Security, Scalability and Resiliency with the Acquia Platform
by Chris Stone
Acquia has long been on the forefront of cloud security as it supports some of the world’s most important organizations on the Acquia Platform -- the largest provider of Drupal infrastructure in the world.
This week marked the announcement that Acquia is now ready to support customers with Drupal 8 -- from its Platform for building, delivering, and optimizing websites and digital experience -- to its customer success teams. We bring an enhanced level of D8 security to the Drupal 8 platform, but also have the talent, expertise, and processes in place to provide every confidence that our customers’ have the high level of availability and security their digital presence demands.
Our security experts have always provided “inside out” analysis of your Drupal code by staying on top of the latest security vulnerabilities and understanding these ahead of our competitors. Automated code analysis tools can only test against a limited set of static and dynamic patterns and are difficult to maintain and update against the latest issues. This week we are also announcing a new Security as a Service (SECaaS) offering which provides a web application vulnerability scanning service. This will provide an “outside in” report on your site security for the top 10 vulnerabilities identified by the Open Web Application Security Project.
Since the insight provided by these services is only as good as the actions you can take, Acquia has not only assembled the largest team of security experts in the Drupal ecosystem, but our Professional Services team provides an optional remediation workshop which will put a plan together to address any vulnerabilities identified in the report.
Acquia also offers a suite of security products and services ranging from Acquia Cloud Edge Protect powered by Cloudflare to Acquia Cloud Shield. For increased protection, Acquia Cloud Edge Protect provides a web application firewall (WAF) to proactively mitigate DDoS attacks and Acquia Cloud Shield provides a dedicated, logically isolated section of the Acquia Cloud with a customizable network configuration. Shield combines the security benefits of a private network with the ease of operation of a managed platform-as-a-service.
To help ensure that our security controls are designed and operating effectively, Acquia undergoes several annual third party attestations performed by an independent certified public accounting firm and qualified security assessor (QSA) including SOC 1/ISAE 3402 Type 2, SOC 2 Type 2 , PCI-DSS, and HIPAA AT101.
As our security team expands and Acquia achieves crucial security certifications, Acquia’s customers can continue to expect their work will be safe and secure with Acquia watching their backs.