fhs
Volume 10, Number 30 -- August 24, 2010

SafeStone Taps RSA for SIEM Expertise

Published: August 24, 2010

by Alex Woodie

Safestone Technologies has long been a partner of RSA Security and used the security giant's expertise in authentication to bolster the environments of its IBM System i customers. With this month's update to Safestone's security software, the vendors have strengthened the partnership with an IBM i connection to RSA's security information and event management (SIEM) system.

Safestone says it worked closely with RSA (a division of EMC) to launch i Connect, which is a new component of the DetectIT suite that's designed to move IBM i log data to enVision, RSA's SIEM solution.

The i Connect product watches for more than 300 different IBM i event types, including changes or additions to user profiles, object authorities, network access, use of SQL, and entries to the security journal and system history log, the vendor says.

i Connect also includes filtering mechanisms to help avoid overloading the RSA SIEM with unimportant system events. (Remember, IBM i is quite exact, and prolific, in its log monitoring and journaling capabilities compared to your "standard" X64 or Unix environment). Administrators can screen logs by event type, message ID, job name, job user name, program name, and time and day of week.

Safestone also did some work on its Syslog connecter with DetectIT 14.3, and this played heavily into the launch of i Connect and its integration with enVision. The vendor says it made "extensive enhancements" to its Syslog interface with DetectIT 14.3 to support high volume environments.

Previously, the only way to get IBM i log data into enVision was to send it via FTP. With the Syslog-based mechanism that Safestone developed for enVision with DetectIT 14.3 and i Connect, it is much easier and faster to move the data to enVision.

enVision is used by more than 1,600 organizations around the world, according to RSA. At the heart of the SIEM solution is the LogSmart Internet Protocol database (or IPDB), which RSA says is very good at managing unstructured data, such as that coming from all the various Syslog agents feeding data into the SIEM, as well as many other sources (although IBM i log data is more refined, and verbose, than most sources).

Several other features were added with version 14.3, and one of the most compelling is an enhancement to Powerful User Passport (PUP), the software launched last year that minimizes the potential impact that individuals with privileged user profiles can take, by allowing users to "swap" into powerful user profiles for limited periods of time.

With this release, PUP now monitors all SQL activity the user takes while swapped into a powerful user profile, like ALLOBJ. Since SQL is one of the most powerful (and dangerous, because it is not monitored natively) capabilities of the IBM i platform, creating a full audit trail of all SQL activities while a user is swapped into a powerful user profile with PUP makes perfect sense. (It probably should have been there before, but late is better than never.)

DetectIT 14.3 also brings full RSA certified support for version 7.1 of the SecurID Authentication Manager. It also features more flexible deployment options, Safestone says. SecurID is used to implement two-factor authentication; it prevents a user from gaining access to System i or other servers unless they can provide two forms of authentication, such as a password or PIN and a hardware authenticator, such as a smart card or USB token.

The new release of DetectIT supports IBM i version 7.1. For more information, see www.safestone.com.


RELATED STORIES

Safestone Unveils i/OS Compliance Software

Safestone Gives Away Free PCI Assessments to i OS Customers

Safestone Cracks Down on Excessive Authority with PUP

Safestone Gives i Security Officers Greater Control

Safestone Re-emerges with New Corporate Identity, i OS Security Tools



                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
BYTWARE

Take an object-based approach to exit point security.

Secure your system and access to data more efficiently with
the object-based approach of StandGuard Network Security.

Simplify your security by focusing on the intent of
the request rather than its syntax to create and enforce security policies
in less time and at lower cost
. StandGuard Network Security provides
a non-intrusive, phased-in approach that meets your regulatory compliance
needs on Power Systems running IBM i.

Try StandGuard Network Security free for 30 days.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

SEQUEL Software:  FREE Webinar. Aug 25. Learn how SEQUEL simplifies EnterpriseOne data access.
PowerTech:  FREE Webinar! Top 10 IBM i Security Risks. August 25, 10 a.m. CT
COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
The iSeries Express Web Implementer's Guide: List Price, $49.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
Can the AS/400 Survive IBM?: List Price, $49.00
Chip Wars: List Price, $29.95


 
The Four Hundred
IBM Ducks i Pricing on Most Entry Power7 Servers

BladeCenter S Express i Edition Gets a Power7 Upgrade

The Power 795: Cheaper Performance, Expensive Software

As I See It: The Once and Future HP Way

An Encryption Horror Story

Four Hundred Guru
Remove Trailing Blanks from Legacy Columns with the IBM OLE DB Providers

How Did I Do That?

Admin Alert: Six Things You May Not Know About i/OS Passwords

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
August 7, 2010: Volume 12, Number 32

July 31, 2010: Volume 12, Number 31

July 24, 2010: Volume 12, Number 30

July 17, 2010: Volume 12, Number 29

July 10, 2010: Volume 12, Number 28

July 3, 2010: Volume 12, Number 27

TPM at The Register
US puts $30bn of IT projects up for review

AMD nabs ex-Intel techie as server CTO

Oracle names self virtualization king

Big biz loved Dell servers and storage in Q2

Mobile PC buyers buying peppier boxes

HP rings up Hurd's final quarter

HP hires headhunter to replace Hurd

AIX 7.1 moves forward to Power7 iron

Amazon challenges cloudy startups

IBM whips out its TPC-C...cluster

SGI previews Q4 financials

IBM completes Power7 server arsenal

THIS ISSUE SPONSORED BY:

ProData Computer Services
Bytware
RevSoft
DRV Technologies
RJS Software Systems


Printer Friendly Version


TABLE OF CONTENTS
PHP and JavaScript Come Together in Zend Studio 8

SafeStone Taps RSA for SIEM Expertise

SkyView Gets Tough on User Profiles

Profound Updates I/O Handler for RPG Open Access

IGEL Adds 5250 Emulation to Linux Thin Clients

News Briefs and Product Shorts:

LogLogic Strives to Create Better Visibility of Log Data . . . Third-Party ERP Support Does Save Money, Nucleus Says . . . RentalMan Gets Hooks into IntelliChief . . . IBS Launches New BI, CRM Products . . . ACOM to Throw In Free Printer on Software Sale . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2010 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement