fhs
Volume 9, Number 11 -- March 17, 2009

Raz-Lee Summarizes i OS Security Settings in New Compliance Product

Published: March 17, 2009

by Alex Woodie

The IBM System i is a notoriously difficult nut for auditors to crack. Accustomed to "standards-based" Windows and Unix systems, auditors sometimes struggle to make their way around a subject's i OS-based computer. To help alleviate the pain of hunting for security data for auditors and IT managers alike, i OS security software developer Raz-Lee Security last month launched a new product called Compliance Evaluator that seeks to include the most relevant compliance-related security information in a concise, one-page summary.

Raz-Lee, which is based in Israel and has its U.S. offices near New York City, has plenty of experience with helping customers deal with security regulations. Its iSecurity suite can generate hundreds of reports detailing exactly whether a given System i server (and the company running it) is compliant with computer security provisions of countless laws, including Sarbanes Oxley, HIPAA, PCI, Basel II, the California Privacy Act, and ISO 17799, just for starters.

But not everybody wants to wade through the technical minutia--or can understand it, for that matter. Whether a group of users has exceeded the password reset limit of 60 days may be an important thing to consider when sculpting a security enforcement policy. But when all you want is a big picture summary of a customer's AS/400 security posture, the nitty gritty detail actually hurts productivity; it doesn't help it.

That's where the latest addition to Raz-Lee iSecurity suite, Compliance Evaluator (formerly called Compliance On-Demand), comes in. Compliance Evaluator is intended to be used by IT managers and auditors who periodically need concise summaries of System i security settings. The product gathers data from i OS's QAUDJRN, and generates one-page summary reports, which include an overall compliance score and ratings for specific security-related components, such as system values, network attributes, and user profiles. All of the reports are output in Excel format, and can be automatically e-mailed to managers or off-site auditors.


Auditors and IT managers can get a quick summary view of how their AS/400 servers' security settings stack up to SOX and other regulations with Raz-Lee's new Compliance Evaluator.

Raz-Lee CEO Shmuel Zailer says the new product marks a breakthrough in System i security reporting. "With Compliance Evaluator, we've take a giant step forward toward our mission of making System i security easily attainable for managers and auditors," Zailer says. "The clear, single-view display of complex, comprehensive security data makes managers' tasks a lot easier, enabling them to quickly assess--and immediately improve--the security of their environment."

The security settings of up to 99 System i servers or LPARs can be summarized by Compliance Evaluator. The product can then take this data and compare the different security scores, generate site-wide security summaries, or even create baseline levels for compliance.

Compliance Evaluator uses the security reporting and scheduling capabilities of several other iSecurity products, including the Firewall and Audit products, to generate its summary. Because of this, it cannot be sold separately from the suite. Instead, it's meant to help with security compliance reporting of existing and future iSecurity customers.

Compliance Evaluator is available now. Pricing is tier-based and begins at $4,000. For more information, visit www.raz-lee.com.


RELATED STORIES

Raz-Lee Eases Compliance with Update to iSecurity

Raz-Lee Updates iSecurity Suite

Raz-Lee Signs BOSaNOVA to Resell Security Software

Raz-Lee Targets U.S. Market with iSeries Security Tools



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
BYTWARE

Do you know the full spectrum of
malicious code threats?

Today's malicious code comes in many forms
and from where you least expect it. SOX-style
legislation and the evolving threat from viruses is
challenging the ability of IT management to keep
up with security requirements.

As threats from malicious code evolve, protect
your systems and network by taking the fight to
the viruses where they hide.

Learn more in
"The Modern Virus Threat"
webcast.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

New Generation Software:  Watch a demo, then test drive NGS-IQ
Northeast User Groups Conference:  19th Annual Conference, April 6 - 8, Framingham, MA
COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
The Four Hundred
The Data Center Is the Computer

IBM and Partners Work on Future Chip Tech

IBM-Marist Survey Emphasizes Technology in Education and Careers

Mad Dog 21/21: The Case of the Vanishing Equity

Disk Arrays Sales Down in Q4; IBM Slammed

Four Hundred Guru
Looking for Commitment, Part 1

Treasury of new DB2 6.1 Features, Part 2: Grouping Sets and Super Groups

Admin Alert: Six Ways to Mess Up i5/OS User Profiles Security (And What To Do About It)

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
March 14, 2009: Volume 11, Number 11

March 7, 2009: Volume 11, Number 10

February 28, 2009: Volume 11, Number 9

February 21, 2009: Volume 11, Number 8

February 14, 2009: Volume 11, Number 7

February 7, 2009: Volume 11, Number 6

TPM at The Register
DellHPSunIBM unmoved by Cisco blades

Fusion-io ups SSD ante

Sun parks cloud at data center Valhalla

Supercomputer niche chucks rocks at Nehalem

IBM rejiggers x64 servers, blades

Texas Memory Systems punts Texas-sized SSD

Have IT vendors been hit harder than IT departments?

Sun beefs servers with SSDs

Stratus punts freebie VMware virt software

IBM not worried about Cisco blades

IBM boasts of full 8Gb Fibre Channel for blades

EuroMidEastAfrica server biz tumbles

Intel 'Nehalem' Xeons poised for March 31 launch

AT&T wants to run your data center

THIS ISSUE SPONSORED BY:

ProData Computer Services
Bytware
Maximum Availability
Bsafe Information Systems
Twin Data


Printer Friendly Version


TABLE OF CONTENTS
Codelyzer Offers Relief from Application Maintenance Burdens

Raz-Lee Summarizes i OS Security Settings in New Compliance Product

Aldon Stresses Importance of End Users with Updated Help Desk

Tape Backup Recovery Points Improved With RecoverNow

Upstart i Developer Brings AS/400s to the Cloud

News Briefs and Product Shorts:

Financial System Outsourcer Taps UC4 to for Job Automation . . . Malaysian Bank Invests $5.5 Million in Power Systems Upgrade . . . No Chapter 11 Bankruptcy for Island Pacific, 3Q Says . . . Lawson M3 Customers Get New B2B Option from Axway . . . Mid-Market Companies Want to Be Green, Too . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement