BOXXE LIMITED

boxxe Sophos Firewall

Sophos Firewall provides a true next-gen platform to tackle the modern encrypted internet and evolving threat landscape. It identifies hidden risks, protects against threats, and responds to incidents without taking a performance hit. Xstream Architecture utilizes a packet processing architecture that delivers extreme levels of visibility, protection, and performance.

Features

  • Deep packet inspection
  • Intrusion prevention (IPS)
  • Zero day protection
  • Proxy-based dual-engine anti-virus scanning
  • Perimeter defence
  • Country-based blocking
  • TLS1.3
  • Machine learning
  • Deep learning file analysis
  • Advanced web protection

Benefits

  • HTTPS scanning
  • Pharming protection
  • Application control
  • Traffic shaping (QoS0
  • CASB cloud app visibility
  • Two factor authentication (2FA)
  • Education and SafeSearch features
  • Web caching
  • Web application firewall
  • Live anti-spam

Pricing

£0 a device

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at peter.parsons@boxxe.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

7 5 1 3 8 0 7 0 9 7 9 2 6 3 5

Contact

BOXXE LIMITED Peter Parsons
Telephone: 07704551950
Email: peter.parsons@boxxe.com

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Retirement calendar for EOL of software and hardware versions: https://support.sophos.com/support/s/article/KB-000035279?language=en_US
System requirements
  • For hardware instances, not applicable as installed on Sophos hardware
  • For software appliance: network interface cards X2
  • For software appliance: RAM: 4GB minimum
  • For software appliance: HDD or SSD: 10GB minimum, 64GB recommended
  • USB pen drive: 1GB

User support

Email or online ticketing support
Email or online ticketing
Support response times
Sophos Support is available 24 hours per day, 7 days per week, 52 weeks per year, including statutory, public, and bank holidays.

For Enhanced Support Plan:
Critical Within 4 hours
High Within 8 hours
Medium Within 24 hours
Low Within 24 hours

For Enhanced Plus Support Plan:
Critical Within 1 hour
High Within 2 hours
Medium Within 24 hours
Low Within 24 hours

Please see this link for details (page 9):
https://www.sophos.com/en-us/medialibrary/PDFs/Support/Sophos-Support-Services-Guide.pdf
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AA or EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Web chat
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
WCAG 2.1 AA or EN 301 549
Web chat accessibility testing
No testing has been completed at this time.
Onsite support
Yes, at extra cost
Support levels
Enhanced
• 24/7 multi-channel support
• Software downloads, updates, & maintenance
• Access to support knowledgebase and support forums
• Warranty (Appliances only)
• Hardware replacement (Appliances only)
• Remote assistance support

Enhanced Plus - includes all features of the Enhanced plan above and the following:
• Remote consulting
• Priority case and sample handling
• Phone calls routed to senior Technical Support Engineers

TAM - includes all features of Enhanced and Enhanced plus with the following:
• Named Technical Account Manager (TAM)
• Front of the line access to product information
• Personalized communications and alerts
• Performance and feature optimization
• Enhanced escalation
• Emergency Onsite Support

Please see this link for reference:
https://www.sophos.com/en-us/support/technical-support
Support available to third parties
Yes

Onboarding and offboarding

Getting started
The following resources are available:
https://www.sophos.com/en-us/support/documentation/sophos-xg-firewall
Service documentation
Yes
Documentation formats
HTML
End-of-contract data extraction
To export all the records from the firewall log to a text or CSV file:

On the Home page, under Firewall, click View firewall log.
For information about the Home page, see About the Home page.

In the console tree, select a log.
Right-click the record list, and then click Export All Records.
In the File name box, type a name for the file.
In the Save as type list, click the file type that you want.
End-of-contract process
The customer will be unlicensed, out of support and will stop receiving product updates and protection.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
WCAG 2.1 AA or EN 301 549
Description of service interface
Sophos Central provides cloud management for all Sophos products, including Sophos Firewall. It makes day-to-day setup, monitoring and management for the Sophos Firewall easy. It also provides helpful features such as alerting, backup, management, one-click firmware updates and rapid provisioning of new firewalls.
Accessibility standards
None or don’t know
Description of accessibility
The Sophos Central Admin Console can be accessed at https://cloud.sophos.com/ with supported web browsers.
Sophos Central currently supports the following browsers:
• Google Chrome.
• Microsoft Edge.
• Mozilla Firefox.
• Apple Safari (Mac only).

It is recommended to install or upgrade to a supported version in the above list and to always run an up-to-date version. Sophos aims to support the latest version and previous versions of Google Chrome, Mozilla Firefox, and Apple Safari.

