Feeds

Compuware aims to catch insiders

Staff still the big security weakpoint

  • alert
  • submit to reddit

Intelligent flash storage arrays

It is a sad, if well-known fact that the majority of security breaches in any business are the work of insiders. This is as true for IT security breaches as any other area, and finding out what has happened and who did it can be a tricky problem.

One answer is to be able to audit the activity of trusted users within a business, so it becomes possible to track not only who has had access to what application, but also what activities took place. This is the goal of the Application Auditing solution from Compuware, which is capable of providing detailed forensic information and audit reports. The toolset is based on the company’s Hiperstation mainframe security system, which is directly integrated with the mainframe operating system. Heavy transaction loads can be accommodated in this way, with some Hiperstation claimed to have recorded more than eight million transactions per day.

The system can have a wide range of uses, such as tracking users’ common work practices with applications so that workflow and operation can be improved. It is the security context, however, that is the primary target, and here it can provide indisputable proof of user actions that can be used to detect events that range from finding operational problems through to serious policy violations. In this context, it then gives the evidence needed to prevent incidents from becoming larger by catching up with the miscreants more quickly.

The company has indicated that, prior to the formalization of Application Auditing as an offering some of the tools have already been used to provide audit-based evidence in legal proceedings. ®

Providing a secure and efficient Helpdesk

More from The Register

next story
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
Google opens Inbox – email for people too thick to handle email
Print this article out and give it to someone tech-y if you get stuck
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
FTDI yanks chip-bricking driver from Windows Update, vows to fight on
Next driver to battle fake chips with 'non-invasive' methods
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Entity Framework goes 'code first' as Microsoft pulls visual design tool
Visual Studio database diagramming's out the window
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
New hybrid storage solutions
Tackling data challenges through emerging hybrid storage solutions that enable optimum database performance whilst managing costs and increasingly large data stores.