Search This Blog

Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts

Thursday, August 16, 2012

CA Technologies Adds Aspera Software License Management to its Service Management Portfolio


Press Releases

CA Technologies Adds Aspera Software License Management to its Service Management Portfolio

OEM Agreement Helps Customers Address Complexities of Software Licensing and Mitigate Audit Risk
ISLANDIA, NY and AACHEN, Germany—August 16, 2012—CA Technologies (NASDAQ: CA) and Aspera GmbH (“Aspera”), a wholly-owned subsidiary of USU Software AG (“USU”), today announced an OEM agreement under which CA Technologies will embed Aspera’s industry-leading SmartTrack license management technology in its industry-leading CA IT Asset Manager software.

CA IT Asset Manager helps organizations reduce the risk of license compliance and optimize the cost, management and distribution of existing assets.
Findings from the latest annual survey conducted at Gartner's IT Financial, Procurement and Asset Management Summit again show higher numbers of audits year over year.  In the same research note, Gartner recommends that “CIOs should invest the funds needed to ensure that robust asset management is in place and effective, and that asset management staff are empowered to ensure compliance."
Software license agreements with vendors can also be highly complex, making it difficult for customers to get maximum business value from them while also rigorously maintaining compliance with licensing terms.
According to Gartner analyst Patricia Adams, “Correlating license entitlement with installed software is not an easy task.  Therefore, vendors specializing in software license optimization are emerging to address this market niche.”**
“Aspera lives and breathes software license management,” said Christof Beaupoil, president of Aspera Technologies Inc., the U.S.-based sister company of Aspera GmbH. “By providing CA Technologies with both our technology and expertise, Aspera can help CA Technologies customers more quickly and easily achieve their efficiency and compliance goals.”
Aspera’s software license management technology complements the broader CA Technologies Service Management solutions portfolio, which addresses all aspects of software, hardware and network resource ownership on-premise and in the cloud—along with associated IT operations.
Aspera also delivers its technology as a cloud-based service, which aligns well with the CA Technologies IT Management-as-a-Service (ITMaas) strategy.
"IT organizations are under intense pressure to get the most out of every dollar of IT spend, even as their environments are becoming increasingly complex," said Lokesh Jindal, senior vice president, Service and Portfolio Management, CA Technologies.  "Our relationship with Aspera will help our customers worldwide fulfill this core objective by empowering them to improve utilization of all the assets that support their service delivery."
*Gartner, Inc., Software Vendor Auditing Trends: What to Watch For and How To Respond by Jane B. Disbrow, Alexa Bona, Frances O’Brien, Frank DeSalvo, Ted Friedman, Jo Ann Rosenberger, Joseph Neapolitan, Victoria Barber, Stewart Buchanan, May 23, 2012
**Gartner, Inc., Software License Optimization Vendor Overview by Patricia Adams, July 3, 2012
About Aspera
Aspera is a highly specialized provider of software license management solutions. Our unique, entitlement-centric approach has been successfully implemented in international projects for over a decade. SmartTrack is the tool of choice for large companies wishing to effectively manage software assets governed by significant volume license agreements. More than 130 world class businesses – including 20 Fortune Global 500 companies – rely on Aspera’s expertise for license management. Aspera has partners in Scandinavia, Germany, Netherlands, the UK, and Australia.
Following the industry standard ISO/IEC 19770-1 our services include but are not limited to: LaaS, software recognition engineeringlicense clearinginterface monitoring, and application troubleshootingmaster catalogextended catalog, ITIL certified organization and process consulting, project management, integration, and customer support.
Aspera was founded in 2000 in Aachen, Germany and currently employs 65 professionals. It is registered in the USA under Aspera Technologies Inc. Aspera GmbH and Aspera Technologies Inc. are wholly owned subsidiaries of USU Software AG. More information is available at www.aspera.com.
About CA Technologies
CA Technologies (NASDAQ: CA) provides IT management solutions that help customers manage and secure complex IT environments to support agile business services. Organizations leverage CA Technologies software and SaaS solutions to accelerate innovation, transform infrastructure and secure data and identities, from the data center to the cloud. Learn more about CA Technologies at www.ca.com.

Sunday, August 12, 2012

Teaming Gmail, Google Search Not Security Risk

http://www.pcworld.com/article/260739/teaming_gmail_google_search_not_security_risk.html#tk.nl_bdx_h_crawl

Tuesday, March 27, 2012

Nikon Corporation Takes Control of eDiscovery Process with Symantec’s Clearwell eDiscovery Platform

Nikon Corporation Takes Control of eDiscovery Process with Symantec’s Clearwell eDiscovery Platform


MOUNTAIN VIEW, Calif. – Mar. 26, 2012 – Symantec Corp. (Nasdaq: SYMC) today announced that Nikon Corp (TYO: 7731), the leading Japanese manufacturer of optical instruments, has chosen Symantec’s Clearwell eDiscovery Platform for in-house eDiscovery. Nikon is leveraging Symantec’s flexible, cross-border solution to perform early case assessments and first-pass review in order to mitigate risk and reduce the overall costs of eDiscovery. With Symantec’s Clearwell eDiscovery Platform, Nikon is able to rapidly and accurately filter, process, search and analyze data in multiple formats and languages.

Click to Tweet: Nikon Corp Takes Control of #eDiscovery Process with @Symantec’s @Clearwell eDiscovery Platform: http://bit.ly/w5qrJ6

“Using Symantec’s Clearwell product in-house allows us to dramatically decrease costs associated with early case assessments,” said Takuya Shirahata, executive staff, 1st section, 2nd intellectual property department, Nikon Corporation. “Processing and analyzing the increasing volume of data for our case is a huge undertaking, but with the help of Symantec’s Clearwell eDiscovery Platform we are able to process the data in a matter of days. The product’s easy to use interface, double-byte support and transparent search capabilities provide our legal team with quick and continuous visibility into case facts, which allows us to meet appointed deadlines and stay within budget.”

Japanese customers continue to select Symantec’s Clearwell eDiscovery Platform for the product’s battle-tested technology and features that provide critical capabilities such as robust support for double-byte and Japanese encodings. In addition, the product provides the flexibility necessary for cross-border eDiscovery cases typically faced by Japanese customers, where litigation often demands multi-jurisdictional support and requires data to be processed in Japan and other countries such as the United States. For instance, Symantec’s Clearwell eDiscovery Platform can be deployed on a hosted basis or onsite, which allows eDiscovery to be conducted in Japan without having to send data to the U.S. for processing. This enables customers like Nikon to maintain control over potentially sensitive data and avail themselves of business hour support in-country.

“The global impact of litigation is leading corporations around the world to closely evaluate their eDiscovery strategies and take greater control of escalating costs,” said Trevor Eddy, senior director, Information Intelligence Group, Symantec Corp. “Through extensive research and development, Symantec’s Clearwell eDiscovery Platform has been built to meet the unique eDiscovery needs of our Japanese customers. By bringing eDiscovery in-house, Nikon is able to leverage Symantec’s innovative technology to better manage the eDiscovery process and simultaneously reduce costs.”

Related
Connect with Symantec
About Symantec
Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.

Friday, March 23, 2012

Why Hackers Set Their Sights on Small Business


If you run a small business, and think that none of your data was of interest to a hacker, consider this: what if a hacker could take stolen bank account or credit card information from your computer and package it with the same information from a hundred or a thousand other small businesses? Would it be worth something then?
"SMBs don't know how defenseless they've become, especially to automated and industrialized attack methodologies by organized crime," Christopher Porter tells PCWorld. Porter, a principal with the Verizon RISK Team, is the author of a new report from Verizon on security risk.
"[Hackers] scan the Internet, looking for remote access services, and then try the default credentials. Once they gain access, they automatically install keyloggers to collect password information [as it's typed in]," Porter says. "Then they send the information it out via e-mail or by uploading it to an FTP server or a web site. They aggregate the data and sell it on the black market."
Hackers could use the keylogger to figure out how access and drain a small business' bank account, but more commonly, Porter said, they'll target point-of-sale systems, as four Romanians did recently. "That kind of attack is increasing, because they're low-risk and low-cost attacks for organized crime." Because they're geographically widespread, it's hard for any one police department to follow up.
For more, click the link below: 


http://www.pcworld.com/businesscenter/article/252302/why_hackers_set_their_sights_on_small_businesses.html#tk.nl_bdx_h_crawl

Wednesday, March 21, 2012

ACI Worldwide Named a Leader in IDC Marketscape: Financial Crimes Management 2012 Vendor Assessment


ACI Worldwide Named a Leader in IDC MarketScape: Financial Crimes Management 2012 Vendor Assessment

Proactive Risk Manager™ Recognized for Real-Time Pattern Recognition Abilities, Customizable Alerts, and Reporting Options
Wednesday, March 21, 2012
ACI’s ranking is based on its flagship fraud detection product, Proactive Risk Manager. IDC Financial Insights stated, “Proactive Risk Manager's greatest strength is its integration with ACI's other payment products, particularly its BASE24-eps card processing system and its MTS wire and ACH systems. This integration enables Proactive Risk Manager to operate almost entirely in real time. Real-time alerting and decisioning continues to be a primary selling point, reflecting the product's roots in the card market.”
Shesh Gorur, vice president & product line manager, ACI Worldwide, said, “We are delighted to be recognized as a Leader by IDC in this report. Our goal is to provide a product that is both flexible and powerful, supporting our customers’ current needs while allowing them to react to the evolving world of payments fraud.”
As defined by the report, financial crime management includes the IT solutions that anticipate, detect, analyze, and prevent fraudulent transactions, money laundering, and employee financial misconduct through the use of one or more of the following: decision trees, neural networks, predictive scoring models, network link analysis, scenario matching, data mining, case management, and entity and device profiling.
Proactive Risk Manager is a comprehensive enterprise fraud detection solution to help card issuers, merchants, acquirers and financial institutions combat financial crime. By monitoring account activity across all lines of business, Proactive Risk Manager enables users to see more fraudulent activity in a shorter amount of time, minimizing losses and helping to preserve the customer relationship. Proactive Risk Manager combines the power of predictive analytics and expertly defined rules for fast, accurate and flexible response to the evolving and growing nature of fraud and money laundering.

For more information on Proactive Risk Manager please visitwww.aciworldwide.com/proactiveriskmanager.

Tuesday, March 20, 2012

Motorcycle Superstore Revs Its Engines w/ Accertify Chargeback Mgt. Solution

Motorcycle Superstore Revs Its Engines with Accertify Chargeback Management SolutionAccertify Drives Significant Lift in Win Rates; Dramatically Simplifies Disputes Process
CHICAGO, IL,  March 20, 2012 -- 
Accertify, a leading fraud prevention and risk management provider, and Motorcycle Superstore, the leading online motorcycle outfitter, today shared strong results of Motorcycle Superstore's deployment of Accertify's Chargeback Management Solution. This solution achieved an overall lift in chargeback win rates of 62% for Motorcycle Superstore, and also cut the number of steps involved in the resolutions process in half.
"When comparing the win rates of our chargeback disputes before and after engaging Accertify, we saw a 62% lift in performance," stated Jason Miller, Chief Technology Officer of Motorcycle Superstore. "Not only did we drive revenue and improve cash flow as a result, but this intuitive and automated solution also simplified every step of the chargeback process across all of the major card brands and processors – ultimately reducing by half the number of steps involved."
"Chargebacks present one of the biggest challenges for merchants to manage and a real threat to the bottom line," said Jeff Liesendahl, President of Accertify. "In addition to the potential direct cost, hidden expenses such as bank fees, manual efforts, product losses, and lost delivery and fulfilment delays can all have an extremely negative impact on a business. Our Chargeback Management solution simplifies this process, automatically addressing card brand and processor requirements to save our clients time, win more chargebacks, and increase top line revenue."
An industry first when launched in 2011, Accertify's Chargeback Management product is a comprehensive solution that automates all aspects of the chargeback management process from review and analysis to representment and reporting. Accertify's technology takes the hassle out of managing chargebacks and helps merchants save time, reduce manual efforts, and boost revenue recovery. Also available as a standalone product, Motorcycle Superstore chose to leverage the Chargeback Management Solution as a fully-integrated component of Accertify's data management platform, which provides them with extensive fraud fighting capabilities as well.
To request a demonstration or learn more about Accertify's Chargeback Management Solution or any other of the company's risk management products or services, pleaseContact Us at www.accertify.com.
About Accertify
Accertify Inc., a wholly owned subsidiary of American Express, based in Itasca, IL, is a leader in providing e-commerce companies with hosted software solutions, tools and strategies for preventing online fraud and mitigating enterprise-wide risks. Its Interceptas® platform integrates the various components of fraud prevention, applies state-of-the-art automation to each step in process and offers advanced capabilities for managing fraud data. Built with a merchant's perspective, Interceptas delivers flexibility in preventing fraud related to card-not-present purchases, online scams and policy abuse, merchandise returns and exchanges and other data management challenges. Accertify is committed to providing online companies with the most cost-effective solution to fraud available. For more information, visit www.accertify.com.

Monday, March 12, 2012

News Release from Symantec - Runaway Data Growth

Symantec Helps Organizations Get Control of Runaway Data Growth

Data Insight 3.0 Creates Accountability for Unstructured Information Governance
Share on Facebook Tweet
MOUNTAIN VIEW, Calif. – March 12, 2012 – Symantec Corp. (Nasdaq: SYMC) today announced Symantec Data Insight 3.0, the latest version of its solution that improves information governance by providing intelligence into ownership and usage of unstructured data such as documents, presentations, spreadsheets and emails. Enhancements to Symantec Data Insight help organizations transform storage operations and simplify information governance processes to reduce costs, reduce risk and achieve compliance.

Read more detailed blog posts:
According to Gartner, the growth rate of data is 40 to 60 percent; but for unstructured data in the enterprise, the growth rate can be up to 80 percent¹ and is becoming increasingly difficult to manage and protect. IT organizations are faced with seemingly impossible data governance objectives to reduce costs, reduce risk and achieve compliance. IT lacks the business context for the data and must engage the data owners who best understand the value of the data. However, challenges in understanding who owns the data and how it is being used impact IT’s ability to operationalize data governance.

