Cybersecurity
With SeqSphere+ version 10.5 we did (with fixing of several issues; all were non-critical) and will do proactive vulnerability assessments in preparation for the EU Cyber Resilience Act. Systematic external OWASP assessment is in progress. Critical updates will be communicated to all registered users via email, via our home-page, and within the software. With respect to cybersecurity the following topics next to required ports (see below) might be of interest:
- The password policy can be defined for the user accounts by the admin (by default no policy is set).
- The access logging can be enabled, that logs user logins, sample retrieval, storage, and deletion. They are stored in monthly CSV files (by default access logging is disabled).
- The sample audit trail logs each modification for a sample, together with user login name and timestamp. The audit trail is always enabled. It is lost when the sample is deleted.
- The default database schema does not contain direct patient identifiers (like patient name, patient id or birthday). Users with permissions to edit project samples can also add such new fields. However, user roles can be configured to prevent users from creating new fields, thereby restricting the storage of sensitive patient information.
- It is recommended to open the server port (by default 8064) only to the client computers and not to the internet.
Ports and Services
The communication between Ridom Typer Client and Ridom Typer Server runs on port 8064 (port can be changed).
The server and client are communicating via https using a self-signed certificate that is created when the server is started for the first time (SHA-256 with RSA encrypting, 2048 bit).
For some (optional) functions the Ridom Typer Client needs an internet connection. The following hosts are connected:
Upload
| Function
|
Host
|
Protocol, Port
|
Upload/download for Ridom Typer license activation, alternatively activation by email possible |
act.ridom.de |
https, 443
|
Upload of alleles and optional allelic profiles for cgMLST.org submissions and download of task templates |
nomenclature.ridom.de |
https, 443
|
Upload of spa-types and optional metadata for S. aureus spa-typing and download of spa-types |
spa.ridom.de |
https, 443
|
| Upload of meta data for EBI ENA submission |
www.ebi.ac.uk |
https, 443
|
| Upload of read data for EBI ENA submission (via FTP or Aspera) |
webin.ebi.ac.uk |
ftp, 21 or TCP/UDP, 33001
|
The top two functions are recommended, the bottom three are only optional functions.
Download
| Function
|
Host(s)
|
Protocol, Port
|
| Download of MBioSEQ Ridom Typer software updates |
www.ridom.de |
https, 443
|
| Download of genomes from NCBI Genome |
www.ncbi.nlm.nih.gov |
https, 443
|
| Download of read data from NCBI SRA |
trace.ncbi.nlm.nih.gov, sra-pub-run-odp.s3.amazonaws.com |
https, 443
|
| Download of MLST schemes from BIGSdb at Oxford University |
pubmlst.org, rest.pubmlst.org |
https, 443
|
| Download of MLST schemes from BIGSdb at Institut Pasteur |
bigsdb.pasteur.fr |
https, 443
|
| Geocoding with GeoNames |
www.geonames.org |
http, 80
|
Additional Download required only for Linux
| Function
|
Host(s)
|
Protocol, Port
|
| Download of conda packages from conda-forge and bioconda (anaconda default channel is not used) |
conda.anaconda.org |
https, 443
|
| Download of MOB-Suite and CheckM2 databases |
zenodo.org |
https, 443
|
| Download of Biopython package |
pypi.org |
https, 443
|
The Ridom Typer Server does not require any internet connection.
Submission to public cgMLST.org
The public cgMLST.org Nomenclature Server (www.cgMLST.org) provides a global nomenclature for stable public cgMLST schemes, i.e. for Task Templates that were downloaded from the Task Template Sphere. If Samples are using those downloaded Task Templates some data might be submitted to cgMLST.org anonymously:
- when Samples are processed for such a Task Template, the new allele sequences are by default anonymously automatically submitted to and stored at cgMLST.org (usually 2-3 target/gene sequences per new genome). The automatic allele submission can be disabled in the in the client settings, by using the menu item Options | Preferences, and selecting the the item Online Connection | Allele Submission to cgMLST.org. However, if a Sample has new alleles that are not known at cgMLST.org, the new alleles are treated as missing data in the distance calculation (e.g., in Comparison Table) and/or
- for samples that do not belong to an existing Complex Type (CT), it is possible to submit the allelic profile to define a new CT. The allelic profile of the new CT will be stored on cgMLST.org. No epi data or submitter data of the sample will be stored on cgMLST.org. The automatic submission of allelic profiles can be configured in a pipeline script. By default this option is also turned on.
If no submission of any data is wanted or allowed, then only local Task Templates must be used. Samples that are using only local Task Templates will not and cannot be submitted to cgMLST.org. Local Task Templates can be defined using the cgMLST Target Definer, or by converting public Task Templates into local ones.
Remote Access
By installing Ridom Typer, Ridom has by no means remote access to the user's local computer or Ridom Typer database.
Remote access for training and support is usually done with Microsoft Teams.