NETSUITE DATA CENTER FACT SHEET - JCurve Solutions

Transcription

NETSUITE DATACENTER FACT SHEETEnterprise-Class Data Management,Security, Performance and AvailabilityNetSuite is the world’s largest cloud ERPvendor, supporting over 40,000 organizations,processing over 500 million applicationrequests per day with 9 terabytes of dataadded every day. NetSuite also has a trackrecord since 1998 of maintaining the securityof our customers’ records.NetSuite Data Center ArchitectureNetSuite operates six geographicallyseparated data centers present in twoRegions, US and Europe. The data centersoperate in a hub-spoke architecture. Eachregion has a dedicated data center thatprovides data mirroring, disaster recoveryand failover capabilities for the other datacenters in that region in case any datacenter becomes non-operational. Customerdata is not shared between the regions.All data center facilities are operated by aChicagoleading collocation provider, which providesearthquake and fire protection, along withheating, cooling and backup power. TheNetSuite application is multi-tenant, and allservers, storage and hard drives are built onseveral layers of redundancy.www.netsuite.com

Facts about NetSuite’s DataCenter InfrastructureData Management Redundancy: Many layers in the NetSuitesystem implement multiple levels of redundancy.This design allows one or more elements tofail without any interruption in service byhaving multiple, redundant systems online toautomatically assume processing on behalfof the failed component. Disaster Recovery: Within one region, data isreplicated and synchronized between theactive data centers and the dedicated DRdata center by way of a proprietary replicationmechanism built in house. In the event thatthe primary data center fails, all operationsfail over to the DR data center. This failoverprocedure is tested and proven on the livesite twice annually. The failover procedure isautomated and can be triggered in pushbutton fashion. NetSuite has operationsengineers geographically distributed fromeach other, as well as the data centers inorder to be able to execute a failover in anydisaster scenario. NetSuite conducts semiannual DR exercises to ensure that systemsand processes are in place, as well as toassess and enhance competency of allrelevant personnel key to the successfulimplementation of DR activities. NetSuitedata centers utilizes tape backups whichsupports customer-initiated data restores. Scalability: NetSuite supports over 40,000organizations with over 500 million applicationrequests per day with 9 terabytes of dataadded every day. NetSuite has designed itssystems to accommodate surges and spikesCopyright 2018, Oracle and/or its affiliates. All rights reserved.in usage, and to scale upward smoothly toaddress increased volume and transactions.Application Security Encryption: Transmission of users’ unique IDand passwords, as well as all data in theresultant connection, are encrypted withindustry standard protocol and cipher suite.NetSuite supports Custom Attribute encryptionand provide encryption APIs. The applicationauthentication is token based while end userauthentication supports modern two factorauthentication with mobile devices orauthentication FOBs. Application-Only Access: The system isdivided into layers that separate data fromthe NetSuite application itself. Users of theapplication can only access the applicationfeatures, and not the underlying database orother infrastructure components. Role-Level Access and Idle Disconnect:Customers can assign each end user aspecific role with specific permissions to onlysee and use those features related to his orher own job. There is a complete audit trailwhereby changes to each transaction aretracked by the user login details and atimestamp for each change is provided. Thesystem also detects idle connections andautomatically locks the browser screen toprevent unauthorized access from anunattended computer screen. IP Address Restrictions: Restrictions onaccessing a NetSuite account from specificcomputers and/or locations can be enforced.This is very useful for customers who areconcerned not only about who is able to accessPage 2

