Ceridian Self Service System

Due to the sensitive nature of HR and payroll data, security is critical. With Ceridian, all salary, employment, and personal data are safe from unauthorized access. Ceridian uses the highly secure, and Web standard 128-bit SSL (Secure Socket Layer) technology to prevent eavesdropping of the communications between the browser and the server. SSL is the industry-standard method developed by Netscape Communications Corporation for protecting Web communications. The SSL security protocol provides data encryption, server authentication, message integrity, and optional client authentication for a TCP/IP connection. SSL comes in two strengths, 40-bit and 128-bit, which refer to the length of the "session key" generated by every encrypted transaction. The longer the key, the more difficult it is to break the encryption code. Any software with encryption features having key lengths over 40 bits is considered strong encryption by the U.S. Government for export purposes.

Most browsers support 40-bit SSL sessions, and the latest browsers enable users to encrypt transactions in 128-bit sessions. 128-bit encrypted messages are 309, 485, 009, 821, 345, 068, 724, 781, 056 (3.09x1024) times harder to break than 40-bit messages.

All auditing and validation is performed by the SQL 2000DB on the server.

Our policy does not allow specific naming of the security products used; however, the products are within the top three market leaders. (The question associated with this record asks what type of firewall, vendor release level, operating systems we use.)

Ceridian uses a multi-tiered DMZ design. MetaFrame ports 1494 TCP and 1604 UDP are open to the Internet for MetaFrame use. Web servers are located on a separate segment, with only ports 80 and 443 (for SSL communication) open to the Internet.

We have security monitoring in the form of log reviews and Intrusion Detection. Intrusion Detection is based on both signatures and anomaly occurrence and include both network and host sensors. The IDS systems deployed include the ability of automated and manual responses based on the event and also provide for event correlation thereby suppressing duplicate events.