| Endpoint and Device Discovery: Identify all endpoints on the network, all devices ever connected to these endpoints (servers, desktops, laptops, etc.), and support both active device scanners for unmanaged endpoints as well as continuous discovery of device connections via managed endpoints. |
Ensures Security and Regulation Compliance
- Allows the organization to identify all endpoints (managed and unmanaged) as well as all devices that are currently or have ever been connected to these endpoints.
- Understand the breadth of endpoints and devices being used across the organization.
- Gain insight into the use of removable devices / media and data usage.
- Lay the foundation for the development of a comprehensive Data Protection posture in compliance with internal security policy and external regulations / standards.
|
| Data Loss Mitigation: Assess device and data usage, including what device, on what machine, by which user, and when; ability to explore by: unique device, device type, device vendor, users and user groups, machines, hours of operation, and more. |
Secures Data from Data Leakage/Theft
- Provides the organization with information on usage of all removable devices (e.g., USB memory drives) and media (e.g., CDs/DVDs) by user, machine and time.
- Prevent malicious and/or unintentional data transfer to removable devices / media.
- Ensure data is encrypted and secure when on removable devices / media.
|
| Data Protection Security Policy: Define security policy with global and user- and/or machine-specific rules based on specific organizational needs using a “whitelist” approach. |
Increases Data Security
- Organizations can implement global data protection policies with the flexibility to make exceptions as needed by defining what devices and media may connect to the network and what users (or user groups) may do with them.
- Create a whitelist of allowable devices at any level of granularity: at device class (e.g., all UFDs), device group, device model and/or even specific ID levels.
- Define forced encryption policy for data flows onto removable devices / media.
- Define data transfer policy elements, including: copy limits, scheduling per user or user group, and file type.
|
| Security Policy Enforcement: Automated enforcement of your data and device usage policies across your entire network, and of your encryption policy for sensitive data flowing onto removable devices / media. |
Increases Security Compliance
- Permits organizations to automate the enforcement of their data protection security policy at any level of granularity needed
- Flexible enforcement by user (or user group), machine (or group), device / media, file type, time of day, and more.
- Control of data transfers to removable devices / media (inbound / outbound), including port access.
- Flexible encryption options, using AES-256 standard ciphering.
- Policies can be updated and enforced whether endpoint is on- or off-line.
|
| Audit and Compliance: Automatic logging of all network events related to your Data Protection policy, including endpoint status, device connection, user activity (such as data transfers), and file tracking (including full content shadowing), providing visibility into policy compliance and violations. All log information is compliant with Syslog protocols. |
Ensures Audit Readiness
- Organizations can monitor and report on all relevant network events, and be prepared for compliance audits and/or forensics using standard and customizable reports.
- Monitor all user activity such as device usage and data transfers.
- Report on all device / media and data security policy compliance and violations.
- Use patented bi-directional file shadowing to track all transferred files (or even file content).
- Easy access to all information needed for compliance audits and forensics.
- Show potential impact presented by unauthorized devices.
- Enables integrated event management to lower administrative costs and provide more alerting and reporting options.
|
| Flexible / Scalable / Secure Design: Provide organization-wide control and enforcement using scalable client-server architecture with a central database which facilitates load balancing and distributed control. Install tamper-proof agents on every endpoint on the network, and protect against unauthorized removal. Fully support both Windows Active Directory and Novell eDirectory / NDS structure. |
Adapts to Your Growing Business
- Supports any sized organization, from small, local startups to large, global corporations, from hundreds of endpoints to hundreds of thousand endpoints; fast growing organizations can scale installation as needs dictate.
- Protects endpoints from unintentional and/or malicious tampering; maintains endpoint security posture even in dire events.
- Leverages existing directory information when enforcing policies; reduces admin workload; reduces setup / startup / ramp up time.
- Optimized database reduces footprint, increases query speeds and improves maintenance for lower administration costs.
- Supports virtualized server configurations for server-side cost reduction and “green” initiatives.
|