SlideShare une entreprise Scribd logo
1  sur  16
Security Solutions for a Smarter Planet: IBM Directions in Security Jason Burn
Welcome to the smarter planet 162 million Almost 162 million smart phones were sold in 2008, surpassing laptop sales for the first time. 90% Nearly 90% of innovation in automobiles is related to software and electronics systems. 1 trillion Soon, there will be 1 trillion connected devices in the world, constituting an “internet of things.” The planet is getting more  Instrumented ,  Interconnected  and  Intelligent .
Protection of sensitive and large volumes of data, shared globally Protection of sensors and  actuators in the wild Protection of  digital identities With the smarter planet opportunities come   new security and privacy risks
Additional security and privacy risks impacting customers Addressing compliance  complexity Adoption of virtualization  and cloud computing Addressing the new  cyber threat landscape Expectation of  privacy
So how can security help us take advantage of opportunities on the smarter planet? ,[object Object],[object Object],[object Object],[object Object],[object Object],Security enables us to  take risks  and  innovate confidently .  Virtualization  Tele Working Outsourcing Cloud Computing
“ Secure by design” A new model for building a smarter planet ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],… IBM can help
IBM’s security strategy Delivering secure  products and services Providing end-to-end coverage  across all security domains  ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],IBM Security Solutions. Secure by Design.
So where do we start? …… many scenarios to plan for… External Threats Insider Threats Inadvertent Deliberate ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
“ Foundational Controls” = seatbelts and airbags ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],* Sources: W.H. Baker, C.D. Hylender, J.A. Valentine, 2008 Data Breach Investigations Report, Verizon Business, June 2008 ITPI: IT Process Institute, EMA December 2008 Cost Effectiveness Agility Time Complexity Pressure
“ Foundational Controls” represent a hygienic process… ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],N etwork, Server, and End Point P hysical Infrastructure P eople and Identity D ata and Information A pplication and Process Control Govern and secure complex infrastructure and ensure regulatory compliance  Understand health and performance of services across your infrastructure  Drive down cost, minimize human error and increase productivity Visibility Automation Adherence to ITIL (ITSM) sets apart highest performers in security management
… And “Foundational Controls” provide an effective approach for dealing with the growing compliance landscape ,[object Object],[object Object],[object Object],[object Object]
IBM Security Framework supports Integrated Service Management helping you assess and manage risk DATA AND INFORMATION Understand, deploy, and properly test controls for access to and usage of  sensitive data PEOPLE AND IDENTITY Mitigate the risks associated with user access to corporate resources APPLICATION AND PROCESS Keep applications secure, protected from malicious or fraudulent use, and hardened against failure   NETWORK, SERVER AND END POINT Optimize service availability by mitigating risks  to network components PHYSICAL INFRASTRUCTURE Provide actionable intelligence on the desired state of physical infrastructure security and make improvements  GOVERANCE, RISK MGMT AND COMPLIANCE Ensure comprehensive management of security activities and compliance with all security mandates  GRC
IBM security portfolio Overview = Professional Services = Products = Cloud-based & Managed Services Identity and  Access Management  Mainframe Security Virtual System Security Database Monitoring and Protection Encryption and Key Lifecycle Management App Vulnerability Scanning Access and Entitlement Management Web Application Firewall Data Loss Prevention App Source Code Scanning SOA Security Intrusion Prevention System Messaging Security Data Masking Infrastructure Security E-mail  Security Application Security Web/URL Filtering Vulnerability  Assessment Firewall, IDS/IPS,  MFS Mgmt. Identity Management Data  Security Access Management GRC Physical Security Security Governance, Risk and Compliance SIEM and Log Management Web / URL  Filtering Security Event  Management  Threat Assessment
How we add value: IBM leverages our skills to help meet your goals   IBM has industry’s broadest Security Solutions portfolio IBM understands Security & Risk are business problems first,  technical problems second   IBM has deep  industry expertise IBM has a huge ecosystem of leading security partners IBM has the  client success stories  to demonstrate results
ONE  voice   for security . IBM SECURITY SOLUTIONS INNOVATIVE   products and services . IBM SECURITY FRAMEWORK COMMITTED  to the vision of a Secure Smarter Planet . SECURE BY DESIGN
Trademarks and disclaimers ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

Contenu connexe

Tendances

10 Security Essentials Every CxO Should Know
10 Security Essentials Every CxO Should Know10 Security Essentials Every CxO Should Know
10 Security Essentials Every CxO Should KnowIBM Security
 
Mobile Vision 2020
Mobile Vision 2020Mobile Vision 2020
Mobile Vision 2020IBM Security
 
PAS: Leveraging IT/OT - Convergence and Developing Effective OT Cybersecurity
PAS: Leveraging IT/OT - Convergence and Developing Effective OT CybersecurityPAS: Leveraging IT/OT - Convergence and Developing Effective OT Cybersecurity
PAS: Leveraging IT/OT - Convergence and Developing Effective OT CybersecurityMighty Guides, Inc.
 
IT Security Bedrohungen optimal abwehren_Tom Turner und Andreas Wespi
IT Security Bedrohungen optimal abwehren_Tom Turner und Andreas WespiIT Security Bedrohungen optimal abwehren_Tom Turner und Andreas Wespi
IT Security Bedrohungen optimal abwehren_Tom Turner und Andreas WespiIBM Switzerland
 
The Future of Cyber Security - Matthew Rosenquist
The Future of Cyber Security - Matthew RosenquistThe Future of Cyber Security - Matthew Rosenquist
The Future of Cyber Security - Matthew RosenquistMatthew Rosenquist
 
Accelerating SOC Transformation with IBM Resilient and Carbon Black
Accelerating SOC Transformation with IBM Resilient and Carbon BlackAccelerating SOC Transformation with IBM Resilient and Carbon Black
Accelerating SOC Transformation with IBM Resilient and Carbon BlackIBM Security
 
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...IBM Security
 
Cognitive security
Cognitive securityCognitive security
Cognitive securityIqra khalil
 
