Secure, Managed File Transfer and Automation
豪勉科技股份有限公司 _ 楊南岳
Secure, Managed File Transfer and Automation _ Moving - - PowerPoint PPT Presentation
Secure, Managed File Transfer and Automation _ Moving Files is Business-critical Legal Documents Loan Information XML Data Files X-Rays Purchase Orders Patient Records Insurance Test Results Large
豪勉科技股份有限公司 _ 楊南岳
2
Patient Records Account Statements Insurance Claims Legal Documents Loan Information X-Rays Test Results Purchase Orders XML Data Files Large Video Files Credit Card Payments Customer Information
3
4
Email Attachments Home Grown Scripts Cloud File Share FTP Servers
5
企業內外檔案 交換
Managed File Transfer
使用者間檔案 分享
Inside Enterprise Cloud Email Attachment Dropbox, Box.net Central NAS File Sharing (Copy&Paste) iCloud Drive, Google Drive Microsoft Lync, Sharepoint Line, WhatsApp, Skype SMB,NFS,HTTP,FTP Web 2.0 Modern UI
6
IT needs to deploy systems which
meets users’ needs & provides governance required by IT IT requirements
Control Visibility Security Compliance
Employee needs
Convenient Straightforward Easy to use Fast
The Balance: Usability & Security
7
Goals PCI DSS Requirements Build and Maintain a Secure Network and Systems Install and maintain a firewall conguration to protect cardholder data Prohibit direct public access between the Internet and any system component in the cardholder data environment. Protect Cardholder Data Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Do not store sensitive authentication data after authorization Limit cardholder data storage and retention time Maintain a Vulnerability Management Program Protect all systems against malware and regularly update anti- virus software or programs Implement Strong Access Control Measures Restrict access to cardholder data by business need to know Restrict physical access to cardholder data Identify and authenticate access to system components Regularly Monitor and Test Networks Track and monitor all access to network resources and cardholder data Implement audit trails to link all access to system components to each individual user. Maintain an Information Security Policy Maintain a policy that addresses information security for all personnel
8
Internet Trusted Network
FIREWALL FIREWALL
9
Internet Trusted Network
FIREWALL FIREWALL
modules
10
Internet Trusted Network
FIREWALL FIREWALL
11
Conditional Logic
12
13
14
Internet Trusted Network
FIREWALL FIREWALL
Person-to-Person
15
16
Upload attachment and/or message
17
Send email notification with link to message and attachment Upload attachment and/or message
18
Send email notification with link to message and attachment Upload attachment and/or message Receive Message Two Options
19
Read message and download attachment Send email notification with link to message and attachment Upload attachment and/or message Receive Message Two Options
20
Goals PCI DSS Requirements Build and Maintain a Secure Network and Systems Install and maintain a firewall configuration to protect cardholder data Prohibit direct public access between the Internet and any system component in the cardholder data environment. Protect Cardholder Data Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Do not store sensitive authentication data after authorization Limit cardholder data storage and retention time Maintain a Vulnerability Management Program Protect all systems against malware and regularly update anti- virus software or programs Implement Strong Access Control Measures Restrict access to cardholder data by business need to know Restrict physical access to cardholder data Identify and authenticate access to system components Regularly Monitor and Test Networks Track and monitor all access to network resources and cardholder data Implement audit trails to link all access to system components to each individual user. Maintain an Information Security Policy Maintain a policy that addresses information security for all personnel
21
HTTPS
FTPS, SFTP, HTTPS
Mobile Users Any FTPS Client Any SFTP Client Other Ipswitch Clients Microsoft Outlook Web Browser Email Server Any FTPS Server Any SFTP Server Mainframe / Unix Server Network Share
FTPS, SFTP, HTTPS FTPS, SFTP, HTTPS, AS1/AS2/AS3 FTPS, SFTP, HTTPS, AS1/AS2/AS3
Any FTPS Server Email Server Any SFTP Server Any HTTPS Server Any ASx Server SMIME Server Web Browser Any FTPS Client Any SFTP Client Any AS2 or AS3 Client Other Ipswitch Clients Mobile Users