Only users with an admin role can access the management console. The login requires an email and password as well as an MFA (Multi-factor Authentication).
Accessibility testing
Sophos Central does not currently have a VPAT compliance attestation. As a central console, many separate Sophos products appear in Sophos Central. Some of these products are accessibility compliant and we continue to improve the accessibility of our individual products.
API
No
Customisation available
No

Scaling

Independence of resources
Sophos Central is segmented into a number of logically separate virtual networks based on the various workloads they perform (such as authentication or endpoint management). All workloads are then placed into auto-scaling groups, behind a load balancer, so that when a particular workload sees increased load/traffic, additional temporary resources can be allocated to give the group capacity to handle the load.

Analytics

Service usage metrics
Yes
Metrics types
Extensive on-box reporting provides valuable insights into threats, users, applications, web activity and much more. Note that specific reporting functionality may be dependant on other protection modules to get the full benefits (for example web protection or web and app reports)
Reporting types
  • Real-time dashboards
  • Regular reports

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Sophos

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
Explicit overwriting of storage before reallocation
Equipment disposal approach
In-house destruction process

Data importing and exporting

Data export approach
To export all the records from the firewall log to a text or CSV file:

On the Home page, under Firewall, click View firewall log.
For information about the Home page, see About the Home page.

In the console tree, select a log.
Right-click the record list, and then click Export All Records.
In the File name box, type a name for the file.
In the Save as type list, click the file type that you want.
Data export formats
  • CSV
  • Other
Other data export formats
PDF
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Transport-level encryption is used to secure management communication between the client software and Sophos Central platform via certificates and server validation.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • Other
Other protection within supplier network
It is carried out using secured services such as SFTP, HTTPS, TLS encrypted, etc.

Availability and resilience

Guaranteed availability
Sophos Central does not provide a traditional SLA because the availability of our products is not dependent on the availability of the web portal. However, the availability of the web portal ranged between 99.99 and 100% over the past year, depending on geographic region.

Sophos Central status can be viewed here:
https://centralstatus.sophos.com/#!/
Approach to resilience
Sophos Central is hosted on Amazon Web Services (AWS), across a number of virtual machine instances and services that dynamically scale to handle the current Sophos Central workload.

Sophos Central is segmented into a number of logically separate virtual networks based on the various workloads they perform (such as authentication or endpoint management). All workloads are then placed into auto-scaling groups, behind a load balancer, so that when a particular workload sees increased load/traffic, additional temporary resources can be allocated to give the group capacity to handle the load.
Outage reporting
Sophos Central status can be viewed here:
https://centralstatus.sophos.com/#!/

It also has a subscribe button at the top right to receive status notifications.

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Access to the Sophos Central admin console requires a login (email and password) as well as MFA (Multi-Factor Authentication).
Sophos Central also supports Azure AD Federation authentication.

Except for the SuperAdmin, Users need to have an admin role assigned to them to get access to the Sophos Centrla admin console.
Access restrictions in management interfaces and support channels
Sophos Central has a Role Management feature that provides admins the capability to assign pre-defined administrative roles to users who need access to the Sophos Central Admin Console. The following are the available pre-defined administrative roles:
• Super Admin
• Admin
• Help Desk
• Read-only

Please refer to this link for more information:
https://docs.sophos.com/central/Customer/help/en-us/central/Customer/concepts/AdminRoles.html
Access restriction testing frequency
At least every 6 months
Management access authentication
  • 2-factor authentication
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Access to the Sophos Central admin console requires a login (email and password) as well as MFA (Multi-Factor Authentication).
Sophos Central also supports Azure AD Federation authentication.

Except for the SuperAdmin, Users need to have an admin role assigned to them to get access to the Sophos Centrla admin console.

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 1 month and 6 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 1 month and 6 months
How long system logs are stored for
Between 1 month and 6 months

Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
A-Lign
PCI DSS accreditation date
09/02/2021
What the PCI DSS doesn’t cover
It only covers our Sophos MTR Product.

Other Sophos Central products do not contain or protect any cardholder-related information and is therefore not required to be PCI Compliant.
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
SOC 2 Type 2

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
No
Security governance approach
The Sophos Information security framework (SISP) is based upon leading practices such as ISO 27001, SOX, and PCI as well as with Sophos priorities. Our ISPF and Security policy is part of a holistic approach to Information Security Management. Contents of ISP and security policy drives development of technical security standards, processes, and configurations will be utilized by staff and vendors to implement security controls. They also provide the context for training, awareness, audits, and compliance assurance activities. Lastly, they provide Sophos with necessary information to risk adjust business initiatives and improve the state of the Sophos Information Security Program.
Information security policies and processes
Sophos has a dedicated cybersecurity team. The team has developed and deployed security policies, standards, and procedures validated by an active governance and audit program.
Sophos aligns with the NIST Cybersecurity Framework and ISO 27001 controls.