4 Ways to Build your Immunity to Cyberthreats
4 Ways to Build your Immunity to Cyberthreats4 Ways to Build your Immunity to Cyberthreats
4 Ways to Build your Immunity to CyberthreatsIBM Security
 
Cognitive Security Case Study
Cognitive Security Case StudyCognitive Security Case Study
Cognitive Security Case StudyCredo Ventures
 
From reactive to automated reducing costs through mature security processes i...
From reactive to automated reducing costs through mature security processes i...From reactive to automated reducing costs through mature security processes i...
From reactive to automated reducing costs through mature security processes i...NetIQ
 
The 10 most trusted companies in enterprise security for dec 2017
The 10 most trusted companies in enterprise security for dec 2017The 10 most trusted companies in enterprise security for dec 2017
The 10 most trusted companies in enterprise security for dec 2017Merry D'souza
 
Security Awareness Training
Security Awareness TrainingSecurity Awareness Training
Security Awareness TrainingDaniel P Wallace
 
Presentation cloud security the grand challenge
Presentation   cloud security the grand challengePresentation   cloud security the grand challenge
Presentation cloud security the grand challengexKinAnx
 
The importance of information security nowadays
The importance of information security nowadaysThe importance of information security nowadays
The importance of information security nowadaysPECB
 

Tendances (20)

10 Security Essentials Every CxO Should Know
10 Security Essentials Every CxO Should Know10 Security Essentials Every CxO Should Know
10 Security Essentials Every CxO Should Know
 
Mobile Vision 2020
Mobile Vision 2020Mobile Vision 2020
Mobile Vision 2020
 
PAS: Leveraging IT/OT - Convergence and Developing Effective OT Cybersecurity
PAS: Leveraging IT/OT - Convergence and Developing Effective OT CybersecurityPAS: Leveraging IT/OT - Convergence and Developing Effective OT Cybersecurity
PAS: Leveraging IT/OT - Convergence and Developing Effective OT Cybersecurity
 
IT Security Bedrohungen optimal abwehren_Tom Turner und Andreas Wespi
IT Security Bedrohungen optimal abwehren_Tom Turner und Andreas WespiIT Security Bedrohungen optimal abwehren_Tom Turner und Andreas Wespi
IT Security Bedrohungen optimal abwehren_Tom Turner und Andreas Wespi
 
The Future of Cyber Security - Matthew Rosenquist
The Future of Cyber Security - Matthew RosenquistThe Future of Cyber Security - Matthew Rosenquist
The Future of Cyber Security - Matthew Rosenquist
 
Accelerating SOC Transformation with IBM Resilient and Carbon Black
Accelerating SOC Transformation with IBM Resilient and Carbon BlackAccelerating SOC Transformation with IBM Resilient and Carbon Black
Accelerating SOC Transformation with IBM Resilient and Carbon Black
 
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
Leveraging Validated and Community Apps to Build a Versatile and Orchestrated...
 
Cognitive security
Cognitive securityCognitive security
Cognitive security
 
4 Ways to Build your Immunity to Cyberthreats
4 Ways to Build your Immunity to Cyberthreats4 Ways to Build your Immunity to Cyberthreats
4 Ways to Build your Immunity to Cyberthreats
 
Cognitive Security Case Study
Cognitive Security Case StudyCognitive Security Case Study
Cognitive Security Case Study
 
Dr K Subramanian
Dr K SubramanianDr K Subramanian
Dr K Subramanian
 
Dit yvol4iss40
Dit yvol4iss40Dit yvol4iss40
Dit yvol4iss40
 
IBM Security Strategy Intelligence,
IBM Security Strategy Intelligence,IBM Security Strategy Intelligence,
IBM Security Strategy Intelligence,
 
From reactive to automated reducing costs through mature security processes i...
From reactive to automated reducing costs through mature security processes i...From reactive to automated reducing costs through mature security processes i...
From reactive to automated reducing costs through mature security processes i...
 
The 10 most trusted companies in enterprise security for dec 2017
The 10 most trusted companies in enterprise security for dec 2017The 10 most trusted companies in enterprise security for dec 2017
The 10 most trusted companies in enterprise security for dec 2017
 
IT Position of Trust Designation
IT Position of Trust DesignationIT Position of Trust Designation
IT Position of Trust Designation
 
Security Awareness Training
Security Awareness TrainingSecurity Awareness Training
Security Awareness Training
 
Presentation cloud security the grand challenge
Presentation   cloud security the grand challengePresentation   cloud security the grand challenge
Presentation cloud security the grand challenge
 
The importance of information security nowadays
The importance of information security nowadaysThe importance of information security nowadays
The importance of information security nowadays
 
Looking into the future of security
Looking into the future of securityLooking into the future of security
Looking into the future of security
 

En vedette

OS Database Security Chapter 6
OS Database Security Chapter 6OS Database Security Chapter 6
OS Database Security Chapter 6AfiqEfendy Zaen
 
Telenet | Change & the brain
Telenet | Change & the brain Telenet | Change & the brain
Telenet | Change & the brain The Tipping Point
 
23 network security threats pkg
23 network security threats pkg23 network security threats pkg
23 network security threats pkgUmang Gupta
 
Customer Touchpoint Mapping
Customer Touchpoint MappingCustomer Touchpoint Mapping
Customer Touchpoint MappingYear of the X
 
Touch Point Wheel - 3 FEB 2011
Touch Point Wheel - 3 FEB 2011Touch Point Wheel - 3 FEB 2011
Touch Point Wheel - 3 FEB 2011Niels van Maaren
 
Touchpoints: a Customer Experience Story | MCorp Consulting
Touchpoints: a Customer Experience Story | MCorp ConsultingTouchpoints: a Customer Experience Story | MCorp Consulting
Touchpoints: a Customer Experience Story | MCorp ConsultingMichael Hinshaw, CEO McorpCX
 