Symantec Data Insight addresses these challenges by continuously monitoring data usage and enabling rule-based inferences for data ownership. Understanding how data is being used enables effective unstructured data management operations – facilitating tasks such as reclamation and chargeback. By assigning data ownership, IT organizations can establish a framework for collaboration with the business to address data governance objectives. Since the initial launch, Symantec has seen broad adoption and use of Data Insight to reduce storage costs, simplify protection of critical data, and meet compliance.

Click to Tweet: Symantec Helps Organizations Get Control of Runaway Data Growth with Data Insight 3.0: http://bit.ly/AoQIh8

Transform Storage Operations
Symantec Data Insight’s detailed data usage analytics of unstructured data, such as growth, frequency of access, inactive data, and user activity are essential to reducing storage costs and streamlining unstructured data storage operations such as reclamation, tiering, migration to cloud storage and capacity planning. Rapid growth of unstructured data and the emergence of Big Data are significantly increasing the magnitude of the operations challenge. Data Insight is particularly well-suited to support large-scale data management operations with its highly scalable and parallel architecture. With optimizations in collection, indexing and query algorithms, Data Insight delivers actionable analytics with enhanced performance across large data sets.

Empower the Business
Symantec Data Insight helps storage, security and compliance professionals empower the data owners inside the business to better manage and protect unstructured data through a new data custodian management feature.

  • Data Custodian Management: Data Insight helps automate the discovery and management of custodians for unstructured data within the business. IT can automatically engage the business owners or custodians with valuable usage, permissions, and classification reporting and analytics, empowering the business to become better stewards of an organization’s resources.
  • Managing Data Growth: Data Insight automates custodian reviews of inactive or orphan data facilitating storage remediation actions, such as deletion, archival, or migration as well as assisting with data retention guidelines based on data ownership classification. Data Insight’s ownership and usage capabilities help organizations build a consumption-based chargeback model to promote accountability for efficient use of the storage.
  • Protecting Confidential Data: Symantec continues to strengthen the integration between Symantec Data Insight and Symantec Data Loss Prevention. Features such as risk scoring and sensitive data alerts, combine Data Loss Prevention’s content-awareness with Data Insight’s usage and permissions analysis to help prioritize remediation of data based on risk. Data Insight’s custodian management feature will streamline the risk remediation process, especially important given the rapid growth of unstructured data.
  • Governing Access to Data: Through Data Insight’s integration with the Aveksa Access Governance suite, organizations can easily establish business processes to control who can access key data resources across the enterprise. By incorporating the ownership and access information discovered by Symantec’s Data Insight into the Aveksa system, organizations can more easily and efficiently achieve compliance and better enforce access policies.
Comprehensive Coverage
Data Insight 3.0 now features a new integration point with Veritas Storage Foundation 6.0. Customers using Storage Foundation for file serving can now leverage Data Insight for their data management needs. Data Insight also features enhanced operations for NetApp network attached storage (NAS) and expanded coverage to support both CIFS and NFS protocols.

Data Insight provides comprehensive support for leading platforms such as NetApp NAS, EMC NAS, Windows File Servers, Microsoft SharePoint, and Unix File Servers with Veritas Storage Foundation file system. Data Insight also provides support for leading directory services, such as Microsoft Active Directory, LDAP, and NIS/NIS+.

Quotes
  • “Data Insight has given us a better understanding of how unstructured data is being created, used, stored, and retained,” said Starla Rivers, Sr. Information Security Architect, Sharp HealthCare. “With the integration between Data Insight and Symantec’s Data Loss Prevention solution, we are able to identify and manage data by content, access, age and risk. This allows us to work with the business custodians to protect that data through tighter access controls and a clean-up process. This is helping us with our data governance objectives of gaining efficiency and reducing risk.”
  • “NetApp and Symantec are committed to delivering innovative solutions that help our mutual customers employ new strategies to manage, retain and protect growing data volumes,” said Chris Cummings, vice president, products and solutions marketing, NetApp. “The combined strengths of Symantec Data Insight integrated with NetApp’s high performance storage systems enables organizations to better understand who owns information, how it’s being accessed, and how it’s being used to accelerate the business. This in-depth understanding helps customers efficiently manage data growth, make better decisions and drive successful business outcomes at the speed of today’s business.”
  • “Data Insight provides visibility into the who and how as context to 'eating the elephant.’ Our enterprise customers large and small find the task of classifying information somewhat insurmountable based upon volume, complexity, and lack of visibility,” said Marc Johnson, Practice Director for Data Center Management and Storage, Creative Breakthroughs, Inc. “Data Insight’s ownership and usage analytics help organizations link security, storage, and compliance in an unprecedented way. Never before have the walls crumbled between IT security and IT storage the way that Data Insight incites.”
  • “With Symantec Data Insight and Aveksa integrated together, organizations can safely and efficiently delegate access decisions to the line-of-business custodians, while ensuring compliance with controls and constraints defined by Information Security,” said Deepak Taneja, CTO at Aveksa. “Symantec Data Insight provides information on data resource ownership, classification and usage, and Aveksa leverages this to provide business-user-friendly access activities, including certification, access request, and access remediation. The end result is a full lifecycle management system for controlling enterprise access to applications and data. ”
  • “Data Insight demonstrates innovation and integration across Symantec’s security and storage portfolio,” said Vivian Tero, Program Director for Governance, Risk and Compliance, IDC. “Data Insight’s data ownership and usage analysis benefits both storage and security stakeholders, by enabling efficient management of data growth to reduce cost and simplifying protection of sensitive data, regardless of where it is stored.”
  • “It is difficult for most organizations to identify the data owners for a majority of the unstructured data in their organization,” said Don Angspatt, vice president, product management, Storage and Availability Management Group, Symantec Corp. “Data Insight 3.0 enables our customers to not only identify data owners but also automatically engage them to reduce storage management costs, achieve compliance, and facilitate data protection, thereby increasing the effectiveness of an organization’s data governance initiatives.”
Pricing and Availability
Data Insight is available immediately. Estimated pricing starts at $5,000 USD with either a per-User or per-TB licensing option.

