• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • SafeStone Taps RSA for SIEM Expertise

    August 24, 2010 Alex Woodie

    Safestone Technologies has long been a partner of RSA Security and used the security giant’s expertise in authentication to bolster the environments of its IBM System i customers. With this month’s update to Safestone’s security software, the vendors have strengthened the partnership with an IBM i connection to RSA’s security information and event management (SIEM) system.

    Safestone says it worked closely with RSA (a division of EMC) to launch i Connect, which is a new component of the DetectIT suite that’s designed to move IBM i log data to enVision, RSA’s SIEM solution.

    The i Connect product watches for more than 300 different IBM i event types, including changes or additions to user profiles, object authorities, network access, use of SQL, and entries to the security journal and system history log, the vendor says.

    i Connect also includes filtering mechanisms to help avoid overloading the RSA SIEM with unimportant system events. (Remember, IBM i is quite exact, and prolific, in its log monitoring and journaling capabilities compared to your “standard” X64 or Unix environment). Administrators can screen logs by event type, message ID, job name, job user name, program name, and time and day of week.

    Safestone also did some work on its Syslog connecter with DetectIT 14.3, and this played heavily into the launch of i Connect and its integration with enVision. The vendor says it made “extensive enhancements” to its Syslog interface with DetectIT 14.3 to support high volume environments.

    Previously, the only way to get IBM i log data into enVision was to send it via FTP. With the Syslog-based mechanism that Safestone developed for enVision with DetectIT 14.3 and i Connect, it is much easier and faster to move the data to enVision.

    enVision is used by more than 1,600 organizations around the world, according to RSA. At the heart of the SIEM solution is the LogSmart Internet Protocol database (or IPDB), which RSA says is very good at managing unstructured data, such as that coming from all the various Syslog agents feeding data into the SIEM, as well as many other sources (although IBM i log data is more refined, and verbose, than most sources).

    Several other features were added with version 14.3, and one of the most compelling is an enhancement to Powerful User Passport (PUP), the software launched last year that minimizes the potential impact that individuals with privileged user profiles can take, by allowing users to “swap” into powerful user profiles for limited periods of time.

    With this release, PUP now monitors all SQL activity the user takes while swapped into a powerful user profile, like ALLOBJ. Since SQL is one of the most powerful (and dangerous, because it is not monitored natively) capabilities of the IBM i platform, creating a full audit trail of all SQL activities while a user is swapped into a powerful user profile with PUP makes perfect sense. (It probably should have been there before, but late is better than never.)

    DetectIT 14.3 also brings full RSA certified support for version 7.1 of the SecurID Authentication Manager. It also features more flexible deployment options, Safestone says. SecurID is used to implement two-factor authentication; it prevents a user from gaining access to System i or other servers unless they can provide two forms of authentication, such as a password or PIN and a hardware authenticator, such as a smart card or USB token.

    The new release of DetectIT supports IBM i version 7.1. For more information, see www.safestone.com.

    RELATED STORIES

    Safestone Unveils i/OS Compliance Software

    Safestone Gives Away Free PCI Assessments to i OS Customers

    Safestone Cracks Down on Excessive Authority with PUP

    Safestone Gives i Security Officers Greater Control

    Safestone Re-emerges with New Corporate Identity, i OS Security Tools



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    SEQUEL Software:  FREE Webinar. Aug 25. Learn how SEQUEL simplifies EnterpriseOne data access.
    PowerTech:  FREE Webinar! Top 10 IBM i Security Risks. August 25, 10 a.m. CT
    COMMON:  Join us at the Fall 2010 Conference & Expo, Oct. 4 - 6, in San Antonio, Texas

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    IBM Ships Fat Memory for Power 770 and 780 Systems Early An Introduction to Python on IBM i, Part 1

    Leave a Reply Cancel reply

Volume 10, Number 30 -- August 24, 2010
THIS ISSUE SPONSORED BY:

ProData Computer Services
Bytware
RevSoft
DRV Technologies
RJS Software Systems

Table of Contents

  • PHP and JavaScript Come Together in Zend Studio 8
  • SafeStone Taps RSA for SIEM Expertise
  • SkyView Gets Tough on User Profiles
  • Profound Updates I/O Handler for RPG Open Access
  • IGEL Adds 5250 Emulation to Linux Thin Clients
  • LogLogic Strives to Create Better Visibility of Log Data
  • Third-Party ERP Support Does Save Money, Nucleus Says
  • RentalMan Gets Hooks into IntelliChief
  • IBS Launches New BI, CRM Products
  • ACOM to Throw In Free Printer on Software Sale

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Big Blue Raises IBM i License Transfer Fees, Other Prices
  • Keep The IBM i Youth Movement Going With More Training, Better Tools
  • Remain Begins Migrating DevOps Tools To VS Code
  • IBM Readies LTO-10 Tape Drives And Libraries
  • IBM i PTF Guide, Volume 27, Number 23
  • SEU’s Fate, An IBM i V8, And The Odds Of A Power13
  • Tandberg Bankruptcy Leaves A Hole In IBM Power Storage
  • RPG Code Generation And The Agentic Future Of IBM i
  • A Bunch Of IBM i-Power Systems Things To Be Aware Of
  • IBM i PTF Guide, Volume 27, Numbers 21 And 22

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle