Intelligent Control for Financial Service Companies
 |
Security breaches and data theft aimed at gaining access to private
customer information, credit card data, and bank account details are on
the rise. Financial institutions must protect the confidentiality,
integrity, and availability of the systems that store this critical
information. Regulatory and
industry requirements, such as S-Ox
and PCI, also define strict standards for network availability and
security best practices – they also mandate stiff penalties for failure
or non-compliance. At the same time, customers demand 24x7 access to
their personal financial information and cannot tolerate breaches of
their data or service interruptions. |
While
policy and process are paramount to maintaining the security of this
information, financial institutions can also look for technology to
help augment these controls. Prospective solutions must be simple to
use, manage, and deploy. But they must also be scalable and
cost-effective and provide the range of functionality characteristic of
a holistic approach.
Key features of Intelligent Control of users and applications
- complete Network Admission Control (NAC) - user
authentication, role derivation, and host posture assessment to ensure
only valid users and devices enter the LAN
- improved application performance - Layer 7
identification, prioritization, and treatment of applications to
protect assets and put business needs first
- complete user control - identity- and role-based policies to control access to applications and other resources
- faster troubleshooting - username, device, application, and resource tied together to accelerate incident response
- simplified
compliance and audit trail - full documentation of all policies, as
well as all LAN activities, tied to username and resource to speed
audits
Key projects ConSentry can help address
- Control access to resources that store customer records and credit card data for PCI compliance
- Protect wired and wireless LAN from unauthorized access
- Segment employee access to sensitive servers and applications
- Enable guest Internet access without compromising other corporate LAN resources
- Ensure only compliant devices get on the LAN, with host posture check
|