20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT...

13
Whitebox Security Intelligent Access Governance

Transcript of 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT...

Page 1: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Whitebox SecurityIntelligent Access Governance

Page 2: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

What Is Access Governance?

“..Enabling the business view of access governance by bridging

the gap between the IT steps required to deliver it.”

Who has access to what?

Who reviewed and approved what?

Who did what? (When, where and how)

Who should have access to what?

Whitebox Security 2012 © All Rights Reserved. 2

Page 3: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Why Should You Care?

BUSINESSLocate sensitive data. Identify & assign owners. Get usage visibility. Manage risk.

SECURITYClassify data. Create access policies. Monitor Activities. Detect usage anomalies.

OPERATIONSAutomate access management efforts. Remove stale resources. Be effective.

COMPLIANCEMange controls. Certify access to data and applications. Automate access requests.

Whitebox Security 2012 © All Rights Reserved. 3

Page 4: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Who Is Whitebox Security?

•Founded 2007, Pioneered Intelligent Access

Governance, award winning innovator.

•Backed by the European EuroStars™ program.

•Based in Tel Aviv with strong presence in EMEA & APAC markets.

•Fast growing, 50+ customers, 250% yearly growth.

Whitebox Security 2012 © All Rights Reserved. 4

Page 5: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Featured Customers

Whitebox Security 2012 © All Rights Reserved.

Access

Data

ERP

Page 6: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Solution Overview

Whitebox Security 2012 © All Rights Reserved. 6

WhiteOPS™Intelligence Engine

Impact Analysis

Role Analytics

Entitlement

Identity Monitoring

Activity Monitoring

Policy Compliance

Application Compliance

Segregation of Duties

Unified Access Policies

Business Impact

Operational Impact

Risk Management

Cross-System

Pattern Discovery

Policy Enrichment

Usage Analysis

Lifecycle

Reviews

Business Transactions

Data Access

Unified Access

Page 7: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

The WhiteOPS™ Architecture

Applications ERP ( SAP /

ORACLE )

UDG – NAS

Storage

Security

Systems

Whitebox Security 2012 © All Rights Reserved. 7

WhiteOPS™

BA

MB

AM

WP

CW

PC

Page 8: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

What Is Intelligent Access Governance?

Whitebox Security 2012 © All Rights Reserved. 8

“Personnel involved in access approval, certification and remediation will find an

intelligence gathering and reporting tool such as WhiteOPS™ useful.”

Earl Perkins, 2012 Cool Vendors In Security Report, Gartner

Data Classification

Owner Identification

Usage Profiling

Unified Access Policies

Access Certification

Request Automation

Activity Monitoring

Identity Monitoring

Data Enrichment

Page 9: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Case Study: Data Governance Global Airline

7K Users

EMC2

Celerra

Business Owners

4.5 Months

EL-AL, global airline, required to meet SoX and PCI compliance.

"Resource utilization and permission management became an

impossible goal to achieve not to mention access governance”

The 4.5 months project included data classification, business

owners detection and automated access certification.

11 Data Owners have now complete control over their data.

310,000 excess privileges (38%) removed during the project.

Whitebox Security 2012 © All Rights Reserved. 9

Page 10: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Case Study: ERP Governance Public

Company (NYSE)

6 Months

SoD Controls

E&Y

100% Compliance

Retalix (NASDAQ:RTLX), leader in Point Of Sale solutions, provider

of end-to-end solutions to world class retailers (Tesco, etc.)

Oracle eBS is at the heart of core business processes.

E&Y led the SoX compliance project on WhiteOPS™ platform.

After Six months, Retalix successfully passed the SoX audit.

Deliverables: SoD, Controls Automation and Activity Monitoring.

Whitebox Security 2012 © All Rights Reserved. 10

Page 11: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Case Study: Access Governance Global Bank,

6 Months

5,000 Users

Access Certification

500 Application

0.5M Privileges Removed

Regulatory driven access certification across 500 applications.

Project included COTS and home grown banking applications.

End User: The bank’s remote branches managers.

The project was completed on time and on budget.

500,000 excess privileges (22%) removed during phase I.

Whitebox Security 2012 © All Rights Reserved. 11

Page 12: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...

Where To Now?

(Unstructured) Data Governance Solution In-Depth

Access Governance Solution In-Depth

ERP Governance Solution In-Depth

Demo!

Q&A

Whitebox Security 2012 © All Rights Reserved. 12

Page 13: 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT Master II (3).pptx Author: tparisio Created Date: 5/2/2013 5:19:28 PM ...