August 26, 2016
Recently, questions were raised about Salesforce’s ability to compete in industries that require high levels of protection on their data. Their response? Salesforce Shield. Beyond adding stronger security capabilities to the platform, Salesforce Shield is a signal of Salesforce’s willingness to prioritize and respond to arising needs of different industries as they scale and expand into being the platform solution for areas like health and financial services. Salesforce Shield is a critical piece of the platform, despite being a new addition. Here, I’ll go through frequently asked questions about the software as an introduction.
What is Salesforce Shield?
Salesforce Shield is a software suite that encompasses four main services: Event Monitoring, Field Audit Trail, Platform Encryption, and Transaction Security. Shield was created as a response to the concern that comes from data that used to be stored on private servers now being stored in the Cloud. While Salesforce has always maintained good practices in order to prevent data leakage in the Cloud, Shield is the next step because it allows for an additional level of security in order to meet certain industry regulatory compliance rules.
What are the use cases for Shield?
The uses for Shield’s additional security features depend on the business’s current or planned use of Salesforce.
- Event Monitoring is highly useful during an audit. If an organization is frequently audited, Event Monitoring is a great tool because it allows all of the changes made within Salesforce per user to be tracked. Salesforce Classic has a feature that is similar to Event Monitoring but often enterprise clients need more than the basic functionality that comes built in to Salesforce. Event Monitoring is a more exhaustive add-on option.
- Transaction Security allows users to add processes to Event Monitoring. When a certain event happens, you can configure Salesforce to use that event as a trigger for another event or process to happen. Examples of this would be: preventing users from accessing Salesforce via an unsupported browser, restricting or triggering a notification of an API extraction of data, requiring two-factor authentication (2FA) for specific reports, etc.
- Field Audit Trail, similar to Event Monitoring, is a more exhaustive version of a Salesforce feature that already exists. Field History is the free version which supports 20 tracked fields and retains data for 18 months. Field Audit Trail supports an audit history of the past 10 years of data with up to 60 fields per object tracked. Again, any highly audited company that is being frequently asked to export this data will be glad for this feature.
- Platform Encryption allows you to encrypt the data stored in Salesforce. Salesforce is currently piloting a Bring Your Own Key (BYOK) feature and -- unlike standard encryption-- this allows for encryption of standard fields and supports encrypting unstructured content like files. It supports search, and platform functions such as validation rules, workflows, etc. are made encryption aware meaning that data encryption won’t interrupt their function like Salesforce’s basic encryption feature does. There’s no limit on encryption field size with Shield, allowing for much more robust data encryption.
Does every business need to use Shield?
No. For many businesses the security built into Salesforce is adequate. Salesforce Classic even allows for the encryption of data it just doesn’t support as many features as Salesforce Shield and won’t meet the more stringent security requirements of certain industries.
Is Shield secure enough to protect financial and health organizations’ information?
Yes, for most of them. Salesforce is rapidly working to make sure Shield meets all security standards so any areas of shortfall should be resolved soon. The release of Shield’s BYOK feature will be a big step towards this as it will provide local control over the generation and storage of encryption keys. This is an industry security standard in many industries that deal with extremely sensitive data.
What’s the process for setting up Shield? Do you need a developer team?
Shield set-up is admin friendly. No customization is required, making it easy to set up by anyone with basic Salesforce knowledge.
What are advantages to using Shield vs. third-party encryption services?
The biggest advantage to Shield is that it’s a native solution. This provides quick benefits such as easier set-up and an expedited vetting process for enterprise clients. Secondly, the need for integrations and customizations necessary to work with Salesforce must be reviewed for security best practices when using third-party vendors. This need is abolished when using a native Salesforce solution. The operation of Salesforce Shield is typically much faster than a third-party vendor because it does not have to relay the traffic through an additional layer. Finally, the use of a third-party vendor does require infrastructure setup in most cases, so going back to the question above, Shield is much easier to set-up than outside software. Note that customers who wish to have exclusive custodianship of their encryption key will still need to use a third-party encryption service.
This addition to Salesforce as a platform was a necessity in their maturity as cloud encryption has become an essential requirement of cloud computing. The growth of industry-specific clouds to include the health and financial services industries added urgency to this security emphasis. As the uses of Salesforce grows and becomes more complex, it’s exciting to see the platform evolving.
To learn more about how the best IT teams are using Salesforce, download our special report based on data gathered from over 1,500 users.