Confidential: University of California San Francisco Medical Center Situation and background Risks Opportunities Evaluation of candidates Security compliance Core requirements Cost analysis Project recommendation Asks/Questions/Decisions Next steps User acceptance testing Architecture approval Deployment Slide 0 Agenda – Secure Project May 1, 2014 UCSF Information Technology
Confidential: University of California San Francisco Medical Center Allows with confidential information to be delivered securely outside of UCSF Primary users include: Health Care Providers Legal Department Finance Department Human Resources UCSF’s secure system will be end of life and out of compliance on November 14, 2014 All existing functionality will be replicated in the new system There is no migration path for the current system; this provides an opportunity to evaluate leaders in the market Slide 1 Secure Project
Confidential: University of California San Francisco Medical Center Slide 2 UCSF Flow Vontu Data Loss Prevention Tumbleweed Secure Antivirus and SPAM Hygiene server External Recipient Secure Access SSL UCSF Firewall UCSF Departments/Users To: Subject : Secure: PHI stuff
Confidential: University of California San Francisco Medical Center Slide 3 Gartner - Secure Gateway
Confidential: University of California San Francisco Medical Center Slide 4 Five Year TCO FIVE YEAR TCO ANALYSIS CISCO IRONPORT CLOUD CISCO IRONPORT APPLIANCE AXWAY MAILGATE APPLIANCE AXWAY MAILGATE CLOUD Capital Expenses Appliance (Two for redundancy) $ 6, $ 22, Implementation services $ 6, $ 3, Fifth year appliance refresh (Two for redundancy) $ 6, $ 25, Perpetual Software License $ 14, Cloud Set Up Fee $ 7, Operating Expenses Hosting Fee (5 years) $ 57, Annual Software License (5 years) $ 55, $ 77, $ 91, $ 81, TOTAL $ 82, $ 117, $ 164, $ 186,064.00
Confidential: University of California San Francisco Medical Center Cisco IronPort Lowest TCO for either cloud or on premise solution Leads Gartner’s Magic Quadrant for secure gateways Reduces risk of exposure from compromised accounts Meets all core requirements UCSF sender experience remains the same Slide 5 Secure Recommendation
Confidential: University of California San Francisco Medical Center 1.Please provide names of a few people who can assist with user acceptance testing. 2.Is the current Tier 3 classification correct? System recovery is 5 days, Recovery point is 24 hours Secure can be queued for delivery once the system is recovered Alternative communications would be utilized during an outage 3.Should external accounts be maintained longer than 1 year? Secure messages are purged after 60 days Maintaining external login accounts may increase security risk Short expiration could lead to higher volume of calls to the service desk and general dissatisfaction Slide 6 Asks/Questions/Decisions
Confidential: University of California San Francisco Medical Center User Acceptance Testing Account creation and navigation of interface Test sending, receiving, forwarding and recalling Architecture Validate design and implementation plans Procurement & Deployment Engage professional services Produce documentation and appropriate messaging for the user community Slide 7 Next Steps...
Confidential: University of California San Francisco Medical Center Slide 8 Secure Timeline