Connect with Symantec
About Storage and Availability Management from Symantec
Symantec helps organizations secure and manage their information-driven world with storage managementhigh availability/disaster recovery,email archiving, and backup & recovery solutions.

About Symantec
Symantec is a global leader in providing security, storage and systems management solutions to help consumers and organizations secure and manage their information-driven world. Our software and services protect against more risks at more points, more completely and efficiently, enabling confidence wherever information is used or stored. More information is available at www.symantec.com.

Tuesday, February 28, 2012

News Release from CA Technologies - Security for MS SharePoint

CA Technologies Extends Content-Aware Identity and Access Management, Delivers Security Solution for Microsoft SharePoint

Company Enhances CA SiteMinder, CA DataMinder to Drive Next-Generation IAM and Improved Information Security, Risk Management
SAN FRANCISO, February 27, 2012, - RSA Conference – CA Technologies (CA: NASDAQ) today announced advancements to further build-out its Content-Aware Identity and Access management (IAM) vision and deliver a security solution for Microsoft® SharePoint® to help improve information security, reduce risk and meet compliance mandates.
Traditional IAM stops at the point of access. CA Technologies Content-Aware IAM vision, a next-generation approach, takes IAM a step further to help control users, their access and how they handle information. This innovative approach helps organizations protect critical information from inappropriate use or disclosure.
“Balancing business productivity and enablement with security and data protection is one of the top priorities for the Chief Security Officer. This is made more difficult by today’s collaborative environments that include extended teams from within and outside an organization,” said Mike Denning, general manager, Security, CA Technologies. “For example, there are more than 65,000 Microsoft SharePoint customers, which equates to a lot of users accessing a lot of data. The challenge is to make sure the right users access the right data and handle it in the right way, which requires a layered security approach that includes Content-Aware Identity and Access Management from CA Technologies.”
To help address these challenges, CA Technologies is adding capabilities and integrating new releases of CA SiteMinder® and CA DataMinder™ (formerly CA DLP), to deliver a Content-Aware security solution and help organizations protect the information stored, accessed and used in the Microsoft SharePoint environment. The CA SiteMinder and CA DataMinder updates, and resulting solution for SharePoint, will be available in March.
“Organizations are challenged with unknown Personally Identifiable Information (PII) that exists within documents residing across the enterprise,” said Jeremy Britton, director, security & privacy services, Deloitte & Touche LLP. “The ability to identify and classify potential data risks in content, and control access based on the levels of risk, allows organizations to more effectively manage regulatory compliance and protection of sensitive data.”
CA Technologies Solution for Microsoft SharePoint
As organizations expand their use of Microsoft SharePoint, they may face accelerated growth of siloed SharePoint instances, the proliferation of sensitive data across the SharePoint environment and increased compliance mandates.
CA DataMinder includes CA DataMinder™ Classification, which dynamically scans, locates and classifies sensitive content stored within Microsoft SharePoint, including intellectual property, financial information and PII such as social security numbers, credit card numbers and other employee relevant data. CA SiteMinder 12.5 will be enhanced to use the content classification information from CA DataMinder as input for access policies to more precisely determine whether a user should be granted access to a document. This combination will provide more fine-grained and better defined access control, helping to improve the security of data without hampering productivity.
CA Technologies security solution for Microsoft SharePoint will provide the following capabilities:
• Convenient authentication through CA SiteMinder single sign-on, authentication, authorization and auditing;
• Content-aware access management with automatic data discovery, classification and content-aware access control; and
• Information lifecycle control for SharePoint data from creation, storage, access, distribution and disposal.
“We have supported many implementations for IAM systems – all improving security postures for those customers. A next-generation IAM approach that classifies and flags documents with sensitive content and then associates identity and access policies with that content will further enhance information protection,” said Jason Wilcox, manager, Security Practice at YASH Technologies, a leading technologies and services outsourcing partner. “We are excited about the advancements that CA Technologies is making in the market, and look forward to working with our clients to advance the way they implement identity and access management.”
CA Technologies first delivered capability for Content-Aware IAM by associating content and data policies with identities and roles managed by CA IdentityMinder™ (formerly CA Identity Manager). This helps to better control and protect information as users and groups change within organizations. By enabling CA SiteMinder to use content classification information, data security is strengthened by adding the access element.
In addition, as organizations begin to shift from IT rationalization and optimization to deliver business service innovation and growth, CA Technologies Content-Aware IAM technologies help enable and secure organizations to achieve business outcomes such as speed, cost and risk efficiencies and improved performance. The key is to strike the balance between security and business enablement.
The CA SiteMinder 12.5 release will include a number of additional core improvements including simplified management, support for Web 2.0 / Identity 2.0 technologies and enhanced federation management. Visit the CA Security Management blog for further details on the new releases of CA SiteMinder and CA DataMinder.
CA IAM Solutions Adopt the “Minder” Brand
Building on the strong brand equity of CA SiteMinder, CA Technologies has renamed the products and solutions in its security portfolio using the “Minder” naming convention. Visit http://bit.ly/wtzJCN to see the new names.

Thursday, February 23, 2012

News Release from Symantec

Symantec Survey Reveals Significant Adoption of Enterprise Mobile Apps, IT Focuses on Balancing Benefits and Risks
 
MOUNTAIN VIEW, Calif. – Feb. 22, 2012 – Symantec Corp. (Nasdaq: SYMC) today announced the results of its 2012 State of Mobility Survey, which revealed a global tipping point in mobility adoption. The survey highlighted an uptake in mobile applications across organizations with 71 percent of enterprises at least discussing deploying custom mobile applications and one-third currently implementing or have already implemented custom mobile applications.

Despite this adoption, almost half (48 percent) of survey respondents mentioned that mobility is somewhat to extremely challenging and a further 41 percent of survey respondents identified mobile devices as one of their top three IT risks. Yet in the face of these challenges, IT is striking a balance between mobile benefits and risks by transforming its approach to mobility to deliver improved business agility, increased productivity and workforce effectiveness.

Click to Tweet: 71% of organizations are already using or planning to use custom mobile applications: http://bit.ly/xUEG5F

“We are impressed by the pace of mobile application adoption within organizations,” said CJ Desai, senior vice president, Endpoint and Mobility Group, Symantec. “This cultural change from refusing mobile devices not long ago, to actively distributing and developing mobile applications, has introduced a new set of challenges and complexities for IT staff. Encouragingly, from a security perspective, a majority of organizations are thinking beyond the simple case of lost or stolen mobile phones.”

The State of Mobility Survey reveals the challenges organizations are grappling with in accommodating the mobility tipping point and also identifies and quantifies mobility-associated risks as perceived by IT decision makers. In this survey, more than 6,000 organizations from 43 countries bring to light the change in the usage of mobile devices and mobile applications.

Mobile Devices Now Critical Business Tools
The significant adoption of mobile applications demonstrates remarkable confidence, by organizations, in the ability for mobility to deliver value. This confidence is further supported by a rare alignment between expectations and reality. Generally, the gains expected from new technologies far exceed the reality upon implementation. However, for the smartphones and tablets currently in use, 70 percent of those surveyed expected to see increased employee productivity, yet 77 percent actually saw productivity gains after implementing. Furthermore, 59 percent of respondents are now relying on mobile devices for line-of-business applications, another sign that mobility has graduated to mainstream status.

Mobile Initiatives Significantly Impacting IT Resources
As with the adoption of any new technology, mobility is challenging IT organizations. Almost half (48 percent) of respondents mentioned that mobility is somewhat to extremely challenging, while two thirds noted that reducing the cost and complexity is one of their top business objectives. In Symantec’s view, this increased pain level indicates the transition from small pilots and tactical implementations − where policies are often bypassed and exceptions are made − to enterprise-wide deployments where policy standards across a larger scale introduce greater complexity. This also suggests that many implementations are not yet taking sufficient advantage of their existing enterprise systems and processes, which would alleviate much of the pain and cost that comes with larger scale and resource duplication.

Mobility Risks Impacting Organizations
Mobile adoption is not without risks, and IT organizations recognize this challenge. Approximately three out of four organizations indicate maintaining a high level of security is a top business objective for mobility and 41 percent identified mobile devices as one of the top three IT risks, making it the leading risk cited by IT. Concerns are wide-ranging, from lost and stolen devices, data leakage, unauthorized access to corporate resources and the spread of malware infections from mobile devices to the company network. With mobile devices now delivering critical business processes and data, the cost of security incidents can be significant. The average annual cost of mobile incidents for enterprises, including data loss, damage to the brand, productivity loss, and loss of customer trust was USD$429,000 for enterprise. The average annual cost of mobile incidents for small businesses was USD$126,000.

