20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT...
Transcript of 20120715 - WBX PPT Master II (3) · 2017. 1. 23. · Microsoft PowerPoint - 20120715 - WBX PPT...
Whitebox SecurityIntelligent Access Governance
What Is Access Governance?
“..Enabling the business view of access governance by bridging
the gap between the IT steps required to deliver it.”
Who has access to what?
Who reviewed and approved what?
Who did what? (When, where and how)
Who should have access to what?
Whitebox Security 2012 © All Rights Reserved. 2
Why Should You Care?
BUSINESSLocate sensitive data. Identify & assign owners. Get usage visibility. Manage risk.
SECURITYClassify data. Create access policies. Monitor Activities. Detect usage anomalies.
OPERATIONSAutomate access management efforts. Remove stale resources. Be effective.
COMPLIANCEMange controls. Certify access to data and applications. Automate access requests.
Whitebox Security 2012 © All Rights Reserved. 3
Who Is Whitebox Security?
•Founded 2007, Pioneered Intelligent Access
Governance, award winning innovator.
•Backed by the European EuroStars™ program.
•Based in Tel Aviv with strong presence in EMEA & APAC markets.
•Fast growing, 50+ customers, 250% yearly growth.
Whitebox Security 2012 © All Rights Reserved. 4
Featured Customers
Whitebox Security 2012 © All Rights Reserved.
Access
Data
ERP
Solution Overview
Whitebox Security 2012 © All Rights Reserved. 6
WhiteOPS™Intelligence Engine
Impact Analysis
Role Analytics
Entitlement
Identity Monitoring
Activity Monitoring
Policy Compliance
Application Compliance
Segregation of Duties
Unified Access Policies
Business Impact
Operational Impact
Risk Management
Cross-System
Pattern Discovery
Policy Enrichment
Usage Analysis
Lifecycle
Reviews
Business Transactions
Data Access
Unified Access
The WhiteOPS™ Architecture
Applications ERP ( SAP /
ORACLE )
UDG – NAS
Storage
Security
Systems
Whitebox Security 2012 © All Rights Reserved. 7
WhiteOPS™
BA
MB
AM
WP
CW
PC
What Is Intelligent Access Governance?
Whitebox Security 2012 © All Rights Reserved. 8
“Personnel involved in access approval, certification and remediation will find an
intelligence gathering and reporting tool such as WhiteOPS™ useful.”
Earl Perkins, 2012 Cool Vendors In Security Report, Gartner
Data Classification
Owner Identification
Usage Profiling
Unified Access Policies
Access Certification
Request Automation
Activity Monitoring
Identity Monitoring
Data Enrichment
Case Study: Data Governance Global Airline
7K Users
EMC2
Celerra
Business Owners
4.5 Months
EL-AL, global airline, required to meet SoX and PCI compliance.
"Resource utilization and permission management became an
impossible goal to achieve not to mention access governance”
The 4.5 months project included data classification, business
owners detection and automated access certification.
11 Data Owners have now complete control over their data.
310,000 excess privileges (38%) removed during the project.
Whitebox Security 2012 © All Rights Reserved. 9
Case Study: ERP Governance Public
Company (NYSE)
6 Months
SoD Controls
E&Y
100% Compliance
Retalix (NASDAQ:RTLX), leader in Point Of Sale solutions, provider
of end-to-end solutions to world class retailers (Tesco, etc.)
Oracle eBS is at the heart of core business processes.
E&Y led the SoX compliance project on WhiteOPS™ platform.
After Six months, Retalix successfully passed the SoX audit.
Deliverables: SoD, Controls Automation and Activity Monitoring.
Whitebox Security 2012 © All Rights Reserved. 10
Case Study: Access Governance Global Bank,
6 Months
5,000 Users
Access Certification
500 Application
0.5M Privileges Removed
Regulatory driven access certification across 500 applications.
Project included COTS and home grown banking applications.
End User: The bank’s remote branches managers.
The project was completed on time and on budget.
500,000 excess privileges (22%) removed during phase I.
Whitebox Security 2012 © All Rights Reserved. 11
Where To Now?
(Unstructured) Data Governance Solution In-Depth
Access Governance Solution In-Depth
ERP Governance Solution In-Depth
Demo!
Q&A
Whitebox Security 2012 © All Rights Reserved. 12