Touchpoint Dashboard Journey Mapping Guide 2014
Touchpoint Dashboard Journey Mapping Guide 2014Touchpoint Dashboard Journey Mapping Guide 2014
Touchpoint Dashboard Journey Mapping Guide 2014Touchpoint Dashboard
 

En vedette (8)

OS Database Security Chapter 6
OS Database Security Chapter 6OS Database Security Chapter 6
OS Database Security Chapter 6
 
Telenet | Change & the brain
Telenet | Change & the brain Telenet | Change & the brain
Telenet | Change & the brain
 
23 network security threats pkg
23 network security threats pkg23 network security threats pkg
23 network security threats pkg
 
Customer Touchpoint Mapping
Customer Touchpoint MappingCustomer Touchpoint Mapping
Customer Touchpoint Mapping
 
Touch Point Wheel - 3 FEB 2011
Touch Point Wheel - 3 FEB 2011Touch Point Wheel - 3 FEB 2011
Touch Point Wheel - 3 FEB 2011
 
Touchpoints: a Customer Experience Story | MCorp Consulting
Touchpoints: a Customer Experience Story | MCorp ConsultingTouchpoints: a Customer Experience Story | MCorp Consulting
Touchpoints: a Customer Experience Story | MCorp Consulting
 
Touchpoint Dashboard Journey Mapping Guide 2014
Touchpoint Dashboard Journey Mapping Guide 2014Touchpoint Dashboard Journey Mapping Guide 2014
Touchpoint Dashboard Journey Mapping Guide 2014
 
Training For Assessor
Training For AssessorTraining For Assessor
Training For Assessor
 

Similaire à Security solutions for a smarter planet

Smart security solutions for SMBs
Smart security solutions for SMBsSmart security solutions for SMBs
Smart security solutions for SMBsJyothi Satyanathan
 
Ibm security overview 2012 jan-18 sellers deck
Ibm security overview 2012 jan-18 sellers deckIbm security overview 2012 jan-18 sellers deck
Ibm security overview 2012 jan-18 sellers deckArrow ECS UK
 
Don't risk it presentation
Don't risk it presentationDon't risk it presentation
Don't risk it presentationVincent Kwon
 
Security Intelligence: Finding and Stopping Attackers with Big Data Analytics
Security Intelligence: Finding and Stopping Attackers with Big Data AnalyticsSecurity Intelligence: Finding and Stopping Attackers with Big Data Analytics
Security Intelligence: Finding and Stopping Attackers with Big Data AnalyticsIBM Security
 
Security for the IoT - Report Summary
Security for the IoT - Report SummarySecurity for the IoT - Report Summary
Security for the IoT - Report SummaryAccenture Technology
 
Maloney slides
Maloney slidesMaloney slides
Maloney slidesOnkar Sule
 
Mobility Security - A Business-Centric Approach
Mobility Security - A Business-Centric ApproachMobility Security - A Business-Centric Approach
Mobility Security - A Business-Centric ApproachOmar Khawaja
 
The ROI on Intrusion Prevention: Protecting Both Your Network & Investment
The ROI on Intrusion Prevention: Protecting Both Your Network & InvestmentThe ROI on Intrusion Prevention: Protecting Both Your Network & Investment
The ROI on Intrusion Prevention: Protecting Both Your Network & InvestmentIBM Security
 
IBM Security Products: Intelligence, Integration, Expertise
IBM Security Products: Intelligence, Integration, ExpertiseIBM Security Products: Intelligence, Integration, Expertise
IBM Security Products: Intelligence, Integration, ExpertiseShwetank Jayaswal
 
Information protection and compliance
Information protection and complianceInformation protection and compliance
Information protection and complianceDean Iacovelli
 
Cy Cops Company Presentation
Cy Cops Company PresentationCy Cops Company Presentation
Cy Cops Company PresentationChaitanyaS
 
Software security, secure software development in the age of IoT, smart thing...
Software security, secure software development in the age of IoT, smart thing...Software security, secure software development in the age of IoT, smart thing...
Software security, secure software development in the age of IoT, smart thing...LabSharegroup
 
Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...
Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...
Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...Andris Soroka
 
Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...
Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...
Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...Sirius
 
Maloney Slides
Maloney SlidesMaloney Slides
Maloney Slidesecommerce
 
The Charter of Trust
The Charter of TrustThe Charter of Trust
The Charter of TrustDefCamp
 
Securing the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the InternetSecuring the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the Internetaccenture
 
Securing the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the InternetSecuring the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the Internetaccenture
 

Similaire à Security solutions for a smarter planet (20)

Smart security solutions for SMBs
Smart security solutions for SMBsSmart security solutions for SMBs
Smart security solutions for SMBs
 
Ibm security overview 2012 jan-18 sellers deck
Ibm security overview 2012 jan-18 sellers deckIbm security overview 2012 jan-18 sellers deck
Ibm security overview 2012 jan-18 sellers deck
 
Don't risk it presentation
Don't risk it presentationDon't risk it presentation
Don't risk it presentation
 
Security Intelligence: Finding and Stopping Attackers with Big Data Analytics
Security Intelligence: Finding and Stopping Attackers with Big Data AnalyticsSecurity Intelligence: Finding and Stopping Attackers with Big Data Analytics
Security Intelligence: Finding and Stopping Attackers with Big Data Analytics
 
Security for the IoT - Report Summary
Security for the IoT - Report SummarySecurity for the IoT - Report Summary
Security for the IoT - Report Summary
 
Maloney slides
Maloney slidesMaloney slides
Maloney slides
 
Mobility Security - A Business-Centric Approach
Mobility Security - A Business-Centric ApproachMobility Security - A Business-Centric Approach
Mobility Security - A Business-Centric Approach
 
The ROI on Intrusion Prevention: Protecting Both Your Network & Investment
The ROI on Intrusion Prevention: Protecting Both Your Network & InvestmentThe ROI on Intrusion Prevention: Protecting Both Your Network & Investment
The ROI on Intrusion Prevention: Protecting Both Your Network & Investment
 
IBM Security Products: Intelligence, Integration, Expertise
IBM Security Products: Intelligence, Integration, ExpertiseIBM Security Products: Intelligence, Integration, Expertise
IBM Security Products: Intelligence, Integration, Expertise
 
CCA study group
CCA study groupCCA study group
CCA study group
 
Information protection and compliance
Information protection and complianceInformation protection and compliance
Information protection and compliance
 
Cy Cops Company Presentation
Cy Cops Company PresentationCy Cops Company Presentation
Cy Cops Company Presentation
 
Software security, secure software development in the age of IoT, smart thing...
Software security, secure software development in the age of IoT, smart thing...Software security, secure software development in the age of IoT, smart thing...
Software security, secure software development in the age of IoT, smart thing...
 
Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...
Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...
Data Security Solutions - Cyber Security & Security Intelligence - @ Lithuani...
 
Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...
Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...
Security Incident and Event Management (SIEM) - Managed and Hosted Solutions ...
 
Presentación AMIB Los Cabos
Presentación AMIB Los CabosPresentación AMIB Los Cabos
Presentación AMIB Los Cabos
 
Maloney Slides
Maloney SlidesMaloney Slides
Maloney Slides
 
The Charter of Trust
The Charter of TrustThe Charter of Trust
The Charter of Trust
 
Securing the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the InternetSecuring the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the Internet
 
Securing the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the InternetSecuring the Digital Economy: Reinventing the Internet
Securing the Digital Economy: Reinventing the Internet
 

Plus de Vincent Kwon

Smarter Eduction - Higher Education Summit 2011 - D Watt
Smarter Eduction - Higher Education Summit 2011 - D WattSmarter Eduction - Higher Education Summit 2011 - D Watt
Smarter Eduction - Higher Education Summit 2011 - D WattVincent Kwon
 
Paul croft - Auckland Cloud Camp 2010
Paul croft  - Auckland Cloud Camp 2010Paul croft  - Auckland Cloud Camp 2010
Paul croft - Auckland Cloud Camp 2010Vincent Kwon
 
Derek wilson - Cloud Camp 2011
Derek wilson - Cloud Camp 2011Derek wilson - Cloud Camp 2011
Derek wilson - Cloud Camp 2011Vincent Kwon
 
The unprecedented state of web insecurity
The unprecedented state of web insecurityThe unprecedented state of web insecurity
The unprecedented state of web insecurityVincent Kwon
 
Capitalising on Complexity - Ross Pearce
Capitalising on Complexity - Ross PearceCapitalising on Complexity - Ross Pearce
Capitalising on Complexity - Ross PearceVincent Kwon
 
IBM Maximo for Utilities
IBM Maximo for UtilitiesIBM Maximo for Utilities
IBM Maximo for UtilitiesVincent Kwon
 
IBM 'After 5' Session - IBM System X
IBM 'After 5' Session - IBM System XIBM 'After 5' Session - IBM System X
IBM 'After 5' Session - IBM System XVincent Kwon
 
VMWare Sponsor Presentation: Accelerating the journey to cloud
VMWare Sponsor Presentation: Accelerating the journey to cloudVMWare Sponsor Presentation: Accelerating the journey to cloud
VMWare Sponsor Presentation: Accelerating the journey to cloudVincent Kwon
 
Turn data into intelligence: Uncover insights. Take action
Turn data into intelligence: Uncover insights. Take actionTurn data into intelligence: Uncover insights. Take action
Turn data into intelligence: Uncover insights. Take actionVincent Kwon
 
Keynote intelligence, innovation & best practice
Keynote    intelligence, innovation & best practiceKeynote    intelligence, innovation & best practice
Keynote intelligence, innovation & best practiceVincent Kwon
 
It optimisation & virtualisation
It optimisation & virtualisationIt optimisation & virtualisation
It optimisation & virtualisationVincent Kwon
 
Enhanced business performance
Enhanced business performanceEnhanced business performance
Enhanced business performanceVincent Kwon
 
Drive business performance with information analytics
Drive business performance with information analyticsDrive business performance with information analytics
Drive business performance with information analyticsVincent Kwon
 
Cloud computing (2)
Cloud computing (2)Cloud computing (2)
Cloud computing (2)Vincent Kwon
 
Acclerating jounrey to cloud computing
Acclerating jounrey to cloud computingAcclerating jounrey to cloud computing
Acclerating jounrey to cloud computingVincent Kwon
 
Gen-i: Business Continuity considering reputation, security and virtualisation
Gen-i: Business Continuity considering reputation, security and virtualisationGen-i: Business Continuity considering reputation, security and virtualisation
Gen-i: Business Continuity considering reputation, security and virtualisationVincent Kwon
 
Wellington Business Keynote - Paul Callaghan
Wellington Business Keynote - Paul CallaghanWellington Business Keynote - Paul Callaghan
Wellington Business Keynote - Paul CallaghanVincent Kwon
 
VMware vSphere 4.0: The best platform for business applications
VMware vSphere 4.0: The best platform for business applicationsVMware vSphere 4.0: The best platform for business applications
VMware vSphere 4.0: The best platform for business applicationsVincent Kwon
 
WebSphere BlueWorks - how to build your business process models using free IB...
WebSphere BlueWorks - how to build your business process models using free IB...WebSphere BlueWorks - how to build your business process models using free IB...
WebSphere BlueWorks - how to build your business process models using free IB...Vincent Kwon
 

Plus de Vincent Kwon (20)

Smarter Eduction - Higher Education Summit 2011 - D Watt
Smarter Eduction - Higher Education Summit 2011 - D WattSmarter Eduction - Higher Education Summit 2011 - D Watt
Smarter Eduction - Higher Education Summit 2011 - D Watt
 
Paul croft - Auckland Cloud Camp 2010
Paul croft  - Auckland Cloud Camp 2010Paul croft  - Auckland Cloud Camp 2010
Paul croft - Auckland Cloud Camp 2010
 
