HyperX now has the ability to send your data to a cloud dashboard to gain further insights into your data. The HyperX Dashboard can be installed internally on your own servers, or it can be used on the Collier Aerospace hosted cloud solution located at https://dashboard.collieraerospace.com.
In either case, there are several security layers involved in the HyperX Dashboard. This document will provide an overview of the following security layers used in the HyperX Dashboard to ensure that your data is protected.
The first security measure starts at install. If you are in an environment that will never use the HyperX Dashboard then you can install HyperX without Dashboard support. This will make HyperX incapable of sending your data anywhere.
When HyperX is installed with Dashboard support, you will have ability to send data to the Dashboard. Data is never automatically sent anywhere. Data will only be sent to the Dashboard when you explicitly request that it be sent. This gives you complete control over when and what data gets sent to the HyperX Dashboard.
Tip
You can install and manage the Dashboard locally so that your data never leaves your premises.
All traffic to and from the Dashboard must be done using HTTP over TLS, or HTTPS. The Collier Aerospace hosted HyperX Dashboard is already configured for secure communication. If self-hosting the HyperX Dashboard it is your responsibility for properly configuring HTTPS for the HyperX Dashboard. If needed, Collier Aerospace can provide guidance for setting this up.
When you attempt to send data from HyperX to the HyperX Dashboard, you will first need to login. So, the first step is creating an account on the HyperX Dashboard. HyperX Dashboard users are managed using Keycloak. Keycloak can be configured to be standalone to manage its own users, or it can be configured to interface with an existing LDAP or Active Directory server.
Visit the URL of your configured Dashboard to sign up or visit https://dashboard.collieraerospace.com/ if using the Collier Aerospace hosted dashboard.
Once you sign up you will not immediately have access to the Dashboard. You must be authorized by a site administrator to ensure that you have a need to be using the HyperX Dashboard. This is to prevent any user with a network connection from having access to the HyperX Dashboard. Once you have been authorized for use, you will be able to login to the HyperX Dashboard. You can then turn on two-factor authentication by visiting your account settings. You can setup an authenticator using either FreeOTP or Google Authenticator.
MFA is an excellent way to ensure that your account remains secure should your password be compromised. MFA is not required for Dashboard use but can be enabled if desired. The Dashboard uses a program called Keycloak to manage user accounts.
To enable MFA:
-
Click on your name in the top right corner of the Dashboard and then click the “Account Settings” button.
-
You will be brought to this page that allows you change settings related to your User Account. Under "Account Security" click "Signing In"
In the "Two-factor Authentication" section click "Set up authenticator application"
-
Follow the instructions on the Authenticator page to set up MFA. The Dashboard supports MFA using one of two mobile apps: FreeOTP and Google Authenticator. Once you have enabled MFA, you will need to enter a code from your authenticator app when you log into the Dashboard, both through the website and through HyperX.
You need to be a Member of at least one Company and one Program in order to upload and view data in the HyperX Dashboard. Companies and Programs are how the HyperX Dashboard ensures that only people authorized to access a company’s data will have access to that data, and only that data.
The top level of security is the Company. You can create your own Company, and you will then become the default Administrator of that Company. Any new Members of the Company will have to be added by email address to the Company by a Company admin. Contact your Company’s admin to be added to the correct company.
Inside a Company you can have one or more Programs. A Program is simply a way to group users and their data. Programs can be added and removed as the need arises. You must belong to at least one Program to start uploading data.
Note
Any authorized user can create Companies and Programs. When you create a Company or Program, you become the default Administrator.
Once set up, users of the Dashboard will only be able to see data that has been uploaded to Programs that they belong to. You will not be able to see any data outside of your assigned Programs (unless manually shared with you). You will not be able to see any User or Company information outside of your own. So, one Company using the Collier Aerospace HyperX Dashboard will have no knowledge of any other Companies using the Dashboard, unless given explicit permission to view another Company.
Company User Roles
There are several different Roles a user can have in a Company that grants them different permissions. Below is a description of each Role.
-
Member – Can view data specific to the Company and who else is in the Company.
-
Maintainer – Can do anything that a Member can plus add or remove users from the Company.
-
Administrator – Can do anything that a Maintainer can do plus change the Company name and delete the Company.
Program User Roles
There are several different Roles a User can have in a Program that grants them different permissions. Below is a description of each Role.
-
Member – Can view data uploaded to the Program and who else is in the Program.
-
Maintainer – Can do anything that a Member can plus add or remove users from the Program.
-
Administrator – Can do anything that a Maintainer can plus change the Program name and delete the Program.
Collier Aerospace Hosted HyperX Dashboard
When using the Collier Aerospace Hosted Dashboard, all uploaded data is stored in AWS GovCloud. AWS GovCloud is ITAR compliant for storing data in the cloud. As part of the GovCloud shared responsibility model, the HyperX Dashboard provides ways to help ensure data is only accessible to authorized users. The sections above cover all of the security measures available to secure data. The HyperX Dashboard provides these security features to help protect data, but it is ultimately the Dashboard User’s responsibility to ensure data is only accessible to authorized users.
Dashboard Maintainers/Administrators have the following responsibilities:
-
Ensure all members of a Program containing ITAR data are authorized to handle ITAR data
-
Programs that only contain members authorized to handle ITAR data are referred to as ITAR Programs.
-
All Dashboard Users have the following responsibilities:
-
Ensure ITAR data is only uploaded to ITAR Programs
-
By default, data is only accessible to Members of a Program.
-
-
When manually sharing data outside of a Program, ensure the User(s) receiving the data are authorized to handle ITAR data.
-
Users outside of a Program can only view the data if manually shared with them.
-
On-Premise HyperX Dashboard
When hosting the HyperX Dashboard on your own servers, in addition to the responsibilities listed above, you have the following responsibility:
-
Ensure the Dashboard is installed on servers that are ITAR compliant.
Are User Accounts Secure?
Yes. User accounts are maintained using the Keycloak IAM solution. User information and passwords are always transmitted over HTTPS so that they are encrypted. Passwords are never stored in plain text.
Does HyperX Upload Data Securely?
Who Can See My Uploaded Data?
By default, only Members of the Program that you upload to can see your data. If you manually share charts with Users outside of your Program, they will also have access to the data used to create that chart. Shared data can be unshared at any time which will remove access from Users who previously had the data shared with them.
The Dashboard site administrator has access to all servers that make up the Dashboard, including the Dashboard database (i.e. the raw data behind the Dashboard), only for purposes of maintaining the database and website. Under no circumstances will Collier Aerospace administrators access your data for reasons other than maintaining the servers.
Important
No other Collier Aerospace employees or anyone outside of Collier Aerospace will ever have access to your data unless you manually grant access to that individual.
Can I Upload ITAR Data?
Yes. All data is stored in AWS GovCloud, which is ITAR compliant. See ITAR Compliance above for more info.
Can I Install the Dashboard Locally and Use It Without an Internet Connection?
Yes. The Dashboard can be installed and managed locally so that it can be used without transferring data off your premises.