Orange County NC Website
DocuSign Envelope ID:AA335D7A-5559-49E4-8BFB-49DFC3C62F17 <br /> YouPlea uses serverless technologies exclusively. While malware relies on persistence, <br /> our resources are provisioned and deprovisioned on demand and exist for only minutes at <br /> a time. <br /> 32. What system hardening strategies are employed by the cloud provider? <br /> YouPlea uses serverless technologies exclusively. There are no systems to harden. <br /> 33. How does the cloud provider perform security testing, including logging, correlation, <br /> intrusion detection, intrusion prevention, file integrity monitoring, time synchronization, <br /> security assessments, penetration testing? <br /> YouPlea ensures security through static code analysis and automated unit, functional, and <br /> integration testing. Further the system uses a serverless architecture making all resources <br /> ephemeral. Logging and correlation are performed through AWS CloudWatch and an <br /> Elastic (ELK) stack. <br /> 34. What technologies and methods does the cloud vendor provide for strong authentication? <br /> YouPlea uses AWS Cognito for authentication and authorization. JWTs are generated at <br /> login and used to validate all requests thereafter. All data is stored in a combination of <br /> AWS DynamoDB and AWS S3. DynamoDB and S3 are configured to prevent public <br /> access. <br /> 35. Provide any other comments and explanations: <br /> Click here to enter text. <br />