Derek wilson - Cloud Camp 2011
Derek wilson - Cloud Camp 2011Derek wilson - Cloud Camp 2011
Derek wilson - Cloud Camp 2011
 
The unprecedented state of web insecurity
The unprecedented state of web insecurityThe unprecedented state of web insecurity
The unprecedented state of web insecurity
 
Capitalising on Complexity - Ross Pearce
Capitalising on Complexity - Ross PearceCapitalising on Complexity - Ross Pearce
Capitalising on Complexity - Ross Pearce
 
IBM Maximo for Utilities
IBM Maximo for UtilitiesIBM Maximo for Utilities
IBM Maximo for Utilities
 
IBM 'After 5' Session - IBM System X
IBM 'After 5' Session - IBM System XIBM 'After 5' Session - IBM System X
IBM 'After 5' Session - IBM System X
 
VMWare Sponsor Presentation: Accelerating the journey to cloud
VMWare Sponsor Presentation: Accelerating the journey to cloudVMWare Sponsor Presentation: Accelerating the journey to cloud
VMWare Sponsor Presentation: Accelerating the journey to cloud
 
Turn data into intelligence: Uncover insights. Take action
Turn data into intelligence: Uncover insights. Take actionTurn data into intelligence: Uncover insights. Take action
Turn data into intelligence: Uncover insights. Take action
 
Keynote intelligence, innovation & best practice
Keynote    intelligence, innovation & best practiceKeynote    intelligence, innovation & best practice
Keynote intelligence, innovation & best practice
 
It optimisation & virtualisation
It optimisation & virtualisationIt optimisation & virtualisation
It optimisation & virtualisation
 
Enhanced business performance
Enhanced business performanceEnhanced business performance
Enhanced business performance
 
Drive business performance with information analytics
Drive business performance with information analyticsDrive business performance with information analytics
Drive business performance with information analytics
 
Cloud computing
Cloud computingCloud computing
Cloud computing
 
Cloud computing (2)
Cloud computing (2)Cloud computing (2)
Cloud computing (2)
 
Acclerating jounrey to cloud computing
Acclerating jounrey to cloud computingAcclerating jounrey to cloud computing
Acclerating jounrey to cloud computing
 
Gen-i: Business Continuity considering reputation, security and virtualisation
Gen-i: Business Continuity considering reputation, security and virtualisationGen-i: Business Continuity considering reputation, security and virtualisation
Gen-i: Business Continuity considering reputation, security and virtualisation
 
Wellington Business Keynote - Paul Callaghan
Wellington Business Keynote - Paul CallaghanWellington Business Keynote - Paul Callaghan
Wellington Business Keynote - Paul Callaghan
 
VMware vSphere 4.0: The best platform for business applications
VMware vSphere 4.0: The best platform for business applicationsVMware vSphere 4.0: The best platform for business applications
VMware vSphere 4.0: The best platform for business applications
 
WebSphere BlueWorks - how to build your business process models using free IB...
WebSphere BlueWorks - how to build your business process models using free IB...WebSphere BlueWorks - how to build your business process models using free IB...
WebSphere BlueWorks - how to build your business process models using free IB...
 

Dernier

business environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxbusiness environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxShruti Mittal
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxmbikashkanyari
 
BAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxBAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxran17april2001
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFChandresh Chudasama
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataExhibitors Data
 
Jewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreJewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreNZSG
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationAnamaria Contreras
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdfShaun Heinrichs
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMVoces Mineras
 
Darshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfDarshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfShashank Mehta
 
Send Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.comSendBig4
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdfChris Skinner
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckHajeJanKamps
 
Appkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptxAppkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptxappkodes
 
How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...
How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...
How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...Hector Del Castillo, CPM, CPMM
 
Onemonitar Android Spy App Features: Explore Advanced Monitoring Capabilities
Onemonitar Android Spy App Features: Explore Advanced Monitoring CapabilitiesOnemonitar Android Spy App Features: Explore Advanced Monitoring Capabilities
Onemonitar Android Spy App Features: Explore Advanced Monitoring CapabilitiesOne Monitar
 
Entrepreneurship lessons in Philippines
Entrepreneurship lessons in  PhilippinesEntrepreneurship lessons in  Philippines
Entrepreneurship lessons in PhilippinesDavidSamuel525586
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfRbc Rbcua
 

Dernier (20)

business environment micro environment macro environment.pptx
business environment micro environment macro environment.pptxbusiness environment micro environment macro environment.pptx
business environment micro environment macro environment.pptx
 
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptxThe-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
The-Ethical-issues-ghhhhhhhhjof-Byjus.pptx
 
BAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptxBAILMENT & PLEDGE business law notes.pptx
BAILMENT & PLEDGE business law notes.pptx
 
Guide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDFGuide Complete Set of Residential Architectural Drawings PDF
Guide Complete Set of Residential Architectural Drawings PDF
 
NAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors DataNAB Show Exhibitor List 2024 - Exhibitors Data
NAB Show Exhibitor List 2024 - Exhibitors Data
 
Jewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource CentreJewish Resources in the Family Resource Centre
Jewish Resources in the Family Resource Centre
 
PSCC - Capability Statement Presentation
PSCC - Capability Statement PresentationPSCC - Capability Statement Presentation
PSCC - Capability Statement Presentation
 
1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf1911 Gold Corporate Presentation Apr 2024.pdf
1911 Gold Corporate Presentation Apr 2024.pdf
 
Memorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQMMemorándum de Entendimiento (MoU) entre Codelco y SQM
Memorándum de Entendimiento (MoU) entre Codelco y SQM
 
Darshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdfDarshan Hiranandani [News About Next CEO].pdf
Darshan Hiranandani [News About Next CEO].pdf
 
Send Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.comSend Files | Sendbig.com
Send Files | Sendbig.comSend Files | Sendbig.com
 
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
20220816-EthicsGrade_Scorecard-JP_Morgan_Chase-Q2-63_57.pdf
 
Pitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deckPitch Deck Teardown: Xpanceo's $40M Seed deck
Pitch Deck Teardown: Xpanceo's $40M Seed deck
 
Appkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptxAppkodes Tinder Clone Script with Customisable Solutions.pptx
Appkodes Tinder Clone Script with Customisable Solutions.pptx
 
WAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdfWAM Corporate Presentation April 12 2024.pdf
WAM Corporate Presentation April 12 2024.pdf
 
How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...
How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...
How Generative AI Is Transforming Your Business | Byond Growth Insights | Apr...
 
