| |
|
|
Security Solutions
Homeland Security EnterSpace
Security Suite™ for Homeland Security
Run-time security decisioning including authentication
support, coarse-to-fine-grained authorization, and federated
attribute retrieval: vertical & horizontal information
sharing on a need-to-know basis.
Homeland security is among the top priorities
of all public and quasi-public agencies; from the federal
level down to individual municipalities. The United States
finds itself in a state of war — but a war far different
than any the nation has ever faced. The current Administration
has implemented the most sweeping reorganization of the federal
government in the last half-century in response this new threat.
Common Information Sharing Method
— One prominent theme that emerges in discussing homeland
security is the need for a massive common information network
built to share and disseminate information among the many
agencies and constituencies involved. However, to be truly
effective for homeland security, the network will have to
be more than just a super network linking various public agencies;
as the greatest challenge within this network will be determining
a user’s need-to-know in a dynamic and fluid environment.
In a real-time, terrorist-prone world, the answer to the need-to-know
question changes from situation-to-situation, and second-to-second.
Even within small organizations, the administrative cost of
managing users' permissions is non-trivial. Given the user
population and number of applications/ files that must be
shared to make for effective defense our Homeland; today's
enterprise access management solutions can not provide a cost-effective,
scalable, common information sharing method. That is, until
now. Jericho Systems' EnterSpace Security Suite provides a
CLEAR and CONSISTENT method
for sharing information and data across organizations involved
in homeland security.
Every Request for a Secured Resource
Is Individually Authorized — While many solutions
exist within the access management and authorization space
for organizations with a role in homeland security, most lack
true real-time functionality. Those who need-to-know are identified
statically and saved in an access-control-list (ACL) by a
human administrator. The result is that the security model
is only as current as the ACL, leading to coarse or poorly
controlled security models and holes in the enterprise's security
posture. As user community size increases and the number of
secured resources under management continues to grow, maintenance
of ACLs becomes progressively more prohibitive.
Many organizations have responded by “batching”
updates to the ACL to minimize the volatility, but unfortunately
this means that security decisions are only as accurate as
the ACL is current. Traditional ACL driven models are inherently
out of date, in that what is being saved is the RESULT of
a security policy being applied to user-specific information.
Therefore, the ACL is only as current as the moment it was
created. The inability of this model to provide security implementations
that accurately reflect “right-now” information
has prevented enterprises from sharing with users all the
information they might have a legitimate need-to-know —
in effect; it has built walls that limit information sharing,
creating information stovepipes strewn throughout the enterprise.
The EnterSpace Security Suite makes a real-time decision for
every request to allow fine-grained, context-sensitive access
decisions that are based upon CURRENT user information and
configurable security policies. It is time to tear down the
walls between the enterprise and its users.
For Example —
A threat to the country is identified, and a very limited
time window is available in which to react. The most important
mission is to get the right information into the hands of
those who have to respond — without exposing that
information to anyone who does not need-to-know. This is
a classic problem in the intelligence and security space,
and can be extremely complex to implement. In the past,
compromises have had to be made because there was no viable
framework available to manage the “need-to-know”
permissions, especially as the Internet has drastically
increased user populations. With our software tool, access
management policies can readily be defined to analyze, based
upon the user’s attributes, whether they fit the profile
of “need-to-know”, and this analysis can be
performed in real-time, at the exact moment when the user
attempts to access a secured resource.
This provides the capability to use up to the
minute user attribute information in the access decision,
as well as contextual information about the situation itself.
For example, assume there is a bio-terrorism threat in a mall
in Atlanta. Based upon security policies that have been previously
defined, the EnterSpace Security Suite can control to a very
fine level of granularity who gets access to particular information.
Local first responder teams in the Atlanta area would be granted
access to the entire body of data required to respond and
contain the threat, while emergency services in surrounding
areas would receive a filtered preparedness notice identifying
the type of threat and required preparations. Security forces
across the country would be given a notice of the threat,
stripped of sensitive details. At each and every access request,
the requester’s need-to-know would be analyzed and taken
into account, giving the user all the information they needed,
without exposing information that would constitute a security
breach.
Security Policies Centrally and Easily
Administered; Enterprise-Wide — With Jericho
Systems, security is a function brought to the enterprise
level. Currently, security is managed on an application-by-application
basis. From the ground up, the EnterSpace Security Suite is
built for distributed administration of the security policies,
allowing the owners of the resources being managed to directly
control the policies defining access throughout the enterprise.
This is a substantial change from traditional security models,
where access controls are maintained both by the programmers
who implement the code that checks the ACL, and by the security
groups who maintain the ACLs themselves. The requirements
of the resource owners are thus at least two steps removed
from the decision, and the ability to effect change in the
security policy is frequently inhibited by programmer availability.
With our software tool, policy changes can be implemented
by the resource owners directly, in real-time, and will be
reflected upon the very next request for the secured resource.
In addition, the GUI for the management of security policies
is built for the non-technical, but business-savvy administrator.
Quickly Leverage Current Enterprise
Investments for Increased Security Functionality
— The EnterSpace Security Suite is designed to quickly
integrate with previously deployed technologies including;
identity management and authentication mechanisms.
Secure, Detailed Logs Provide Single-Point
Auditability — Each time a request is made,
the EnterSpace Security Suite writes a detailed event log
to a repository. This log contains ALL the information relevant
to the decision, including the identity of the requestor,
the resource the requestor tried to access, the version of
the policy used to determine whether to grant the request,
any/all data values used in making the decision and the resulting
decision itself. This log can be written to almost any storage
form, including WORM (Write Once, Read Many) devices for non-changeable
audit logs, or a database for handling reporting and ad-hoc
queries.
Real-Time Alarms Allow “Right-Now”
Response to Inappropriate Requests — When a
request is denied for any reason, the EnterSpace Security
Suite provides a mechanism whereby an alarm condition may
be delivered to a system responsible for notifying individuals
or components to respond to the event. For example, assume
an employee is attempting to access a secured resource that
is highly sensitive: sensitive enough that any denied request
should initiate an alarm. Within the tool’s security
policy definition process, an option is available to cause
an alarm condition to be raised upon denial. At run-time,
when the user’s access attempt is denied, the EnterSpace
Security Suite generates an alarm message which details the
user’s identity, the resource requested, and the reasons
for the denial; then delivers it to a system of your choice.
This might be an SNMP interface to an enterprise management
console, an alert to a paging system, or any other form of
electronic notification.
Collaboration — While
information has long been perceived as having value within
the business environment, the true value is actually in the
solutions that can be derived from it. And in order to do
that, information must be shared among all the people and
systems that have a part to play in bringing those solutions
to life. This collaborative process has been limited severely
in the past by the inability to share information freely among
the participants while maintaining security of the data itself.
Like water in a lake, your data has enormous potential. The
water realizes that potential when it is put into motion to
create energy. By enabling the sharing of information securely,
the EnterSpace Security Suite helps put your data
into motion to create business value.
TO SUMMARIZE: With the EnterSpace Security
Suite, Organizations Involved in Homeland Security Gain Numerous
Solutions; Including:
- Real-Time Access Management with
Sensitivity to the Decision Context — As
every request for access causes the evaluation of the appropriate
security policy against user and situational attributes;
fluid conditions like Homeland Security Threat Status, time-of-day,
strength of authentication, duty-time, etc., can be factored
into access management polices.
- Create, Modify and Implement Enterprise
Security Policies in Seconds — Security policies
are managed by a common infrastructure and immediately affect
the entire user community.
- Consistent Security Policy Evaluation,
Enterprise-Wide — For secured resources under
management by the software tool, the human element is eliminated
from the evaluation process to improve security and reduce
administrative costs.
- Distribute Security Policy Administration
to Subject-Matter-Experts — Whoever owns
the resource (application, function within an application,
physical door, etc.) can administer the security policy
for the resource without the need of software engineers.
- Flexible and Scaleable —
While the EnterSpace Security Suite is built to work at
the enterprise level; the tool's deployment can be limited
to areas where current security models are ineffective or
costly. This allows for quick and flexible impact. Pick
the lowest hanging fruit first; then scale as needed. Resources
that function well with existing security models can work
side-by-side with resources that make use of the Suite for
access management and authorization.
- Single Point Auditability
— A secure event log captures information about the
entire session, forming a single point for auditability
and compliance purposes.
- Generate Alarms and Alerts at the
Time of Attempted Violation — No need to
parse through log files to find security breaches.
- Web Services Security, Single-Sign-On
and Single-Sign-Out — One tool for an enterprise
solution.
- Access Portals for Information Sharing
and Collaboration — Controlled, 1-to-1 access
portals for information sharing and collaboration are quickly
enabled.
- Physical Security Management
— The tool can also be used to manage physical security
with the same consistent, rules-based infrastructure.
Homeland Security Organizations’
ROI in Jericho Systems is Derived from:
- Increased Security, Access and Next
Generation Information Sharing — through
real-time authorization deriving permissions and entitlements
at run-time.
- Decreased Costs —
through minimized administration of security; lessen the
administrative burden of security polices, access control
lists, user groups and security audits.
- Decreased Costs —
through increased productivity brought about by single-point
auditability and real-time alarms and alerts.
- Decreased Costs —
of software engineering. Externalizing security decisioning
to a callable network service can drastically reduce code
bases and thereby application development cycle times.
The EnterSpace Security Suite can perform
hundreds of thousands of authorization decisions per second,
for user communities and resources (items to be secured) in
the tens-of-millions, in a real-time, parallel scaling, fault-tolerant
environment. |
|
|