their NetSuite account, but from where theyaccess it as well. This feature significantlyreduces the risk of unauthorized third partiesaccessing a user’s account. Robust Password Policies: NetSuite offersfine-grained password configurationoptions—from the length of the user’spasswords, to the expiration of a user’spassword at any timeframe they desire.Customers can set up strict password policiesto ensure that new passwords vary from priorpasswords, and that passwords are complexenough to include a combination of numbers,letters and special characters. Accounts arealso locked out after several unsuccessfulattempts. For customers who desire a higherlevel of access control, NetSuite offersmulti-factor authentication using a simplephysical token. In addition to entering theirown passwords, users must possess physicaltokens that generate random one-timepasswords. These cryptographically robustpasswords prevent key loggers, shouldersurfers, phishers and password crackers fromaccessing a user’s account.Operational Security Continuous Monitoring: NetSuite employsnumerous Intrusion Detection Systems (IDS)to identify malicious traffic attempting toaccess its networks. Unauthorized attemptsto access the data center are blocked, andany unauthorized connection attempts arelogged and investigated. Enterprise-gradeanti-virus software is also in place to guardagainst Trojans, worms, viruses and othermalware from affecting the corporatesoftware and applications.Copyright 2018, Oracle and/or its affiliates. All rights reserved. Separation of Duties: In addition to mandatoryemployee background checks at all levels ofNetSuite operations, job responsibilities areseparated. The Principle of Least Authority(POLA) is followed and employees are givenonly those privileges that are necessary to dotheir duties. Physical Access: All data centers’ operatorsmaintain stringent physical security policiesand controls to allow unescorted access topre-authorized NetSuite Operations personnel:ºThe first layer of security includes photo IDproximity access cards and a biometricidentification system. This multi-factorauthentication system provides additionalassurance against lost badge risks or otherattempts at impersonation. Proximity cardreader devices are located at major pointsof entry and are used to secure critical areaswithin the data centers.ºSingle-person portals and T-DAR man trapsguarantee that only one person is authenticatedat one time to prevent tailgating. Reliabledetection and prevention of tailgating andpiggybacking through secure doorssignificantly increases the effectiveness ofthe access control system.ºIn addition, all perimeter doors are alarmedand monitored and all exterior perimeterwalls, doors, windows and the main interiorentry are constructed of materials that affordUnderwriters Laboratory (UL) rated ballisticprotection. Vegetation and other objectsaround the data center are landscaped in amanner such that an intruder would notbe concealed.Page 3

Guarded Premises: On-premise securityguards monitor all alarms, personnel activities,access points and shipping and receiving,and ensure that entry and exit proceduresare correctly followed on a 24x7 basis. Guardsare provided with ongoing awareness trainingand skills-building. Numerous CCTV videosurveillance cameras with pan-tilt-zoomcapabilities are located at points of entry tothe collocation and other secured areaswithin the perimeter. Video is monitored andis stored for review for non-repudiation. Security Certifications: NetSuite haspassed a SOC 1 Type II audit, is certifiedfor PCI-DSS and is EU-US Privacy Shieldcompliant. NetSuite has defined itsInformation Security Management System inaccordance with NIST standards, including800-53 and ISO27000 series standards.ºNetSuite’s SOC 1 Type II audit is preparedby and audited by independent third-partyauditors. SOC 1 Type II reports show thatwe have been through an in-depth auditof our control environment, includingcontrols over data and network security,backup and restoration procedures, systemavailability and application development.The requirements of Section 404 of theSarbanes-Oxley Act make a SOC 1 Type IIaudit report essential to the process ofreporting on the effectiveness of internalcontrol over a company’s financial reporting.ºIn complying with PCI-DSS requirements,NetSuite offers optional 3D Securecredit card authentication—also knownas Verified by Visa and MasterCardSecureCode. 3D Secure adds a higherlevel of credit card fraud protection. Itrequests shoppers to create authenticationpasswords for their credit cards, or requiresthem to enter their password if they alreadyhave one assigned.ºNetSuite has achieved the InternationalOrganization for Standardization (ISO) Dedicated Security Team: NetSuite employsa global security team dedicated to enforcingsecurity policies, monitoring alerts andinvestigating any anomalous behavior withinthe system. This team is active 24x7 frommultiple worldwide locations. All access toproduction is reviewed and granted by thesecurity team. Data Center Performance Audits: NetSuiteOperations management implements suchauditing controls as appropriate for SOC1 Type II and PCI compliance. NetSuite’scomprehensive risk management processhas been modeled after the NationalInstitute of Standards and Technology’s(NIST) special publication 800-30 and theISO 27000 series of standards. Periodicaudits are carried out to help ensurethat personnel performance, proceduralcompliance, equipment serviceability,updated authorization records and keyinventory rounds are above par.Copyright 2018, Oracle and/or its affiliates. All rights reserved.Page 4