Onemonitar Android Spy App Features: Explore Advanced Monitoring Capabilities
Onemonitar Android Spy App Features: Explore Advanced Monitoring CapabilitiesOnemonitar Android Spy App Features: Explore Advanced Monitoring Capabilities
Onemonitar Android Spy App Features: Explore Advanced Monitoring Capabilities
 
Entrepreneurship lessons in Philippines
Entrepreneurship lessons in  PhilippinesEntrepreneurship lessons in  Philippines
Entrepreneurship lessons in Philippines
 
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptxThe Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
The Bizz Quiz-E-Summit-E-Cell-IITPatna.pptx
 
APRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdfAPRIL2024_UKRAINE_xml_0000000000000 .pdf
APRIL2024_UKRAINE_xml_0000000000000 .pdf
 

Security solutions for a smarter planet

  • 1. Security Solutions for a Smarter Planet: IBM Directions in Security Jason Burn
  • 2. Welcome to the smarter planet 162 million Almost 162 million smart phones were sold in 2008, surpassing laptop sales for the first time. 90% Nearly 90% of innovation in automobiles is related to software and electronics systems. 1 trillion Soon, there will be 1 trillion connected devices in the world, constituting an “internet of things.” The planet is getting more Instrumented , Interconnected and Intelligent .
  • 3. Protection of sensitive and large volumes of data, shared globally Protection of sensors and actuators in the wild Protection of digital identities With the smarter planet opportunities come new security and privacy risks
  • 4. Additional security and privacy risks impacting customers Addressing compliance complexity Adoption of virtualization and cloud computing Addressing the new cyber threat landscape Expectation of privacy
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12. IBM Security Framework supports Integrated Service Management helping you assess and manage risk DATA AND INFORMATION Understand, deploy, and properly test controls for access to and usage of sensitive data PEOPLE AND IDENTITY Mitigate the risks associated with user access to corporate resources APPLICATION AND PROCESS Keep applications secure, protected from malicious or fraudulent use, and hardened against failure NETWORK, SERVER AND END POINT Optimize service availability by mitigating risks to network components PHYSICAL INFRASTRUCTURE Provide actionable intelligence on the desired state of physical infrastructure security and make improvements GOVERANCE, RISK MGMT AND COMPLIANCE Ensure comprehensive management of security activities and compliance with all security mandates GRC
  • 13. IBM security portfolio Overview = Professional Services = Products = Cloud-based & Managed Services Identity and Access Management Mainframe Security Virtual System Security Database Monitoring and Protection Encryption and Key Lifecycle Management App Vulnerability Scanning Access and Entitlement Management Web Application Firewall Data Loss Prevention App Source Code Scanning SOA Security Intrusion Prevention System Messaging Security Data Masking Infrastructure Security E-mail Security Application Security Web/URL Filtering Vulnerability Assessment Firewall, IDS/IPS, MFS Mgmt. Identity Management Data Security Access Management GRC Physical Security Security Governance, Risk and Compliance SIEM and Log Management Web / URL Filtering Security Event Management Threat Assessment
  • 14. How we add value: IBM leverages our skills to help meet your goals IBM has industry’s broadest Security Solutions portfolio IBM understands Security & Risk are business problems first, technical problems second IBM has deep industry expertise IBM has a huge ecosystem of leading security partners IBM has the client success stories to demonstrate results
  • 15. ONE voice for security . IBM SECURITY SOLUTIONS INNOVATIVE products and services . IBM SECURITY FRAMEWORK COMMITTED to the vision of a Secure Smarter Planet . SECURE BY DESIGN
  • 16.

