Fusion 360 for Professional organizations (security, sharing, safety)

Fusion 360 for Professional organizations (security, sharing, safety)

designeyeq
Participant Participant
5,619 Views
13 Replies
Message 1 of 14

Fusion 360 for Professional organizations (security, sharing, safety)

designeyeq
Participant
Participant

I run a small design consultancy and we've begun to take on clients with more competitive and proprietary data. Until now, we've used Fusion 360 and it's cloud based data and collaborative systems for small clients.

 

Do any users work with larger organizations with valuable and proprietary IPs? Has IT been receptive to cloud based management and collaboration? Have engineering teams been able to share files effortlessly?

0 Likes
Accepted solutions (1)
5,620 Views
13 Replies
Replies (13)
Message 2 of 14

I_Forge_KC
Advisor
Advisor
Accepted solution

YES

 

The hardest part is getting past people's perception. We've had beaten into our brains that anything "online" is forever in the public space and we can't ever keep that stuff safe or private - but the reality of modern computing systems doesn't jive with old PSAs about MySpace.

 

 

 

This is how we (Innovation Forge) position it when the conversation arises...

 

Locks keep honest people honest: Data theft cannot be prevented. If a "hacker" is dead set on gaining information, they will do it. Whether you are running a closed ecosystem (e.g. Vault) or a cloud data tool, your information is protected to the same degree. The vast majority of IP theft occurs not by malicious 3rd parties, but by poor behavioral practices by employees. There is a greater chance of social engineering that results in unwittingly handing your data over than some forcible attack. The same can be said for upset employees who outright steal and leave the company.

 

Obfuscation/Encryption: Data that lives in a Vault is obfuscated. The data itself is largely useless without the database to correctly piece the information back together. Furthermore, the system can be encrypted to further prevent unauthorized access. Cloud based systems employ the exact same techniques but also include end-to-end transmission encryption as well (so someone with a packet sniffer would be very hard pressed to do much of anything with what they intercept).

 

Your data has lived on the cloud for years anyway: Your personal financial and health records have lived in cloudland for a long time. Odds are your company uses Outlook 365 or IBM SmartCloud for your email... so all of that "sensitive business information" is living out there already. Even if you had an old Exchange or Domino server, you still have a webmail hook that is accessible from outside. While you certainly hear of nefarious plots to steal these types of information - the reality is that those heists typically can't be stopped anyway (see point number 1).

 

Data center employees don't want your stuff: Yes, a data center admin has both physical and virtual access to your data... but they don't want it! They manage thousands of customers' data and have a hard enough time managing the infrastructure to keep things afloat. There is no Amazon employee somewhere just browsing their servers for gold nuggets of IP to sell off. They would need to know very specific information about how and where data is stored to retrieve it - and due to that previously mentioned obfuscation, they would have to spend forever just trying to find all the associated data that goes with something.

 

 

 

I'm not suggesting we put our nuclear secrets on the cloud. What I am suggesting is that the data integrity of the cloud is the same as the data integrity of a private network - despite a few more moving pieces. Your (and your company's) approach to data security in the modern world should be much more in-line with proper behavior and personal responsibilities over a poka-yoke nanny approach.

 

Your mileage may vary.


K. Cornett
Generative Design Consultant / Trainer

Message 3 of 14

phill_scott
Enthusiast
Enthusiast

Is anyone able to explicitly state if Fusion 360 cloud storage security conforms to or complies fully with any security standards issued by defence or government?

Message 4 of 14

brianrepp
Community Manager
Community Manager

Another good place to read up on our security practices is our Trust Center HERE.

0 Likes
Message 5 of 14

phill_scott
Enthusiast
Enthusiast
Thanks. What is Fusion LC? At least I can see that the system is qualified against a specific ISO. That would be a talking point to start with. It's a bit of an improvement over the 2015 whitepaper I found.
Message 6 of 14

Anonymous
Not applicable

Everyone has a different perception on that. Now that we have Cloud protection on our side and different cloud services, it purely depends on what type of service we take.

Message 7 of 14

Sean3073
Enthusiast
Enthusiast

In the "Autodesk Terms of Service", the one everybody signs so to speak says the following in section 2.3, first sentence. "Confidentiality of Your Content and other Confidential Information. You or Autodesk (as the Disclosing Party) may disclose Confidential Information to the other party (the Receiving Party) in connection with the Services. 

 

I don't speak lawyer but I am pretty sure it just said Autodesk as the right to disclose your stuff.

 

I am looking for validation that my "projects" and completely secure from ANY and ALL means of disclosure. A good example would be proprietary data for Boeing. I have turned down jobs because Autodesk has not fully secured every ones data or put another way I have yet to find a document that says it. 

