Security and data protection
Learn about the measures in place to protect sensitive data, including encryption, compliance with privacy laws, user role management, and secure data storage practices.
Implement a secure backup and recovery process for learner records and content
- Describe in detail the data backup process, including what is required of us as an institution, where data is kept, how long data is available, and how data backups can be accessed.
We perform daily SQL database backups and store them on our server for seven days. Data can also be exported via SFTP to your server, where you can retain it for as long as needed.
Is data archived? How long is data maintained
Yes, Moodle allows data archiving through backups. Course and user data can be archived manually or automatically using scheduled backups. The duration of data maintenance depends on your organization’s retention policies, as Moodle provides the flexibility to configure and manage data retention as per your needs.
How do you protect our data? Please detail the security provided by your hosting environment
We use BuyVM.net for hosting, which provides robust security measures, including Tier 4 certified data centers with 24/7 on-site security, DDoS protection, Full Disk Encryption (FDE) for data at rest, and private networking for secure internal data transfer. Regular backups and snapshot capabilities further ensure data integrity and recovery, protecting your data with comprehensive security at every level.
Describe your backup procedures
Our backup procedures include regular backups of course data, stored for 10 years, and virtualization snapshots to mitigate data loss. Backups are tested specifically for restore scenarios. Data is stored in a secure facility with multi-layer access controls, monitored by FranTech, our hosting provider.
Do you have a disaster recovery plan
Yes, our disaster recovery plan includes maintaining separate production and quality assurance servers, using virtualization snapshots to mitigate data loss, and testing for backup restoration scenarios. Our hosting provider, FranTech, ensures infrastructure resilience with multi-homed data centers, robust security measures, and a proven record of disaster recovery.
Team notes
Taken this from Ferantech or buyvm.net.
Does your organization engage executive oversight for cybersecurity? If yes, describe your organization’s information security governance structure
Yes, our organization engages executive oversight for cybersecurity.
Does your organization have a designated Information Security Officer? If not, who has primary responsibility for your organization’s information security program
No, our organization does not have a designated Information Security Officer. The primary responsibility for our information security program rests with the Vice President and the Web Developer.
Does your organization have defined, documented information security standards, policies, and supporting procedures? If yes, identify the foundational framework (NIST, ISO, et. al.) in use
Yes, our organization maintains a documented information security policy and procedures aligned with NIST 800-53 and ISO/IEC 27001 frameworks. This policy covers access control, data classification, encryption standards, incident response, backup and disaster recovery, personnel security, vendor management, and regulatory compliance. We also comply with PCI DSS through quarterly third-party audits, and our platform delivery follows SOC 2 Type 2 controls.
Does your organization engage in information security audits and/or risk assessments? If yes, how often are they performed? Are these engagements performed in-house or outsourced to third parties
Yes, our organization conducts information security audits. We use third-party PCI audits for customer payment information, performed quarterly.
Does your organization outsource - in whole or in part - cybersecurity functions to third party service providers? If yes, identify the outsourced functions and those performed in-house
Yes, our organization outsources cybersecurity functions in part. PCI audits are performed by a third party, while all other cybersecurity functions are handled in-house.
Is your proposed product or service considered a medical device subject to regulation by the Food and Drug Administration? If yes, provide a Manufacturer Disclosure Statement for Medical Device Security (MDS2) for each proposed product/service
No, our proposed service is not considered a medical device subject to regulation by the Food and Drug Administration.
Does your proposed product or service require access to customer confidential data? If yes, please identify the necessary data elements. “Confidential data” refers to Protected Health Information (HIPAA), Cardholder Data (PCI), or other data intended for restricted access or use
No, our proposed service does not require access to or use of customer confidential data, including Protected Health Information (HIPAA) or Cardholder Data (PCI).
Is a formal software development process in place that includes application security requirements
Yes, we follow a Secure Software Development Lifecycle (SDLC) that includes application security requirements.
Are security reviews and regression testing performed on application source code
Yes, security reviews and regression testing are performed on Moodle’s application source code. Regular security audits and automated regression tests are conducted to ensure security and functionality.
Is the proposed product or service subject to industry certifications? If yes, please describe. If your product or service is subject to SOC 2 requirements, please provide your most recent report
Yes, our proposed product Moodle is developed and delivered in accordance with industry-recognized security standards. Moodle U.S. has achieved SOC 2 Type 2 and SOC 3 compliance, as verified by an independent audit. You can read more about this achievement in the official Moodle news release.
While the Moodle platform and our managed services are compatible with SOC 2 requirements, please note that individual client Moodle instances are not automatically certified at the time of installation. If a client requires SOC 2 certification for their specific instance, this can be pursued as a separate process, but it is not included in the standard offering or price. Additionally, Moodle relies on its hosting providers for other certifications such as ISO/IEC 27001, SOC 2 (via AWS), and GDPR compliance.
Does your organization staff its data centers? If not, identify your data center service provider. Identify the number and location of your data centers
We use BuyVM as our data center provider. Their data centers are located in Las Vegas and New York.
Are any of your organizations’ data centers located outside of the United States? If yes, please identify the locations of these “offshore” data centers
No, all our data is stored within the United States, specifically in the data centers located in Las Vegas and New York.
If offshore data centers are in use, are they staffed by your organizations’ workforce or outsourced to third-parties? If outsourced, please confirm that staff agreements cover appropriate data confidentiality requirements
No, all of our data centers are located within the United States. We do not utilize offshore data centers.
Are periodic vulnerability scans performed on information technology systems, networks and supporting security systems
The PCI audit is conducted by a third party on a quarterly basis. This includes vulnerability scans of our IT systems, networks, and supporting security systems to ensure compliance with PCI standards.
Does your organization conduct penetration testing of internal and external data environments? If yes, is the testing performed in-house or outsourced to third parties? How often is penetration testing performed
Penetration testing is part of the quarterly PCI audit and is conducted by a third party.
Does your organization maintain a cybersecurity incident response plan? If yes, how often is the plan tested and updated? What manner of testing is used
Yes, we maintain a cybersecurity incident response plan. The plan is tested annually through simulated exercises to ensure readiness. It is updated regularly based on lessons learned, emerging threats, and any organizational changes.
Secure files transfer
Provides secure file transfer capabilities through encrypted protocols for uploading, downloading, and managing files. Files uploaded to the platform are stored securely on the server, and administrators can set permissions to control who can access, download, or modify files. Moodle supports SSL encryption for secure data transmission and allows restricted access to sensitive content based on user roles.
Does your system provide an approval workflow, including notifications that inform learners and supervisors of enrollments that require approval, new enrollments for themselves and direct reports, and enrollment cancellations
Moodle does not have built-in approval workflows, but this can be achieved by installing plugins like “Enrolment upon approval” or “Course Request Approval”. Notifications can be configured through Moodle’s messaging system.
Does your system include regular automated data backups and disaster recovery measures
Moodle supports automated backups of courses, user data, and configurations, and includes disaster recovery options for system restoration in case of failures.