Notes de l'éditeur

  1. At IBM we see change happening on a global scale. And we see an exciting transformation happening – we see organizations of all types making bold investments in new technologies and new processes that make them more efficient, more agile and more competitive. On a global scale, we see our world literally becoming a Smarter Planet – a planet that is ubiquitously instrumented, interconnected and intelligent. Instrumented, in that sensors are being embedded everywhere. From cars, to roads, to pipelines. Interconnected, in that soon there will be 2 billion people on the Internet and 4 billion mobile subscribers. And, we are seeing an explosion of machine-to-machine communications. Imagine a world with one trillion interconnected people and machines. That’s where our future lies. Intelligent, in that instrumentation and interconnection is causing a data explosion. Powerful new systems for analyzing and deriving insight from this data are providing the world with a new generation of intelligence. Intelligence that not only enables us to run our businesses better, but also helps us save energy, improve crop yields and reduce the impact of natural disasters. “ Smarter Planet” is not just a thought or idea from IBM, it is a vision for IBM and for our customers. It is about how we can work together to make the planet a better place to live, work and play.
  2. This higher level of analytics, intelligence and interconnectedness enable new possibilities, create new complexities, and begets new risks. Some of the risks that organizations worldwide and across sectors / verticals are likely to face in the near future include: Sensitive and a large volumes of data: By one estimate, the volume of created content will quintuple in the next two years – to more than 2.5 zettabytes. (A zettabyte is a 1 followed by 21 zeros.) Smarter Planet domains require more information aggregation and sharing across organizations than is usually found in IT domains, challenging our ability to protect the information and comply with restrictions on data use. Sensors and actuators In the wild: The risks associated with the failure to protect and secure sensor event data are far higher than the risks usually associated with IT event data. Digital identities: Today we use several authenticators – whether in the form of fingerprint scanners, government IDs, employee IDs, bank cards, mobile phones, etc. – to perform multiple functions during a single day. Protecting this information (PII) is critical and there is also the issue about the privacy implications related to the identity trail.
  3. New cyber threat landscape: According to the FBI, cybercrime is now more widespread than narcotics, and its techniques are evolving, its targeting becoming more focused. Adoption of virtualization and cloud computing: The digital and physical infrastructures of our world are increasingly merging, infusing our power grids, banking systems, retail supply chains and city streets with intelligence. Are we now exposing them to the same risks as our Web sites? Also with the growing dependence on smart (mobile) devices, organizations face a new breed of security threats that know no geographical boundaries. Compliance complexity: Depending on the industry, some organizations face multiple regulatory mandates regarding information security, privacy of non-public personal information, and post-data breach notification. If your organization is like most others worldwide, it’s a struggle to keep pace with regulatory mandates, especially given budget and manpower constraints.. Expectation of privacy: The average company’s computer infrastructure is attacked nearly 60,000 times every day. There have been 354 million reported data privacy breaches over the past five years in the US alone. Consumers expect vendors to take every measure possible to protect their personally identifiable information (PII) and privacy.
  4. With new computing models like cloud, we have expanded the ways we can consume computing. And we now have the capability, with advanced software analytic tools, to extract value from data… to see the patterns, the correlations and the outliers. Sophisticated mathematical models are helping us begin to anticipate, forecast and even predict changes in our systems. Not to be overlooked is the growing importance of security and privacy that consumers now expect from companies they do business with.
  5. Secure by Design is a cost-effective approach to constructing safe and reliable systems by applying IBM’s experience with security technologies and best practices in all phases of system creation, from conception through system design, construction and deployment. Being Secure by Design reduces the cost, risk, and unpredictability of integrating new technologies.
  6. This slide shows the diversity of possible events that could have a negative impact on your organization. Typically, the public sector tends to think about the upper two quadrants while the private sector predominantly looks at the lower two. But reality is that both sectors are potentially touched by any of the challenges listed here. Unfortunately, not all infrastructures can be protected from all threats. For example, it would be impossible to fence or guard an electricity transmission network or water delivery system. By applying risk management techniques, attention can be focused on areas of greatest risk, taking into account the prevalence of the threat, the existence of vulnerability, the existing level of protective security and the effectiveness of available mitigation strategies for continuity and sustainability and potential impact.
  7. There is no such thing as 100% security. There is no return without risk. Security involves trade-offs, with cost, complexity, effectiveness and user experience (or agility). To make the right trade-offs, organizations need to align IT security with their business objectives, allocate risk across domains, and enforce the appropriate security level in each area in light of business opportunities, threats, and vulnerabilities. This is business-driven security : orchestrating and fine-tuning security policies across the enterprise to maximize business success. The Pareto principle, often referred to as "the 80-20 rule," applies to IT controls. The principle states that for many phenomena, 80 percent of the consequences stem from 20 percent of the causes. The IT Process Institute (ITPI) conducted studies for 3 years of top performers that indicate IT audit and control related activities are not just a necessary cost, but actually improve operating performance and that a subset of foundational controls have the biggest impact on performance measures. With data on over 330 IT organizations, their analysis shows that a subset of the foundational controls analyzed predict 60% of the performance variation in the companies studied. (Note: For details on the 2006 and 2007 studies, see comments below.) Transition: Security leaders need a way to balance the pressures of managing cost, decreasing complexity, improving effectiveness and assuring agility . IBM can help. ********************************************************************************************* ITPI: IT Process Institute studies (additional details, if needed) 2006: IT Controls Performance Benchmark With the help of researchers from Carnegie Mellon University, Florida State University, and University of Oregon – ITPI analyzed the survey responses of 98 organizations and studied 63 COBIT controls and 25 performance measures. Key findings of this groundbreaking research suggested: - Best practices outlined in the ITIL and COBIT frameworks improve performance - 21 Foundational Controls have the biggest impact on performance measures - Organizations that use Foundational Controls have significantly higher performance Organizations that use Foundational Controls have: - 12% to 37% less unplanned work - 12% to 26% higher change success rate - 2.5 to 5.4 times higher server to system administrator ratio 2007: Updated IT Controls Performance Benchmark We have repeated our groundbreaking study of the impact IT controls on IT operating performance with funding from the Institute of Internal Auditors Research Foundation. Now, with data on over 330 IT organizations, our analysis shows that just 12 of the 53 controls analyzed predict 60% of the performance variation in the companies studied. We also conclude that process maturity is the key that unlocks performance improvement potential of these key IT control processes.