Please see this link for the High-Level Overview of the Sophos Security Policy:
https://www.sophos.com/en-us/trust/high-level-security-policy-overview

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Changes to the production environment are strictly done after following our Change management process (including approval from the Security team if needed) and are reviewed by the operational team.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Changes to the production environment are strictly done after following our Change management process (including approval from the Security team if needed) and are reviewed by the operational team.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We have developed our plans with guidance from the NIST 800-61 Computer Security Incident Handling Guide and we frequently review these plans for compliance with industry standards.

There are many ways Sophos identifies or becomes aware of security incidents. These include:
• Security monitoring capabilities, often in our products, or complementary methods we have developed
• Bug-bounty reports
• Penetration test findings
• Vulnerability analysis
• Code and application analysis
• Research and threat intelligence analysis
• Customer notifications
To report a potential security incident, please see our Responsible Disclosure Program.

Overview of the Sophos Incident Response:
https://www.sophos.com/en-us/trust/incident-response
Incident management type
Supplier-defined controls
Incident management approach
We have developed our plans with guidance from the NIST 800-61 Computer Security Incident Handling Guide and we frequently review these plans for compliance with industry standards.

There are many ways Sophos identifies or becomes aware of security incidents. These include:
• Security monitoring capabilities, often in our products, or complementary methods we have developed
• Bug-bounty reports
• Penetration test findings
• Vulnerability analysis
• Code and application analysis
• Research and threat intelligence analysis
• Customer notifications
To report a potential security incident, please see our Responsible Disclosure Program.

Overview of the Sophos Incident Response:
https://www.sophos.com/en-us/trust/incident-response

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

Sophos is committed to the principles embodied in the Responsible Business Alliance (RBA) Code of Conduct 7.0 (2021). Our commitment is the key to the Company’s business strategy, informs our decision making at all levels, and is core to the Company’s operating procedures.
Covid-19 recovery

Covid-19 recovery

Sophos has in place a robust set of technologies that enables the majority of our global employees to work from home. As a precautionary measure, and to help prevent the spread of coronavirus, we have advised employees in countries reporting a rising number of cases to work from home. We are fully enabled to continue the day-to-day business, including product development and other important efforts, remotely.

We recognize that many other organizations are requiring employees to work from home and need secure connectivity. Customer information with tips on configuring VPN remote access with XG Firewall is available on our Sophos Community page:
https://community.sophos.com/sophos-xg-firewall/f/recommended-reads/119078/sophos-xg-firewall-useful-links-for-configuring-vpn-remote-access
This article provides a quick and easy reference guide to getting started and more.

We have also published practical security guidance for anyone enabling or exploring remote working:
https://news.sophos.com/en-us/2020/03/12/coronavirus-and-remote-working-what-you-need-to-know/
Tackling economic inequality

Tackling economic inequality

Our work on breaking down economic barriers for people living with disabilities: More than 26 million people in India live with some form of disabilities. Through our partnership with the Smile Foundation and the Blind People’s Association, Sophos funded over 100 mini-convenience stores, creating jobs for people living with disabilities, across Ahmedabad, India. \
Equal opportunity

Equal opportunity

Our work on improving education and gender equality: One of the main barriers preventing girls from getting an education are poverty, gender bias, gender-based violence and the lack of proper sanitation facilities in schools. Heeding the call to action, we sought to uplift Ropada, a small village in India. We started by building a primary school that had access to clean drinking water, roads, solar streetlights, and sanitation facilities. Over the years, we expanded our efforts by providing quality education to rural students by adding mentorship and scholarship programs, building a science lab, implemented community programs to prevent dropouts, and continued to support other school-related activities. As a result, we have sponsored over 600 children, and 45% of those are girls.
Wellbeing

Wellbeing

At Sophos, the health and wellbeing of our global team is our top priority. Staff are provided with the following resources:
Employee Assistance Progamme
EAP Aware Mindfulness Channel - mindfulness exercises facilitated by Aware specialists helping staff to focus, release tension, and reset for improved wellbeing.
Calm - all employees are offered one year’s free subscription to Calm, which helps enhance sleep quality, reduce stress and anxiety, and improve focus.
LinkedIn Learning - A tool available to all Sophos employees, which has information on a number of wellbeing subjects, including building resilience and mindfulness.

Sophos is keen to make it as easy as possible to get involved with charity and volunteering activities, be that whether staff want to support this year's focus charity, volunteer their time and skills for a worthy cause, or making regular pre-tax donations, Sophos provides assistance.

In 2022 the Alzheimer's Society is the primary charity that Sophos is supporting.

Pricing

Price
£0 a device
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Free 30 day trials can be accessed from the Sophos website www.sophos.com.
Link to free trial
Www.sophos.com.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at peter.parsons@boxxe.com. Tell them what format you need. It will help if you say what assistive technology you use.