Barracuda WAF-as-a-Service
Barracuda Web Application Firewall protects applications, APIs, and mobile app backends against a variety of attacks including the OWASP Top 10, zero-day threats, data leakage, and application-layer denial of service attacks. By combining signature-based policies and positive security with robust anomaly-detection capabilities, Barracuda WAF can defeat today’s most sophisticated attacks.
Features
- OWASP Top 10 Protection
- API Protection
- Advanced Bot Protection
- Virtual Patching
- Reporting & Analytics
- Load Balancing
- Chaching and Compression
- Traffic Encryption
- Authorization
- CAPTCHA Challenges
Benefits
- Ensure protection from web attacks and DDoS
- Protect your APIs and mobile apps
- Stop bad bots dead in their tracks
- Automate and orchestrate security
- Enable granular access control and secure app delivery
- Gain deep visibility into attacks and traffic patterns
- Proven Security - OWASP Top 10 recognized
- Massively scalable and globally available
- Simplicity with flexibility
Pricing
£3.64 a licence a month
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
1 9 8 8 9 4 4 8 5 4 9 1 2 6 2
Contact
MISCO TECHNOLOGIES LIMITED
Kerry O'Halloran
Telephone: 07722029727
Email: kerryo@misco.co.uk
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- Service is based on license model
- System requirements
-
- Access to communicate with backend web server / system
- Per application license
- Bandwidth allocation
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- 2 hours for critical issues
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Web chat
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Receive technical support and help. Open support tickets for issues.
- Web chat accessibility testing
- Not known
- Onsite support
- No
- Support levels
-
All Barracuda SaaS software comes with 24x7x365 support services included with the service. Premium support can be purchased at additional cost.
https://assets.barracuda.com/assets/docs/dms/Barracuda_Premium_Support.pdf - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- All Barracuda customer have access to Barracuda Campus which documents both how to use the system and gives access to self paced video training. Customer may also purchase Professional Services direct from Barracuda to support installation and delivery of the solution. Professional Services are an additional cost.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- At end of contract Barracuda will destroy any data held within the system within 90 days of license expiry. If customer would like to extract data contract Barracuda Support or Account Manager to discuss options. Professional Services charges may apply for data extraction
- End-of-contract process
- At end of contract Barracuda will destroy any data held within the system within 90 days of license expiry. If customer would like to extract data contract Barracuda Support or Account Manager to discuss options. Professional Services charges may apply for data extraction
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
The Barracuda Web Application Firewall supports a comprehensive REST API module for management and configuration.
https://campus.barracuda.com/product/webapplicationfirewall/api - API documentation
- Yes
- API documentation formats
-
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- Barracuda WAF as a Service has multiple monitoring mechanisms in place to ensure resilliance of services with auto scale capabilties. This ensures as load varies on the platform the correct services are allocated to ensure performance for each customer and across the platform.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
The Barracuda Web Application Firewall reports are broadly classified into following groups:
Security Reports
Summary Reports
PCI DSS Reports
Administration/Audit Reports
Configuration Summary Reports
Traffic Reports: Aggregated System Traffic Reports, Client Traffic Reports, Service Traffic Reports, Server Traffic Reports - Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Barracuda
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- No
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Data sanitisation type
-
- Explicit overwriting of storage before reallocation
- Deleted data can’t be directly accessed
- Equipment disposal approach
- In-house destruction process
Data importing and exporting
- Data export approach
- Via the reporting functionality
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Barracuda Networks supply a service with an SLA of 99.9%. See link for latest SLA documentation
https://assets.barracuda.com/assets/docs/dms/Barracuda_WAFaaS_SLA_US.pdf - Approach to resilience
- Barracuda WAF-as-a-Service is designed and built with resillence in mind. Further Information is available upon request.
- Outage reporting
- Customer may subscribe to outage notifications via SMS and Email for the relevant services. They can also view the outage status by visiting https://status.barracuda.com
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Username or password
- Other
- Other user authentication
- Authentication is required to access the platform. This can be username and password with inbuilt MFA or syncronised with Azure AD
- Access restrictions in management interfaces and support channels
- Access is based on username and password with MFA. Access to functions is controlled via RBAC.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Other
- Description of management access authentication
- Authentication is required to access the platform. This can be username and password with inbuilt MFA or syncronised with Azure AD
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
- SOC type 2
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- Other
- Other security governance standards
- SOC 2 Type 2
- Information security policies and processes
-
Please see below for overview of security standards
https://assets.barracuda.com/assets/docs/dms/Barracuda-WAF-as-a-Service-Security-Overview.pdf
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Details around policies and procedures are not published to the public. Information can be requested during procurment if required
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
If Barracuda becomes aware of any unlawful access to any Customer Data stored that results in the loss, disclosure or alteration of Customer Data (“Security Incident”), Barracuda will promptly (1) notify Customer; (2) investigate the Security Incident; (3) take reasonable steps to mitigate the effects of, and minimize any damage resulting from, the Security Incident.
Security Incidents Notification(s) will be delivered to one or more Customer administrator by a means selected by Barracuda, including via email.
Customer must notify Barracuda promptly of any possible misuse of its accounts or authentication credentials or any security incident related to a Cloud Service. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Details around policies and procedures are not published to the public. Information can be requested during procurment if required
- Incident management type
- Supplier-defined controls
- Incident management approach
-
If Barracuda becomes aware of any unlawful access to any Customer Data that results in the loss, disclosure or alteration of Customer Data, Barracuda will promptly (1) notify Customer; (2) investigate the Security Incident; (3) take reasonable steps to mitigate the effects of, and minimize any damage resulting from, the Security Incident.
Security Incidents Notification(s) will be delivered to one or more Customer administrator by a means selected by Barracuda, including via email.
Customer must notify Barracuda promptly of any possible misuse of its accounts or authentication credentials or any security incident related to a Cloud Service.
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Equal opportunity
Fighting climate change
Our solution is designed to be run as a software only platform, so that no additional hardware is required thus having a carbon neutral impact. Our software is designed as work from home solution, and positively helps customers with their own Covid 19 solutions. We are an equal opportunity employer and staff, irrespective of gender are paid the same for the same job.Covid-19 recovery
Our solution is designed to be run as a software only platform, so that no additional hardware is required thus having a carbon neutral impact. Our software is designed as work from home solution, and positively helps customers with their own Covid 19 solutions. We are an equal opportunity employer and staff, irrespective of gender are paid the same for the same job.Equal opportunity
Our solution is designed to be run as a software only platform, so that no additional hardware is required thus having a carbon neutral impact. Our software is designed as work from home solution, and positively helps customers with their own Covid 19 solutions. We are an equal opportunity employer and staff, irrespective of gender are paid the same for the same job.
Pricing
- Price
- £3.64 a licence a month
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Free Web Application Vulnerability Scan.
Free 30 day trial of Web Application Firewall. - Link to free trial
- https://www.barracuda.com/waf-as-a-service