  8. As businesses try to deploy best practices, they find that there are often thousands of redundant controls to manage. So what are some of the foundational controls that are most important to the management of security in terms of getting a handle on environmental control? IBM has narrowed down the list to 7 security foundational controls (see definitions for these controls below) that are critical and provide the most return on your investment. These set of controls address risk at every layer of the enterprise: People and Identity; Data & Information; Application as well as Network, Server & Endpoint. For example: By managing identities, you can assure the right people have access to the right assets at the right time and for the right reason Of course one of the most important priorities facing organizations today is the need to protect as well as to assure business-critical data, whether it is intellectual property or customer data that is in transit or at rest across the lifecycle. Safeguarding the privacy of client data is not just a good business practice anymore - in many cases, it’s the law. Mandates such as the Health Insurance Portability and Accountability Act (HIPAA) as well as the Payment Card Industry Data Security Standard (PCI-DSS) among others, are prescriptive in terms of what is required of IT for security and risk control. As you glance at the controls listed on this slide, you will start to notice that they are interrelated to some degree. For example, there is a strong relationship between the controls that manage the integrity of sensitive data in databases and other information stores throughout the lifecycle and the controls for authentication and access to secure the data. Tied closely to these are controls for protecting the system infrastructure from new and emerging threats and for security information and event management. In addition to the integration between the controls, also note the synergies between the key controls and best practices in IT service management with processes related to change and configuration management, asset management, and problem and incident management. Beyond using key controls as a pragmatic approach to managing risk, I want to be sure to point out that these controls also support initiatives beyond security and help the business maintain its productivity, efficiency and reliability. An efficient set of controls not only provide more rapid understanding of the business impact of IT events, but allow businesses to take out potentially millions of dollars worth of costs through simplification and automation of manual processes. ******* Foundational Controls Definitions ******** Identity and Access Management: Process for assuring access to enterprise resources has been given to the right people, at the right time, for the right purpose Data and Information Protection: Capability that allows for granular, policy based protection of structured and unstructured data Release Management: Process for assuring efficiency and integrity of the software development lifecycle Change & Configuration Management: Process for assuring routine, emergency and out-of-band changes are made efficiently, and in such a manner as to prevent operational outages. Threat & Vulnerability Management: Process and capabilities designed to protect the enterprise infrastructure from new and emerging threats Problem & Incident Management: Automated workflow and Service Desk designed to assure incidents are escalated and addressed in a timely manner (with forensics teams ready to respond to an emergency) Security Information and Event Management: Automated log management to audit, monitor and report on security and compliance posture
  9. Certain regulations and standards are considered “global”, as they are applied uniformly throughout the world. These would include: PCI, ISO 27001, ITIL, BITS, and BASEL II. Other regulations and standards are considered “international”, such as EUDPD and the SOX variants, because they requirements may vary between countries and regions, and because they may originate in a single country or region, but have cross-border impact. The European Union Data Privacy Directive (EUDPD) is a mandate for the protection of the non-public personal information of all EU citizens. Member states are charged with creating country-specific regulations based upon the general mandate, which will specify restrictions on the use of nonpublic personal information (NPI) within the country, its exchange between EU member states, and its transfer to countries outside the Union. France and Germany reportedly have the most stringent regulations, in some cases not allowing NPI to be shared outside their own borders. Other regulations, such as the United Kingdom Data Protection Act (UKDPA), allow NPI to be shared within the EU with the consent of the data owners. Sharing of certain types of NPI is allowed between the EU and the US under the US Safe Harbor provisions. Many of the other control sets cross over into IT Management (for e.g., data backup/recovery processes, BCDR, post-breach notification requirements, physical facility security and education / awareness / training).
  10. There are 5 unique security focus areas in the Framework that we speak about and that we have organized our solutions around, each with their own value proposition and financial payback: People and Identity Mitigate the risks associated with user access to corporate resources Data and Information Understand, deploy and properly test controls for access to and usage of sensitive business data Application and Process Keep applications secure, protected from malicious or fraudulent use, and hardened against failure Network, Server and End Point Optimize service availability by mitigating risks to network components Physical Infrastructure Provide actionable intelligence on the desired state of physical infrastructure security and make improvements
  11. IBM Confidential ( Note to presenter: The purpose of this slide is to highlight that IBM offers the breadth and depth – unlike any other vendor -- with our security portfolio. The intent is not to engage in a technical discussion at this point or try to cover all areas in detail.) IBM has a unique position in the market as an end-to-end security provider – we can address virtually any dimension of a secure infrastructure – and provide the services and consulting to help customers develop a strategic approach to their security challenges. Across our portfolio, we provide many capabilities that help customers solve a wide range of security problems completely and in the process result in cutting costs , reducing complexity, and assuring compliance . So depending on the types of security risks that are impacting your business, we can look more closely at how we can help address those issues. (Note: There are customer reference examples in the back-up section of this presentation, if you need to highlight how we’re helping customers like DTCC by helping them make their applications more secure.) Notes to presenter: … Point out 1 or 2 capabilities mentioned on this slide and tie it back to a customer example to convey how we help clients meet their business requirements. You can replace reference to DTCC above with another customer reference. If there is interest in a certain domain (i.e., people and identity, application and process, etc.), use some of the backup slides that provide the next level of information on our offerings – including how we can help (1) assess the situation, (2) mitigate or decrease the risk and (3) monitor and manage the risk ongoing. In presentation mode, you can click on the icons displayed on the left hand side of the capabilities boxes to quickly navigate to the appropriate backup slide. Note to presenter: Keep in mind that customers often usually jump in at the wrong point so they may not have completely addressed all security risks. At times they buy something they don’t understand (aka shelfware)… they implement a security solution but forget the need to monitor it ongoing or to invest in training and awareness for a more security aware culture. What this means to you is that even if a customer already has a solution in place… it’s not the end of the story. They may still need services to optimize, or managed services to monitor – for example: Consolidate identity management with Tivoli Identity Manager Work with multiple identity repositories with Tivoli Federated Identity Manager Improve employee productivity with Tivoli Enterprise Single Sign On Protect data center media with STG tape encryption Protect data using zSeries encryption and Lotus Notes encryption Find and remediate application vulnerabilities with Rational app scan Assure privacy compliance with Rational Policy Tester Locate and remediate Malware with ISS IPS Manage incidents with ISS X-Force Emergency Response Services
  12. We believe that no other company is in a better position to assess our clients’ security needs, provide solutions and ensure those solutions are successfully implemented . Why? Because: We have the skills – IBM has X-Force* to understand and remediate threats, and thousands of researchers, developers, consultants and subject matter experts on security initiatives We know how – we have consulted on, and implemented thousands of security projects, so we have the practical expertise in best practices, processes, ROI and we care about our clients’ success We get the big picture – from security strategy and governance to security across mainframes, desktops, networks, pervasive computing and more We know our customers industries – IBM has industry expertise and tailors security solutions to industry vertical challenges – IBM consults on and helps secure business processes We live it – we manage security and privacy for our 400,000 employees worldwide, and our services teams manage more than 7 billion security “events” every day for clients We can prove it – IBM has been providing IT security for 30+ years. We have over 200 security references and more than 50 published case studies We have an ecosystem – IBM has a large business partner community that complements and implements our solutions We can help you choose – IBM Security Services assessors can provide a list of IBM and non-IBM products to assist clients in creating the best solution for their environment