Welcome!

Cloud Expo Authors: Stephen Pierzchala, Keith Mayer, Sebastian Kruk, Pat Romanski, Liz McMillan

Blog Feed Post

360 Degree Electronic Signature Security – Part 1

Nathan Eddy wrote an interesting post for eWeek about CDW’s 2013 State of the Cloud Report. According to a survey of 1,242 IT professionals, cloud computing within organizations continues to rise as do the savings from the adoption these applications.

Respondents continue to cite security as a factor that needs to be addressed in cloud adoption. Security is always top of mind when moving signing processes online, particularly the security of the signature and the authentication of its user. While these are essential – and likely the first thing that comes to mind when contemplating electronic signature security – they only touch the surface of a successful, e-signing security strategy.

Our recommendations for implementing a secure and usable electronic signing solution fall into four categories, with the first two being:

DOCUMENT AND SIGNATURE SECURITY

Document and signature security are at the heart of any electronically signed business transaction. To be certain of this, all audit trail information must be securely embedded in the document; the document and signature must be tamper-evident; and the document must be accessible to all parties.

Keeping signatures and audit trails together in a single document is more secure, easier to manage and more portable. Electronic signatures should travel seamlessly with documents at all times through email, storage and archival systems.

The document and electronic signatures should be protected using digital signature technology. This securely ties together signing intent with user authentication and document information. The digital signature creates a digital fingerprint of the document (called a hash) that can be used at a later point to verify the integrity of the electronic record. If the document is tampered with in the slightest the digital signature, and hence the electronic signature, will be visibly invalidated. This is a unique and significant advantage over the paper world, where it is not always possible to detect whether changes have been made to a document.

Finally, the electronic document and associated signatures, audit trails and evidence must be accessible for the lifetime of the record (50+ years in some cases). This requires a document format that is e-signature friendly. Adobe PDF, an ISO standard, is a reliable choice for the long term.

TRANSACTION SECURITY

Convincing legal evidence requires demonstrating that the process used to capture signatures complied with all applicable laws and regulations, and helped build the signer’s understanding of what they were agreeing to and signing. This is called process evidence and is accomplished by recording all the web pages, documents, legal disclosures and actions taken by users, and linking it to the final e-signed documents in a manner that enables the process to be accurately reproduced from start to finish.

A trail of electronic evidence is the key to ensuring this.  Secure audit trails must be permanently bound to the electronic record via a cryptographic link. This includes having a log of system accesses and all actions that are happening during the actual transaction.

For more information about security when adopting an electronic signature solution for your business, download a white paper on electronic signature security.

Stay tuned for next week’s post covering Part 2 of our recommendations on how to implement a secure and usable electronic signing solution.

The post 360 Degree Electronic Signature Security – Part 1 appeared first on Blog.

Read the original blog entry...

More Stories By Mary Ellen Power

Mary Ellen Power is Vice President of Marketing at Silanis Technology, a leading provider of electronic signature solutions. Ms. Power has led Silanis' customer relations and industry marketing efforts since 2000 where she has had the opportunity to engage with some of the world's largest insurance carriers, financial service providers, government organizations and analyst firms. Over the years, Ms. Power has acquired in-depth knowledge of the electronic signature market and its impact in real-world customer deployments.

Cloud Expo Breaking News
SYS-CON Events announced today that nfina Technologies, a provider of highly reliable cloud server products, will exhibit at SYS-CON's 12th International Cloud Expo, which will take place on June 10–13, 2013, at the Javits Center in New York City, New York. nfina Technologies develops, manufactures, and markets highly reliable cloud server products, designed to solve the most demanding data center requirements in mission-critical cloud applications. Nfina’s staff has decades of experience in co...
SYS-CON Events announced today that OpenStack will exhibit at SYS-CON's 12th International Cloud Expo, which will take place on June 10–13, 2013, at the Javits Center in New York City, New York. OpenStack software controls large pools of compute, storage, and networking resources throughout a datacenter, all managed by a dashboard that gives administrators control while empowering their users to provision resources through a web interface. OpenStack powers some of the most widely-used SaaS app...
“Cloud has everything to do with what has happened with Big Data,” explained Jason Deck, Director of Strategic Alliances at Logicworks, in this exclusive Q&A with Cloud Expo Conference Chair Jeremy Geelan. “Big Data doesn’t exist in its easily accessible way without cloud. From reduced startup costs, to cheap storage, to fast processing, to adequate security, to the easy incorporation of third-party analytics tools, cloud made Big Data accessible to customers of all sizes, with all different bud...
“Social, mobile, analytics and cloud can’t be looked at as distinct technology trends; they are facets of the same movement and an everyday reality for consumers and businesses alike,” said Craig Sowell, IBM VP of SmartCloud Marketing, in this exclusive Q&A with Cloud Expo Conference Chair Jeremy Geelan. “This means that businesses need to start looking at trends as one: cloud is the delivery, analytics is the unique insight, social is a shareable service, and mobile is the ubiquitous access.” ...
With Cloud Expo New York | 12th Cloud Expo [June 10-13, 2013] hurtling towards us, let's take a look at the distinguished individuals in our incredible Speaker Faculty for the technical and strategy sessions at the conference coming up June 10-13 at the Jacob Javits Center in New York City. We have technical and strategy sessions for you all four days dealing with every nook and cranny of Cloud Computing and Big Data, but what of those who are presenting? Who are they, where do they work, wha...
The new open source cloud orchestration platform called OpenStack is the promise of flexible network virtualization, and network overlays are looking closer than ever. The vision of this platform is to enable the on-demand creation of many distinct networks on top of one underlying physical infrastructure in the cloud environment. The platform will support automated provisioning and management of large groups of virtual machines or compute resources, including extensive monitoring in the cloud.
In his session at the 12th International Cloud Expo, Dave Eichorn, Global Data Center Practice Head at Zensar, will share a case study describing how a utility services company handled the migration of its Microsoft platform to the cloud. Challenged with the time-consuming task of opening operations out of temporary offices, this company struggled with the need to simultaneously access data that was accumulated from a vast amount of data-intensive jobs. Zensar migrated the company’s application ...
The rise of cloud computing has exposed hard drive-based storage as the new data center bottleneck. Combating this, data center managers have deployed SSDs to gain the performance needed to provide real-time access to data. However, due to budget constraints, many have turned to consumer-grade SSDs without understanding that they wear out quickly when processing enterprise workloads. In this session, Esther Spanjer will discuss recent endurance advancements in SSD technology that enable usage of...
SYS-CON Events announced today that Wowrack will exhibit at SYS-CON's 12th International Cloud Expo, which will take place on June 10–13, 2013, at the Javits Center in New York City, New York. Wowrack’s core expertise lies in high-availability Private and Public Cloud IaaS Hosting Solutions. Wowrack provides a true Hybrid service – where business release all IT management and hardware provisioning – taking the data center and server system administrative headaches off our customer’s shoulders. ...
At pennies per virtual machine-hour, the economics of cloud computing are both compelling and daunting to replicate. Whether you are building your own cloud infrastructure, building a public cloud or choosing a cloud service, there are key strategy and technology decisions that make the difference between success and failure. In his General Session at the 12th International Cloud Expo, Jason Waxman, VP in the Intel Architecture Group and general manager of the Cloud Platforms Group within Inte...