FIREWALL FIREWALL
22
SECURE TUNNEL LOAD BALANCER (OPTIONAL) HTTPS
FTPS, SFTP, HTTPS
Mobile Users Any FTPS Client Any SFTP Client Other Ipswitch Clients Microsoft Outlook Web Browser Email Server Any FTPS Server Any SFTP Server Mainframe / Unix Server Network Share
FTPS, SFTP, HTTPS FTPS, SFTP, HTTPS, AS1/AS2/AS3 FTPS, SFTP, HTTPS, AS1/AS2/AS3
Any FTPS Server Email Server Any SFTP Server Any HTTPS Server Any ASx Server SMIME Server Web Browser Any FTPS Client Any SFTP Client Any AS2 or AS3 Client Other Ipswitch Clients Mobile Users
FIREWALL FIREWALL
23
Goals PCI DSS Requirements Build and Maintain a Secure Network and Systems Install and maintain a firewall conguration to protect cardholder data Prohibit direct public access between the Internet and any system component in the cardholder data environment. Protect Cardholder Data Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Do not store sensitive authentication data after authorization Limit cardholder data storage and retention time Maintain a Vulnerability Management Program Protect all systems against malware and regularly update anti- virus software or programs Implement Strong Access Control Measures Restrict access to cardholder data by business need to know Restrict physical access to cardholder data Identify and authenticate access to system components Regularly Monitor and Test Networks Track and monitor all access to network resources and cardholder data Implement audit trails to link all access to system components to each individual user. Maintain an Information Security Policy Maintain a policy that addresses information security for all personnel
24
SECURE TUNNEL LOAD BALANCER (OPTIONAL) HTTPS
FTPS, SFTP, HTTPS
Mobile Users Any FTPS Client Any SFTP Client Other Ipswitch Clients Microsoft Outlook Web Browser Email Server Any FTPS Server Any SFTP Server Mainframe / Unix Server Network Share
FTPS, SFTP, HTTPS FTPS, SFTP, HTTPS, AS1/AS2/AS3 FTPS, SFTP, HTTPS, AS1/AS2/AS3
Any FTPS Server Email Server Any SFTP Server Any HTTPS Server Any ASx Server SMIME Server Web Browser Any FTPS Client Any SFTP Client Any AS2 or AS3 Client Other Ipswitch Clients Mobile Users
FIREWALL FIREWALL
AES256
25
Goals PCI DSS Requirements Build and Maintain a Secure Network and Systems Install and maintain a firewall conguration to protect cardholder data Prohibit direct public access between the Internet and any system component in the cardholder data environment. Protect Cardholder Data Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Do not store sensitive authentication data after authorization Limit cardholder data storage and retention time Maintain a Vulnerability Management Program Protect all systems against malware and regularly update anti- virus software or programs Implement Strong Access Control Measures Restrict access to cardholder data by business need to know Restrict physical access to cardholder data Identify and authenticate access to system components Regularly Monitor and Test Networks Track and monitor all access to network resources and cardholder data Implement audit trails to link all access to system components to each individual user. Maintain an Information Security Policy Maintain a policy that addresses information security for all personnel
26
SECURE TUNNEL LOAD BALANCER (OPTIONAL) HTTPS
FTPS, SFTP, HTTPS, AS1/AS2/AS3 FTPS, SFTP, HTTPS, AS1/AS2/AS3
Any FTPS Server Email Server Any SFTP Server Any HTTPS Server Any ASx Server SMIME Server Web Browser Any FTPS Client Any SFTP Client Any AS2 or AS3 Client Other Ipswitch Clients Mobile Users
FIREWALL FIREWALL
FIREWALL
DATA ZONE
NAS or NAS Cluster Antivirus ICAP Servers SQL Server Standalone or Cluster
27
Goals PCI DSS Requirements Build and Maintain a Secure Network and Systems Install and maintain a firewall conguration to protect cardholder data Prohibit direct public access between the Internet and any system component in the cardholder data environment. Protect Cardholder Data Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Do not store sensitive authentication data after authorization Limit cardholder data storage and retention time Maintain a Vulnerability Management Program Protect all systems against malware and regularly update anti- virus software or programs Implement Strong Access Control Measures Restrict access to cardholder data by business need to know Restrict physical access to cardholder data Identify and authenticate access to system components Regularly Monitor and Test Networks Track and monitor all access to network resources and cardholder data Implement audit trails to link all access to system components to each individual user. Maintain an Information Security Policy Maintain a policy that addresses information security for all personnel