Recommendations
Organizations that choose to embrace mobility, without compromising on security, are most likely to improve business processes and achieve productivity gains. To this end, organizations should consider developing a mobile strategy that defines the organization’s mobile culture and aligns with their security risk tolerance.

Some key recommendations include:
Enable broadly: Mobility offers tremendous opportunities for organizations of all sizes. Explore how you can take advantage of mobility and develop a phased approach to build an ecosystem that supports your plan. To get the most from mobile advances, plan for line-of-business mobile applications that have mainstream use. Employees will use mobile devices for business one way or another – make it on your terms.
Think strategically: Build a realistic assessment of the ultimate scale of your mobile business plan and its impact on your infrastructure. Think beyond email. Explore all of the mobile opportunities that can be introduced and understand the risks and threats that need to be mitigated. As you plan, take a cross-functional approach to securing sensitive data no matter where it might end up.
Manage efficiently: Mobile devices are legitimate endpoints that require the same attention given to traditional PCs. Many of the processes, policies, education and technologies that are leveraged for desktops and laptops are also applicable to mobile platforms. So the management of mobile devices should be integrated into the overall IT management framework and administered in the same way – ideally using compatible solutions and unified policies. This creates operational efficiencies and lowers the total cost of ownership.
Enforce Appropriately: As more employees connect their personal devices to the corporate network, organizations need to modify their acceptable usage policies to accommodate both corporate-owned and personally-owned devices. Management and security levers will need to differ based on ownership of the device and the associated controls that the organization requires. Employees will continue to add devices to the corporate network to make their jobs more efficient and enjoyable so organizations must plan for this legally, operationally and culturally.
Secure comprehensively: Look beyond basic password, wipe and application blocking policies. Focus on the information and where it is viewed, transmitted and stored. Integrating with existing data loss prevention, encryption and authentication policies will ensure consistent corporate and regulatory compliance.
Symantec’s 2012 State of Mobility Survey
Symantec’s 2012 State of Mobility Survey was conducted by Applied Research from August-November 2011. The results are based on 6,275 organizations in 43 countries in North America, EMEA (Europe, Middle East and Africa), Asia Pacific, Japan and Latin America. Among small businesses, we spoke with the person in charge of IT. Among enterprises, we contacted senior IT and C-level professionals. For the purposes of this survey, mobile devices refer to handheld devices such as the Blackberry Smartphone, iPhone, Android, iTouch and other similar devices. Laptops are not included in the definition of mobile devices.

Resources
State of Mobility Survey Report
Infographic: Enterprises At The Tipping Point In Mobile Adoption
SlideShare Presentation: State of Mobility Global Results
Mobility: Rising to the Challenge Blog
Mobility in Business Today Blog
State of Mobility Survey Press Kit
Connect with Symantec
Follow Symantec on Twitter
Join Symantec on Facebook
Subscribe to Symantec News RSS Feed
View Symantec’s SlideShare Channel
Visit Symantec Connect Business Community

Wednesday, February 8, 2012

Expansion of Passenger Pre-screening

From the Dept. of Homeland Security:


TSA Pre✓™ Pilot to Expand to Busiest US Airports

Release Date: February 8, 2012
For Immediate Release
Office of the Press Secretary
Contact: 202-282-8010

WASHINGTON – Department of Homeland Security (DHS) Secretary Janet Napolitano and Transportation Security Administration (TSA) Administrator John S. Pistole today announced the expansion of TSA Pre√™, a passenger pre-screening initiative, to additional airports across the country following the program’s success at seven pilot locations.

With more than 336,000 passengers screened to date through TSA Preê lanes, this screening concept enhances security by enabling TSA to focus its efforts on passengers the agency knows less about while providing expedited screening for travelers who volunteer information about themselves prior to flying.

“TSA Pre√™ moves us closer to our goal of delivering the most effective and efficient screening by recognizing that most passengers do not pose a threat to security,” said TSA Administrator John S. Pistole. “We are pleased to expand this important effort, in collaboration with our airline and airport partners, as we move away from a one-size-fits-all approach to a more intelligence-driven, risk-based transportation security system.”

TSA Preê is currently operating with American Airlines at airports in Dallas, Miami, Las Vegas, Minneapolis and Los Angeles, and with Delta Air Lines at airports in Atlanta, Detroit, Las Vegas, and Minneapolis. US Airways, United Airlines and Alaska Airlines are all opting in new passengers and will begin operations later this year.

As part of the initiative’s expansion, TSA Pre√™ will be implemented at the following airport locations throughout 2012:
  • Baltimore/Washington International Thurgood Marshall Airport (BWI)
  • Boston Logan International Airport (BOS)
  • Charlotte Douglas International Airport (CLT)
  • Cincinnati/Northern Kentucky International Airport (CVG)
  • Denver International Airport (DEN)
  • Fort Lauderdale-Hollywood International Airport (FLL)
  • George Bush Intercontinental Airport (IAH)
  • Honolulu International Airport (HNL)
  • Indianapolis International Airport (IND)
  • John F. Kennedy International Airport (JFK)
  • LaGuardia Airport (LGA)
  • Lambert-St. Louis International Airport (STL)
  • Louis Armstrong New Orleans International Airport (MSY)
  • Luis Muñoz Marín International Airport (SJU)
  • Newark Liberty International Airport (EWR)
  • O’Hare International Airport (ORD)
  • Orlando International Airport (MCO)
  • Philadelphia International Airport (PHL)
  • Phoenix Sky Harbor International Airport (PHX)
  • Pittsburgh International Airport (PIT)
  • Portland International Airport (PDX)
  • Ronald Reagan Washington National Airport (DCA)
  • Salt Lake City International Airport (SLC)
  • San Francisco International Airport (SFO)
  • Seattle-Tacoma International Airport (SEA)
  • Tampa International Airport (TPA)
  • Ted Stevens Anchorage International Airport (ANC)
  • Washington Dulles International Airport (IAD)
TSA will continue expanding TSA Preê to additional airlines and airports once they are operationally ready.

Eligible participants include certain frequent flyers from participating airlines as well as members of Customs and Border Protection’s (CBP) Trusted Traveler programs (Global Entry, SENTRI, and NEXUS) who are U.S. citizens and fly on a participating airline. Individuals interested in participating in the pilot can apply via Global Entry at http://www.globalentry.gov/.

If TSA determines a passenger is eligible for expedited screening following the TSA Pre√™ vetting process, information will be embedded in the barcode of the passenger’s boarding pass. TSA will read the barcode at the security checkpoint and then may refer the passenger to a TSA Pre√™ lane, where they will undergo expedited screening, which could include no longer removing the following items:
  • Shoes
  • 3-1-1 compliant bag from carry-on
  • Laptop from bag
  • Light outerwear/jacket
  • Belt
TSA will always incorporate random and unpredictable security measures throughout the airport and no individual will be guaranteed expedited screening. As part of the agency’s risk-based security initiative, TSA is currently testing several other screening initiatives, including initiatives designed to provide positive ID verification for airline pilots and the use of expanded behavior detection techniques.

For more information about TSA’s risk-based security initiatives, visit www.tsa.gov.

###

Thursday, February 2, 2012

Southwest Iowa Renewable Energy, LLC to Pay $10,150 Penalty

Thursday, February 2, 2012
U.S. Environmental Protection Agency, Region 7

901 N. Fifth St., Kansas City, KS 66101

Iowa, Kansas, Missouri, Nebraska, and Nine Tribal Nations


Southwest Iowa Renewable Energy, LLC to Pay $10,150 for Risk Management Plan Violations at Council Bluffs Ethanol Plant


Contact Information: Chris Whitley, 913-551-7394, whitley.christopher@epa.gov

Environmental News

FOR IMMEDIATE RELEASE

(Kansas City, Kan., Feb. 2, 2012) - Southwest Iowa Renewable Energy, LLC has agreed to pay a $10,150 civil penalty and spend at least $38,729 on a supplemental environmental project for failing to file a risk management plan and implement risk management regulations at its dry-mill ethanol plant in Council Bluffs, Iowa.

According to an administrative consent agreement and final order filed by EPA Region 7 in Kansas City, Kan., an inspection of the ethanol plant in January 2010 found that the company had not filed a risk management plan for the facility, as required by the federal Clean Air Act.

Under the Clean Air Act, the Council Bluffs facility was required to file a risk management plan because it had exceeded the 10,000-pound threshold for anhydrous ammonia, an extremely hazardous chemical. Southwest Iowa Renewable Energy was storing approximately 28,000 pounds of anhydrous ammonia at the time of the EPA inspection.

As part of its settlement with EPA, Southwest Iowa Renewable Energy has agreed to perform a supplemental environmental project, through which it will spend at least $38,729 to purchase emergency response equipment for the Council Bluffs and Lewis Township fire departments.

By agreeing to the settlement, the company has certified that the Council Bluffs ethanol plant is now in compliance with federal Risk Management Program regulations.

EPA enforces the Risk Management Program regulations of the Clean Air Act with a goal of preventing accidental chemical releases and minimizing the impact of releases or other accidents that may occur. The establishment of Risk Management Programs and formulation of Risk Management Plans helps companies, industries and municipalities operate responsibly, assists emergency responders by providing vital information necessary to address accidents and other incidents, protects the environment by preventing and minimizing damage from accidental releases, and keeps communities safer.

# # #