 

If I am wrong, some one please point me in the right direction. I LOVE fusion but its starting to look like I have to learn another software for the sole reason of proprietary data and licensing. Once again, I turn to the users agreement that pretty much says Autodesk and share your stuff. Some one please tell me I am wrong. 

 

Sean

P.S. I have read the white papers on security, no mention of the only person with rights to your data  is the user or the fact Autodesk will not share your info. (Put simply)

0 Likes
Message 8 of 14

Sean3073
Enthusiast
Enthusiast

I would love an answer to your question! I second it!

0 Likes
Message 9 of 14

charegb
Community Manager
Community Manager

Hi @Sean3073 

 

I'm not a lawyer either but I am the product lead for Data and Collaboration for Fusion 360 so I hope I can answer this to your satisfaction.

The first section of the section you cite, Confidentiality, is referring only to Autodesk and you and how we might disclose confidential information to each other;  e.g Autodesk contacting you if you go over some quota or if your contract is about to run out. It’s actually not saying that Autodesk will disclose your confidential information to a third party; quite the opposite.

In other words, I can state clearly that Autodesk doesn't disclose your IP to anyone and only you own it. In our Security White Paper, we also state that product team members like myself also do not have direct access to your data, which is why we ask people to share a link or invite us to a project when troubleshooting/support is needed.

As to your question of ownership, please see Section 5 of the Terms of Use:

5. You Own Your Work

You will retain Your ownership rights to files, designs, models, data sets, images, documents or similar material created by You or Your Authorized Users and submitted or uploaded to any Offering by You or Your Authorized Users.

 

I hope that answers your questions.

 

Regards,

Bankim

Message 10 of 14

pjrmachine
Explorer
Explorer

Hello, 

Cybersecurity is becoming increasingly more important/mandatory for manufacturing industry as well as other industries.  We are working on our Cybersecurity Maturity Model Certification (CMMC) and part of those requirements are that cloud based services can certify their servers FEDRamp compliant.  I see that the Autodesk BIM 360 is part Amazon Web Services East Coast servers (AWS) but can not find any information on where the Fusion 360 data is stored and what security protocols Autodesk uses to ensure users data is secure from data breaches?  I have sent a help email with no reply.   Please let me know if you can provide additional information.  I know Autodesk takes Cybersecurity seriously but we are at a crossroads, if we can not get some confirmation of where Fusion 360 cloud data is stored and security protocols so we can satisfy the DFAR NIST or CMMC Cybersecurity requirements we will have to quit using Fusion 360. I did looked through Autodesk Trust Center and could not find the information to satisfy the compliance requirements.   Thank you for your time!

 

Message 11 of 14

jodom4
Community Manager
Community Manager
Hey
We recommend that you first familiarize yourself with the public information on this page: https://knowledge.autodesk.com/support/fusion-360/troubleshooting/caas/sfdcarticles/sfdcarticles/Aut...
 
If this documentation isn't sufficient for your needs, you're welcome to request an SEC audit or RFI on this page: https://www.autodesk.com/trust/contact-us
 
You can also pursue this information through an Autodesk Sales Representative if you have one. 


Jonathan Odom
Community Manager + Content Creator
Oregon, USA

Become an Autodesk Fusion Insider



0 Likes
Message 12 of 14

tom.malcolm
Community Visitor
Community Visitor

Hi Bankim,

Thanks for the information. Do you know if Fusion 360 files are stored in the cloud in an encrypted state? If so, is the user able to contribute an encryption key?

 

Thanks,

Tom

0 Likes
Message 13 of 14

kipp2Z8XW
Community Visitor
Community Visitor

I've read this 4-year-old white paper and it makes no mention of the current US government requirements for CMMC rev 1.0, or the new CMMC rev 2.0 that's scheduled to be in place in May, 2023.

 

I've also seen elsewhere that Fusion 360 uses AWS, and I've found where AWS mentions that can be compatible with CMMC 1.0, depending on the level (there are 5 different levels of compliance).  Unfortunately AWS does not yet make any mention of the pending CMMC 2.0, which changes everything, including going from 5 levels to only 3 levels.

 

Someone at Autodesk has to know whether or not Fusion 360 is CMMC compliant.  I just don't understand why you've not made this information publicly available?

 

Message 14 of 14

Sean3073
Enthusiast
Enthusiast

When it comes right down to it, either your DFAR NIST CMMC or not. Either your compliant with certification or not. I LOVE fusion, and all the help people offer, (community) but there comes a time when your customer, be it D.O.D., DLA, Boeing, L3 Harris on and so forth says you will be compliant, fusion has to go. I have noticed some Autodesk employees word smith in an attempt to gain confidence, and their security might be top notch, but customers don't care plain and simple. Either your certified or not. I really hope Autodesk complies to DFAR NIST and CMMC. I really do, cause as we all grow,, fusion is going to have to go.