The recent disclosure that thousands of Internet-facing SAP NetWeaver implementations are vulnerable to severe compromises will no doubt send some admins scurrying to their security team.
But the release of this information raises a question - is it preferable to fix each vulnerability or secure the environment? We definitely lean to the latter, but see much of the former (and also are sympathetic to some of the reasons why this occurs). In this instance with the SAP NetWeaver vulnerability one of the frustrating things if trying to fix the vulnerability is that without access to the code you are completely dependent on a fix being provided by the vendor. And this is similar for just about any off the shelf web applications. (It also applies to databases - think the Oracle vulnerabilities).
Following a strategic acquisition, CoreSight partners BeyondTrust recently announced the forthcoming PowerBroker Desktops DLP Edition, to help organisations filter and contain sensitive data.
John Mutch, CEO at BeyondTrust stated, “The acquisition of GentleSecurity and the launch of our PowerBroker Desktop DLP solution add a very important technology to our vision of securing the perimeter within.”
The existing version of PowerBroker Desktops has seen significant interest in the Australian market with a number of clients taking advantage of capability to remove administrator rights from Windows PCs. Rather than enhancing security and control at the expense of productivity, PowerBroker Desktops allows end users to remain productive by elevating privileges for applications, software installs, system tasks, scripts, control panel applets and more.
The business case for implementing enterprise single sign-on (ESSO) has solidified. Factors driving ESSO implementations are high password-related help desk costs and the need for shared workstation support in clinical environments. However, improved user convenience is usually the most deeply seated need.
In September, Gartner released the 2010 Gartner MarketScope for Enterprise Single Sign-On. This report provides up-to-date ratings for vendors such as Microsoft Sentillion, Passlogix, IBM, Evidian, Novell and Imprivata. SSO vendors are evaluated on critical decision making criteria such as product offerings, pricing, company viability and customer experience.
For many organisations SharePoint has become the tool of choice for content management because it enhances internal collaboration and can be accessed from any location. And in today's landscape of mobile communication, that's a great advantage. The downside is that this flexible approach to remote access, in conjunction with unique SharePoint security threats, can expose applications and data to attack.
As with any Web application, organisations should consider the security risks before deploying SharePoint. SharePoint applications often contain sensitive and confidential data. With valuable information at risk, SharePoint becomes both a top security concern for businesses and an attractive target for hackers.
If you already rely on Microsoft SharePoint ...
Ph: 03 9878 2726
Ph: 02 8011 3337
E: info@coresight.com.au
10/11 Mary St
BLACKBURN VIC 3130