with regulations often means ensuring your organization is using secure file transfer protocols, encryption processes, and today’s technology.
Keep Reading: How to Help Ensure Compliance with Data Privacy Laws
What is Compliant File Sharing & Transfer?
Compliant file sharing varies from requirement to requirement, but most often requires using encrypted connections to share files with trading partners both on-premises and in the cloud, encrypting files, and ensuring data integrity. Proving compliance typically involves demonstrating secure data transfer methods, and providing audit logs to an auditor. Some solutions, including GoAnywhere MFT, track file movements and give you the ability to pull the logs as needed. Compliant file sharing comes down to awareness: who is viewing your files, where are your files moving to, and are they secure during transfer and in storage?
Compliant file transfers should an important piece of your cybersecurity strategy. Most compliance requirements outline the minimum standards that organizations should follow to safeguard data. Following — or exceeding — requirements and regulations when it comes to file transfer can help you avoid interception and tampering, as well as reduce the risk of data breaches.
Maintaining Compliance
Maintaining compliance varies by requirement. Many compliance requirements outline guidelines for data collection, user access, file transfer, and security both in transit and in motion. Organizations need technical, administrative, and managerial controls in place, as well as organizational policies, to fully enforce and ensure compliance from the top down. Your business can comply by:
- Developing a procedure to quickly locate and delete personal data about a person
- Simplifying your method of safely disposing of customer information when requested to do so
- Ensuring you can appropriately audit your records to find all personal data, including any external companies you’ve shared information with
See how compliance requirements vary:
- GDPR and Data Privacy After Brexit: What's Next?
- Australia's CDR: What is it and Why Does it Matter?
- HIPAA and HITECH: How GoAnywhere MFT Helps the Healthcare Industry Thrive
- PDPA in Singapore Helps Protect Personal Data
- What is Canada's PIPEDA and Who does it Impact?
- What is the California Consumer Privacy Act?
Latest Compliance Resources
Read the most recent compliance-related blogs from GoAnywhere. Can’t find the compliance requirement or regulation you’re looking for? Contact us to learn how GoAnywhere can help you.
Data Sheets for Types of Compliance
You need compliant file transfer, and GoAnywhere has the solution. Get the detailed specs on how GoAnywhere MFT helps achieve compliant file transfer no matter your industry or region:
Type of Compliance | About | Get the Datasheet |
---|---|---|
Overview — How GoAnywhere Helps | Learn how GoAnywhere MFT can help you manage and secure the exchange of private data in order to comply with a variety of compliance laws and regulations. | Meeting Security Standards with GoAnywhere MFT |
FISMA | An effective managed file transfer solution is critical for helping government agencies meet strict security regulations and policies. | Simplified, Secure and Automated Managed File Transfer Solutions for FISMA |
GDPR | GoAnywhere offers several popular encryption technologies to help businesses secure sensitive data and comply with the GDPR. | Meeting GDPR Requirements with GoAnywhere MFT |
Healthcare — Europe-specific | Learn how GoAnywhere MFT gives healthcare organizations a safe, streamlined way to send files and sensitive ePHI and HER data to hospitals, clinics, pharmacies, and insurance companies. | Meeting European Compliance Requirements for Healthcare |
PCI DSS — General | PCI DSS applies to every organization around the world that processes credit or debit card information. GoAnywhere is designed to help you meet PCI DSS compliance requirements. | Meeting PCI DSS Requirements with GoAnywhere |
PCI DSS — Banking & Finance | Banks and financial agencies are starting to move to managed file transfers like GoAnywhere MFT to simplify, secure, and automate their sensitive data transfers. | PCI-Compliant File Transfers for Banking & Finance Organizations |
Top Compliance Case Studies & Use Cases
See how GoAnywhere MFT helps organizations in all industries meet compliance requirements.
Global Health Organization Streamlines PCI DSS Compliance for File Transfers
Industry: Healthcare
Summary: Moving from CoreFTP and WinSCP file transfers may seem challenging. See how this global healthcare IT company found time and cost savings with GoAnywhere Managed File Transfer and never looked back.
Think Mutual Bank Uses GoAnywhere MFT for PCI DSS Compliance
Industry: Banking & Finance
Summary: When Think Bank needed a way to transfer data between systems, they looked for a solution that was easy to implement, helped with PCI-compliant file transfers, and had robust functionality. Cue GoAnywhere MFT: a solution that does all this and more.
University of Tennessee Medical Center Uses MFT to Improve the Security of Sensitive Patient Data
Industry: Healthcare
Summary: Discover how the University of Tennessee Medical Center streamlined its file transfer processes, increased data security for sensitive PHI, and simplified vendor connections with GoAnywhere MFT.
MFT Helps Reduce Fortegra's File Transfer Risk
Industry: Insurance
Summary: Credit insurers, like Fortegra exchange many sensitive financial files weekly. By switching to GoAnywhere MFT from a legacy system, they quickly realized ease-of use, encryption, automation, reporting, and more.
Compliance Webinars On Demand
Meeting Compliance Requirements with GoAnywhere
Achieve compliant file sharing with a secure MFT solution. Discover how to meet secure file transfer requirements with GoAnywhere MFT. This webinar covers different data security compliance standards, the importance of compliance in an organization, and how MFT can help you comply with the proper regulations.
Meeting GDPR Compliance with GoAnywhere
Boost your knowledge of the EU’s General Data Protection Regulation (GDPR) and watch a live demo on how GoAnywhere can help you achieve compliance with secure file transfer.
Ensure File Transfer Compliance with GoAnywhere
With GoAnywhere, you can eliminate cumbersome custom programming and scripting normally required for data transfers. MFT can also improve the quality and security of the files you send in-house or to remote locations, trading partners, other businesses, or the cloud. Data security compliance is important in any organization, and GoAnywhere MFT can help you achieve compliant file sharing, file transfer, and more:
- Role-based administration and permissions: Keeps access privileges with the right users, controls password complexity requirements and sets expiration dates.
- Secure connections for transmitting sensitive data
- Strong encryption key management that you control
- Centralized control of file transfers
- Secure mail module for sending files using email with HTTPS download links
- Detailed auditing and reporting of all transfer activity, drastically simplifying the reporting burden during an audit
- Cloud solutions that conform to guidelines
With an auditable solution with secure file transfers, secure email, separation of permissions by user role, and at rest encryption, GoAnywhere MFT can help you achieve or advance your file transfer compliance. Learn more today.
Get a Personalized Walkthrough
Schedule a demo with one of our experts – ask about pricing, features, and the modules that are most important to you.
Is GoAnywhere Secure?
GoAnywhere MFT works within compliance frameworks, regulations, and standards to help you make the best decisions for your data security. GoAnywhere is ready to help you in your quest for compliance and assist you in processing your data in a secure manner. Whether you use GoAnywhere MFT on-premises or our MFTaaS SaaS solution, you get to make the choices on how to manage, monitor, and audit the controls surrounding your data.
Our Data Security Mission and Philosophy
Why do we care about security and compliance so much?
As a software solution dedicated to protecting your sensitive data in motion and at rest, GoAnywhere MFT takes all aspects of data security seriously. We actively improve MFT security and compliance in GoAnywhere and maintain a roadmap to keep us moving forward. Whether you choose GoAnywhere MFT or our MFaaS solution, you will always be in the driver seat on your data security.
Meet all your IT security and compliance requirements with GoAnywhere MFT. GoAnywhere helps organizations and IT professionals alike comply with regulations, standards, and technologies by providing enterprise-level MFT security features.
Get the infographic: Meeting IT Security and Compliance Requirements with GoAnywhere
For more information, download our datasheet: Our Approach to Security & Compliance
Enabling Data Security Compliance with MFT
Achieving compliance requires a holistic view and plan. With GoAnywhere MFT, you can secure your sensitive files and transmit data using the latest security standards to keep your data secure and comply with regulations, frameworks, and standards. GoAnywhere MFT addresses many controls in popular and widely-used security frameworks, standards, and regulations, including:
PCI DSS
- Centralized controls and management
- Role-based administration and permissions
- Strong Key Management System (KMS)
- Detailed audit logs and reporting
- PCI Security Settings Audit Report
The GDPR
- File transfer encryption technologies (e.g. Open PGP, SSH, and TLS)
- Integrity checks for successful file transfers
- Detailed audit logs and reporting
- Module for sending sensitive emails
- Admin User Roles for auditors and security or data protection officers
HIPAA & HITECH
- File transfer monitoring
- Detailed audit logs and reporting
- Granular user permissions
- Secure data exchange using SFTP, SCP, FTPS, and HTTPS
FISMA & NIST
- A FIPS 140-2 compliance mode for all file transfers
- Detailed audit logs and reporting
- Granular user permissions
- Stringent security controls
Australia's CDR
- Role-based administration and permissions to access data
- Detailed audit logs and reporting
- File encryption technologies
- MFT security settings for sending and receiving confidential emails
PIPEDA
- Stringent security controls and role-based user access
- Data encryption technologies
- Secure data exchange
California Consumer Privacy Act
- Detailed audit logs and reporting
- Centralized controls and management
- File transfer encryption technologies
Singapore's PDPA
- Limited data access based on user permissions
- Data encryption at rest and in motion
- Detailed audit logs and reporting
Do you have specific requirements or risks you want to address? We will collaborate with you to help you understand how GoAnywhere can assist in your compliance efforts.
- CIS
- FISMA & NIST (800-53r4, CSF, PS 800-37r2 RMF)
- ISO 27001 & 27002
- SOC 2
- SOX
- Australia's CDR
- PIPEDA
- CCPA
- Singapore's PDPA
Security Features in GoAnywhere MFT
- Generate full audit trails of all user events and file activity with reporting
- Generate reports of file transfer activity, user statistics, and completed jobs from within the console
- Feed audit log messages to a central SYSLOG server
- Use Domains to virtually segment a GoAnywhere installation into multiple security zones
- Filter connections with IP blacklists and whitelists (Global and User level)
- Block Brute-Force and Denial of Service (DoS) attacks with an automatic IP blacklist
- Authenticate SFTP connections with passwords and/or SSH keys
- Utilize only FIPS 140-2 certified encryption algorithms to meet U.S. Government (NIST) standards
- Authenticate FTPS and HTTPS connections with passwords and/or SSL certificates
- Automatically encrypt files on disk using AES 256 encryption
- Ability to accept or reject files with certain extensions
- Run services under non-standard port numbers
- Create and manage SSL certificates, SSH keys, and Open PGP keys through integrated screens
- Authenticate users against LDAP, Active Directory (AD), IBM i profiles, RADIUS, RSA SecurID, Google Authenticator, Duo Security, and other IAM (Identity and Access Management) solutions
- Define administrator user permissions for separation of duties
- SAML support for single sign-on and dual factor authentication
- Restrict users to specific home directories and subfolders
- Specify folder level permissions (upload, download, delete, rename, etc.) by user and group
- Restrict user logins to certain days-of-week or times-of-day
- Set password policies and expiration intervals
- Authorize selected services (e.g. FTP, SFTP, FTPS, HTTPS and AS2) to certain users and groups
- Disable user accounts after maximum login attempts
- Disable user accounts automatically after a period of inactivity
- Receive instant notifications on login failures
- Disable anonymous login
- View the active sessions for logged-in users with the ability to terminate (kick) sessions
While many organizations still use multiple solutions for their secure file transfer needs, GoAnywhere gives organizations the opportunity to centralize their encryption processes within a single, affordable solution for the enterprise. Reduce your exposure with GoAnywhere’s cutting-edge encryption technologies for data in transit and at rest:
- NIST-certified FIPS 140-2 crypto module
- Strong cipher suites
- Secure transmission protocols
- Detailed audit logs
- Role-based access control
- Multi-factor authentication
End-users can also securely upload files from their own infrastructure, which mitigates organizational remote access compliance issues.
System Hardening
System hardening is a process used to reduce IT vulnerabilities. It typically includes securing system configurations and strengthening internal operating procedures to reduce any available attack surface within an organization.
Fortra strives to apply security best practices in the design, development, and testing of GoAnywhere MFT. GoAnywhere MFT’s security resources, including our services team, are available to assist customers throughout the GoAnywhere MFT hardening process.
Interoperability
GoAnywhere MFT has the ability to interface with partners and external users via multiple protocols and advanced workflows. GoAnywhere is thoroughly tested for interoperability with enterprise-level operating systems, popular web browsers, and to meet commercial and federal compliance regulations. These features make GoAnywhere an excellent integrator at an affordable price. Organizations have used GoAnywhere to create multi-state interoperable systems with 24/7 functionality, meet Drummond requirements for AS2, and provide technical safeguards for file transfers between health organizations.
Learn how organizations use GoAnywhere MFT. There are many ways to connect your GoAnywhere instance with servers, tools, and popular cloud and web apps. Learn about GoAnywhere’s connectivity features, our Cloud Connectors, ways to integrate GoAnywhere MFT with applications you use every day, or our Secure ICAP Gateway, with introduces deep content inspection engine, adaptive data redaction, and flexible policy settings to GoAnywhere MFT’s secure file transfer capabilities.
Certifications & Partnerships
GoAnywhere has received the following certifications:
AS2 Drummond Certified
GoAnywhere MFT is Drummond Certified™ for AS2 which ensures compliance and compatibility with other AS2 solutions. GoAnywhere is also certified for SHA-2, Multiple Attachments, Filename Preservation, and Chunked Transfer Encoding with AS2.
Certified for Windows Server 2012
The GoAnywhere products successfully completed the Certified for Windows Server 2012 requirements using the robust Microsoft Platform Ready tools.
IBM Ready for Power Systems Software
GoAnywhere meets or exceeds IBM's criterion for integration with the Power Systems software stack for System Management, Energy, Security, Availability and Virtualization. Fortra is an IBM Business Partner and fully supports GoAnywhere on AIX, i, and Linux.
Microsoft Azure
The Azure Marketplace is an online store that offers applications and services either built or designed to integrate with Microsoft Azure. By obtaining a listing on the Marketplace, Microsoft has acknowledged that GoAnywhere MFT is certified and optimized to run on Azure.
VMware Ready
Secure Managed File Transfer is ready for virtual private cloud infrastructure when running GoAnywhere Managed File Transfer on vSphere from VMware.
Partnerships
Active involvement in the industries it serves keeps GoAnywhere MFT on the leading edge of secure file transfer services. Current professional partnerships include:
What GoAnywhere Users Say
We migrated all our existing file transfers to GoAnywhere. [They are] very responsive on any questions or issues (which are very few) that we have. I would recommend GoAnywhere MFT to anyone looking for a solid file transfer solution.
James W., UNIX Administrator
[GoAnywhere is a] great managed file transfer application. An enterprise-level quality solution for file transfers, cross-network sharing including external sharing. This product does it all. All manageable and visible via a good admin portal. Great customizability and control. What more can an admin ask for?
Corporate IT Manager Gartner Peer Insights, July 2018
Move Files Securely with GoAnywhere Managed File Transfer
Obtain a personalized quote based on the features you need.
How to Help Ensure Compliance with Data Privacy Laws
If complying with data privacy laws like the GDPR, PDPA, CPA, HIPAA, PCI DSS, PIPEDA, and more sometimes feels like swimming in alphabet soup, there is a life preserver that can simplify, secure, and automate the processes involved. Managed file transfer can proactively help organizations meet strict industry requirements to ensure the data your customers and employees entrust you with stays secure both in transit and at rest.
No organization wants to be hit with the large fines or sanctions for non-compliance of data security laws. Nor do the negative PR and reputation ramifications sound appetizing. Deploying a robust file transfer system can help ensure compliance, with the least risk of human error.
Everyone has rights when it comes to the personal data they choose to share. The various data privacy laws enacted globally help govern and provide oversight into how organizations “borrow” this data with permission, and how they protect it while in their possession.
What Are Some Key Data Privacy Laws?
The European Union’s General Data Protection Regulation (GDPR)
This regulation governs the personal data that organizations have gathered with, and from, anyone else. It also rules how data is transferred between other EU member states and between other EU and non-EU locales. It determines what happens if such data is breached and provides the rights for EU citizens to:
- Request details about how their personal data is processed
- Have their personal data erased
- Withdraw previously given consent
- Request/receive their personal data in a common format
- Send their requested data to another organization
Even though the GDPR deals with the personal data of citizens in the EU, its requirements affect any company that controls or processes their data, including those in the United States, the United Kingdom, Asia, and beyond. Companies found noncompliant face strict fines and penalties.
Related Reading: GDPR and Data Privacy After Brexit: What's Next?
Australia’s Consumer Data Right (CDR)
This measure provides consumers with the ability to efficiently and conveniently access their personal data held by businesses, and to authorize the secure sharing of that data to trusted and accredited third parties. It gives individuals the right to access their personal information, and the right of data portability found in the European General Data Protection Right (GDPR).
Businesses under the CDR protocols should consider:
- Reviewing their policies and processes for privacy and data handling
- Training staff on their CDR obligations and how to manage the risks involved with handling consumer data
- Establishing breach notification procedures
- Ensuring the technology to ensure security measures is in place
Related Reading: Australia’s CDR: What it is and Why Does it Matter
The United States’ Health Insurance Portability and Accountability Act (HIPAA) and HITECH Act
The HIPAA act protects sensitive patient data and applies to any company that deals with protected health information (PHI). HIPAA naturally has a close relationship to the HITECH Act, which was designed to encourage the adoption of electronic health and medical records, although HIPAA’s primary concern is with the portability of health insurance and protecting the rights of workers between jobs to ensure health insurance coverage is maintained. The HITECH Act adds heft to HIPAA’s rules, outlining the technological aspects of protecting data of patients.
Any organization that exchanges PHI or ePHI must be HIPAA compliant. As healthcare organizations adopt health information technology like electronic health records (EHRs), PHI is subject to risk when transferred between hospitals, clinics, pharmacies and insurers using traditional, unsecure file transfer methods like FTP. It’s critical for organizations to secure this data at rest and in motion and ensure the security standards of HIPAA.
Related Reading: How GoAnywhere MFT Helps the Healthcare Industry Thrive
Singapore’s Personal Data Protection Act (PDPA)
This act governs the collection, use, disclosure, and care of personal data. Organizations are obligated to protect personal data in their possession or under their control by making reasonable security measures to prevent unauthorized access, collection, use, disclosure, copying, modification of data, or similar risks.
Specific measures include regular audits, implementation of an authentication method for accessing personal data, definition of user roles or groups and their access rights, setting appropriate password requirements and using anti-malware software.
Noncompliance can result in the oversight commission (PDPC) ordering an organization to stop any business activities which use personal data and issuing fines of $10,000 per offense.
Related Reading: PDPA in Singapore Helps Protect Personal Data
Global - Payment Card Industry Data Security Standard (PCI DSS)
This compliance regulation is mandated by credit card companies to help ensure the security of credit card transactions in the payments industry.
The set of industry requirements is intended to ensure that all companies that process, store, or transmit credit card information maintain a secure environment. Key requirements include firewalls, password protection, and encryption for data at rest and in transit.
Related Reading: PCI DSS Compliance for File Transfers
Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA)
This privacy law applies to private-sector organizations and businesses throughout Canada. The goal of PIPEDA is to ensure that all provinces and territories protect personal data. This includes:
- Asking for and obtaining consent when an individual’s information is initially gathered, used, or shared
- Allowing individuals to view or correct their personal information
- Appropriately storing and disposing of personal data
The core idea of PIPEDA is that businesses should act in good faith when collecting and using personal information. It applies to most businesses in Canada that handle personal information, exempting only provinces and territories where similar laws were put into place prior to PIPEDA. Commercial organizations that collect personal data – including names, addresses, demographics, financial information, and medical information, among others – must comply with PIPEDA unless specifically exempt.
Related Reading: What is PIPEDA?
California Consumer Privacy Act (CCPA)
The CCPA is intended to protect individuals’ private data by making data collection and usage more transparent between consumers and companies, giving Californians ownership over personal data that is collected by businesses. The CCPA adds new rights to Californians’ data privacy protections, specifically:
- The right to know what data a business collects and why, as well as any personal data they use, share, or sell
- The right to delete information a business has, if asked (within reason)
- The right to opt out or withdraw consent from having data sold
If your organization collects California residents’ information, it’s possible that you must adhere to the CCPA, even if your business is not physically located in California.
Related Reading: What is the California Consumer Privacy Act?
How Managed File Transfer Helps to Ensure Data Privacy Compliance
Organizations need technical, administrative, and managerial controls in place, as well as organizational polices, to fully enforce and ensure compliance from the top down. Your business can comply by:
- Developing a procedure to quickly locate and delete personal data about a person
- Simplifying your method of safely disposing of customer information when requested to do so
- Ensuring you can appropriately audit your records to find all personal data, including any external companies you’ve shared information with
One simple way to meet several data privacy requirements is to secure file transfers, both at rest and in transit, using a managed file transfer (MFT) solution. With MFT, you can eliminate the cumbersome custom programming and scripting normally required for data transfers. MFT can also improve the quality and security of files you send in-house or to remote locations, trading partners, other businesses, or the cloud.
GoAnywhere Managed File Transfer, helps organizations meet data privacy requirements, like those noted above, by providing an auditable solution with secure file transfers, secure email, separation of permissions by user roles, and at rest encryption.
The benefits of using GoAnywhere for compliance needs include (but aren’t limited to):
- Role-based administration and permissions: Keeps access privileges with the right users, controls password complexity requirements and sets expiration dates.
- Secure connections for transmitting sensitive data
- Strong encryption key management that you control
- Centralized control of file transfers
- Secure mail module for sending files using email with HTTPS download links
- Detailed auditing and reporting of all transfer activity, drastically simplifying the reporting burden during an audit
- Cloud solutions that conform to guidelines
Every data privacy law has unique requirements and repercussions. To find the best solution for your organization and help avoid fines and sanctions, schedule a live, customized demonstration of GoAnywhere today.