Security
GeMS SWIFT is the complete solution for the
creation, management, delivery, tracking, and reporting of
performance-based SWIFT adaptive eLearning courses and
SWIFT assessment programs over the Internet, Intranet or on
CD-ROM/DVD-ROM. Comprised of GeMS, SWIFT eLearning and Assessment
Environments, and the SWIFT Author, GeMS SWIFT is the only
complete solution that can be up and running in minutes.
GeMS is a web-based Server Application that delivers,
manages, and tracks SWIFT eLearning courses and assessments
published from the SWIFT Author. GeMS is a highly secure
web-based application that includes its own integrated web
server, and administration and reporting interface for
remote management of SWIFT training courses, SWIFT
assessments, and third party training content.
Easy To Install And Secure By Default
GeMS SWIFT's installation program installs and
configures GeMS. There are no caveats or installation
options that must be specified in order to ensure absolute
security. The Server is secure by default.
Host File System Access Is Restricted
Conventional web servers can be manipulated to allow
access to the entire file system. Conversely, GeMS
"document root" is hardwired to a specific subdirectory
beneath the server executable location. This setting cannot
be bypassed.
Authentication
GeMS supports NT Domain and UNIX password authentication
in addition to our own. Support can be added for other
authentication mechanisms.
SSI (Server Side Includes) And CGI (Common
Gateway Interface)
SSI and CGI are commonly used to gain unauthorized
access to host systems and/or to execute arbitrary programs
compromising the security of conventional web servers. GeMS
does not require nor provide SSI or CGI.
HTTP PUT Requests Are Not Processed By
GeMS
Only authenticated users are permitted to upload files
to GeMS via SWIFT Author.
SSL (Secure Sockets Layer)
SSL is fully supported in GeMS.
Extensive Logging
Author, administrator, and learner interactions with
GeMS are logged. If unauthorized access is attempted the
event is logged complete with information that can be used
to track the offending user.
|