28
SECURE TUNNEL LOAD BALANCER (OPTIONAL) HTTPS
FTPS, SFTP, HTTPS, AS1/AS2/AS3 FTPS, SFTP, HTTPS, AS1/AS2/AS3
Any FTPS Server Email Server Any SFTP Server Any HTTPS Server Any ASx Server SMIME Server Web Browser Any FTPS Client Any SFTP Client Any AS2 or AS3 Client Other Ipswitch Clients Mobile Users
FIREWALL FIREWALL
FIREWALL
NAS or NAS Cluster DLP and Antivirus ICAP Servers SQL Server Standalone or Cluster
User DB (AD/Radius/SSO)
29
Goals PCI DSS Requirements Build and Maintain a Secure Network and Systems Install and maintain a firewall conguration to protect cardholder data Prohibit direct public access between the Internet and any system component in the cardholder data environment. Protect Cardholder Data Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Do not store sensitive authentication data after authorization Limit cardholder data storage and retention time Maintain a Vulnerability Management Program Protect all systems against malware and regularly update anti- virus software or programs Implement Strong Access Control Measures Restrict access to cardholder data by business need to know Restrict physical access to cardholder data Identify and authenticate access to system components Regularly Monitor and Test Networks Track and monitor all access to network resources and cardholder data Implement audit trails to link all access to system components to each individual user. Maintain an Information Security Policy Maintain a policy that addresses information security for all personnel
30
31
Failed Transfers by End-Point Peak Transfer Analysis
32
Architecture & Components
HTTPS
metadata
Analytics Server Agent
MOVEit
MOVEit processing
Client
& reporting
share
33
Goals PCI DSS Requirements Build and Maintain a Secure Network and Systems Install and maintain a firewall conguration to protect cardholder data Prohibit direct public access between the Internet and any system component in the cardholder data environment. Protect Cardholder Data Protect stored cardholder data Encrypt transmission of cardholder data across open, public networks Do not store sensitive authentication data after authorization Limit cardholder data storage and retention time Maintain a Vulnerability Management Program Protect all systems against malware and regularly update anti- virus software or programs Implement Strong Access Control Measures Restrict access to cardholder data by business need to know Restrict physical access to cardholder data Identify and authenticate access to system components Regularly Monitor and Test Networks Track and monitor all access to network resources and cardholder data Implement audit trails to link all access to system components to each individual user. Maintain an Information Security Policy Maintain a policy that addresses information security for all personnel
34
SECURE TUNNEL LOAD BALANCER (OPTIONAL) HTTPS
FTPS, SFTP, HTTPS, AS1/AS2/AS3 FTPS, SFTP, HTTPS, AS1/AS2/AS3
Any FTPS Server Email Server Any SFTP Server Any HTTPS Server Any ASx Server SMIME Server Web Browser Any FTPS Client Any SFTP Client Any AS2 or AS3 Client Other Ipswitch Clients Mobile Users
FIREWALL FIREWALL
FIREWALL
NAS or NAS Cluster Antivirus ICAP Servers SQL Server Standalone or Cluster
User DB (AD/Radius/SSO)
DLP
35
SECURE TUNNEL LOAD BALANCER SQL SERVER SAN, NAS OR NAS CLUSTER NODE 1 NODE 2 Mobile Users Any FTPS Client Any SFTP Client Other Ipswitch Clients Microsoft Outlook Web Browser
FTPS, SFTP, HTTPS
SECURE TUNNEL
FIREWALL FIREWALL FIREWALL FIREWALL
Web Browser Any FTPS Client Any SFTP Client Any AS2 or AS3 Client Other Ipswitch Clients Mobile Users
36
Errors / Exceptions / Problems affected
file transfer volume
Average time
to correct errors / problems related to file transfer:
PER INCIDENT Security and compliance incidents
year-over-year
REDUCING RISK
IMPROVING EFFICIENCY
LOW COSTS
37