27001* certification, the leading internationalstandard for measuring Information SecurityManagement Systems (ISMS). The standardrequires a systematic examination of securityrisks, threats, vulnerabilities and their impact.To achieve certification, an organization mustdesign and implement a comprehensive suiteof information security controls and adopt anoverarching management process to ensurethat information security controls continue tomeet the organization’s needs on an ongoingbasis. NetSuite’s compliance with this importantindustry certification demonstrates the company’scontinued commitment to maintaining andimproving its information security managementand data custodianship programs.Performance Scalable Application Architecture: NetSuite’sapplication runs on a three tiered architecture.All three tiers—web, application, and database—are horizontally scalable and support multi-datacenter deployment. NetSuite currently operateson over 4000 hosts in production. Performance Team: NetSuite invests heavilyin performance at every layer. This includes adedicated performance team of developersand DBAs whose sole purpose is to proactivelyverify application performance benchmarks andtune the application for maximum performance. High Performance Databases: NetSuite runson high performance database server hardwarewith multiple cores and maximum RAMconfiguration. NetSuite production databaseservers run exclusively on flash SSD storageensuring the fastest possible database IOperformance available in the industry. Performance Monitoring Tool: NetSuite’sApplication Performance Monitoring toolprovides a comprehensive performancedashboard that allows you to easily and quicklydrill down and investigate the root cause ofyour site’s performance issues. By capturingcritical performance data and quickly identifying,analyzing and fixing the problem areas, youcan optimize performance, improve customerexperience and maintain critical transactions.Availability Service Level Commitment: NetSuite’s SLCguarantees a 99.5% uptime (outside thescheduled service windows) for the NetSuiteproduction applications for all our customers.A credit is available if NetSuite does notdeliver its application services with 99.5%uptime. We have consistently averaged anactual uptime of 99.98% and provide customersa publicly available webpage to display systemstatus at all times at http://status.netsuite.com. World Class Hosting Operations Team:NetSuite has a global team of dedicatedhosting operations personnel with decadesof cumulative experience running large cloudand SaaS business applications demandinghigh performance and high availability. Thisteam proactively monitors the health of theentire system with industry leading alert andtrend based tools designed to identify and* Oracle NetSuite, a wholly-owned subsidiary of Oracle, received an International Standards Organization (ISO) 27001 certification for its InformationSystem Management System (ISMS) supporting the security operations of its products and services that includes NetSuite SaaS, OpenAir PSA SaaS andNetSuite Advance Rating (Monexa).Copyright 2018, Oracle and/or its affiliates. All rights reserved.Page 5

resolve events before they impact the livesite. This team provides 24x7 coverage torespond to any incident with automatedrecovery procedures. Redundant Internet Connections: The networkwas built to meet or exceed commercialtelecommunications standards worldwide foravailability, integrity and confidentiality. AllNetSuite data centers have three 10 Gbpsdiverse-path pipes, designed so that any twoconnections can simultaneously fail withoutimpacting user experience. This redundancyensures reliable connectivity and maximumuptime with no single-point data transmissionbottlenecks to or from the data center.Additionally, each data center has 2 dedicated10 Gbps circuits for data replication. Backup Power Systems: NetSuite has designeda solution for clean, continuous power.Uninterruptible Power Systems (UPSs) areprovisioned in a redundant configurationsupport environmental controls in thecollocation spaces. Each UPS battery systemis designed to carry full load for 15 minuteswithout a generator. Emergency generatorstypically provide backup power in less than10 seconds and are sized to support theentire facility at maximum load. In addition toUPS systems, NetSuite makes use of powermanagement modules and power distributionCopyright 2018, Oracle and/or its affiliates. All rights reserved.units on data center floors for a physicallyintegrated and electrically redundant systemfor source selection, isolation, distribution,monitoring and control of power to computerequipment loads. HVAC Systems: Air conditioning in all datacenters is configured to allow for proper heatdissipation, permitting the sites to operatewithin an acceptable temperature range. Tomaintain the flow of air conditioning, an N 1redundant system of HVAC units is employedwithin each location. The HVAC units arepowered by normal and emergency electricalsystems to maintain their availability. Additionally,cold water tanks have been installed to keepair conditioning units functioning when transitionfrom direct power to generator power duringemergencies is required. Fire Suppression: The latest fire suppressionmethods have been employed at NetSuite’sdata centers. The systems utilize state-ofthe-art “sniffer” systems, augmented by heatdetection and dry-pipe sprinkler systems. Seismic Engineering: NetSuite-operated datacenters provide seismic isolation equipmentto cushion facilities against movement, inaddition to installing earthquake bracing onall equipment racks. Racks are anchored tothe concrete slab below the site’s raised floor.

added every day. NetSuite also has a track record since 1998 of maintaining the security of our customers’ records. NetSuite Data Center Architecture NetSuite operates six geographically separated data centers present in two Regions, US and Europe. The data centers operate in a hub-spoke a