|
RSA Draws Bead on FISMA Compliance with
Cloud Security Solution
August 31, 2010
The
RSA Solution for Cloud Security and Compliance manages security, risk
and regulatory compliance of cloud infrastructures, helping increase
customer confidence to virtualize business-critical applications.
"Security is a top concern organizations have about moving critical
business applications to the cloud," said Jon Oltsik, Principal Analyst
at the Enterprise Strategy Group. "Even with all the benefits cloud
computing provides, CIOs will continue to be wary until there is a way
to manage security and compliance with the same level of assurance that
is available today with physical data center environments. With today’s
announcement, EMC has made an important first step in addressing this
fundamental concern with security in today’s growing virtualized and
cloud infrastructures.”
Featuring an easy to use dashboard based on the RSA Archer eGRC
platform, the solution is designed to give organizations a complete
assessment of security and compliance posture across their VMware
virtual infrastructure. This allows customers to centrally manage
security across both virtual and physical infrastructures using RSA
Archer. The dashboard integrates with a library of more than 100
VMware-specific controls such as administrative authentication, that map
to the most current global regulations such as PCI-DSS and HIPAA to
ensure best practices for deployment. The solution also integrates with
the RSA enVision security information and event management platform to
provide a more comprehensive assessment of security events from across
the enterprise.
"Demonstrating compliance on virtualized platforms has been a
labor-intensive and highly complex process, particularly as many of our
customers require FISMA compliance," said Chris Day, Chief Security
Architect, Terremark Worldwide, a leading global provider of managed IT
infrastructure services. "We've given input throughout the design of the
RSA solution and fully support their shared vision with partners VMware
and Intel. Using the RSA Solution for Cloud Security and Compliance will
enhance our ability to assess the security of the virtual infrastructure
and help the customers that choose Terremark for their cloud
infrastructure respond to compliance audits."
RSA Solution for Cloud Security and Compliance
The RSA Solution for Cloud Security and Compliance helps enable
organizations to rationalize a multitude of compliance requirements,
control frameworks, standards and best practices into a set of
centralized security policies that can be applied to virtual
infrastructure. Simple dashboards are designed to make it easy to
visualize security and compliance posture. Through automated assessments
and simple workflows, the solution helps streamline the process of
managing tasks between security teams that define policies and IT
operations teams responsible for implementing those policies.
Capabilities delivered as part of the RSA solution include:
- Dashboard views
based on the RSA Archer eGRC platform designed to enable
fast and accurate assessment of security and compliance
posture across physical and VMware virtual infrastructure.
- Top-Down Visibility for
Control and Compliance: The RSA solution includes a
comprehensive, centralized library and ready reference of
security controls within the RSA Archer platform. This
library has been expanded to cover more than 100
VMware-specific controls that map the most current, global
regulations such as PCI-DSS and HIPAA. New software
available with RSA Archer automates the measurement of
several VMware configuration elements to simplify the task
of measuring compliance. RSA enVision is being enhanced to
add further intelligence to the RSA Archer platform by
updating the compliance assessments with security-relevant
events. RSA enVision collects security events from an
ecosystem of products including the RSA Data Loss Prevention
suite, VMware vShield, VMware vCloud Director, VMware
vCenter Configuration Manager, EMC Ionix, and HyTrust
appliance to enrich the compliance reports provided by the
RSA Archer platform.
- Process Automation for
Managing Remediation of Security Policies: The RSA
Solution for Cloud Security and Compliance leverages
automated workflow and notification processes in RSA Archer
to simplify the tasks of remediating security issues.
"Our customers are
excited about the opportunity to continue extending and optimizing their
use of virtualization but are hesitant unless they can deliver proof of
compliance against security standards such as PCI or HIPAA and VMware
best practices," said Bret Hartman, Chief Technology Officer of RSA, The
Security Division of EMC. "Today RSA is delivering the first step to
give customers both the capability and confidence to extend their VMware
deployments to handle business-critical applications while providing a
simpler and easier way to help ensure compliance for cloud
infrastructures."
The RSA Solution for Cloud Security and Compliance is the first in a
series of steps to deliver on the vision of security and compliance for
cloud infrastructure which EMC outlined at RSA Conference 2010 in
conjunction with key partners Intel and VMware.
At VMWorld 2010, Booth 1000, EMC will feature demonstrations of the RSA
Solution for Cloud Security and Compliance and will also show a
technology preview demonstration for how the solution will evolve in the
future to leverage VMware vSphere™ and Intel® Trusted Execution
Technology (Intel® TXT) to ensure hardware root of trust and isolation
of regulated workloads.
RSA is contributing actively in the Cloud Security Alliance (CSA)
Consensus Assessments Project for developing an open question-set, based
on the CSA Cloud Controls Matrix, for security assessment of cloud
services. When this work is complete, the RSA solution will be enhanced
to offer tenants a way to assess the security of cloud service provider
environments and their internal datacenters using RSA Archer.
"Intel
is working with VMware and EMC to enable a hardware-based root of trust
for the cloud," said Boyd Davis, Intel Vice President General Manager,
Data Center Group Marketing, "We're excited to see RSA taking the first
step in delivering products and solutions that support our shared
vision."
"Our collaboration with RSA is designed to help customers deploy cloud
environments that provide comprehensive security up and down the virtual
stack," said Parag Patel, vice president, Global Strategic Alliances,
VMware. "RSA's solution ties security controls to higher order
compliance objectives, including collecting and correlating security and
compliance events across the cloud infrastructure and key security
services delivered through VMware's vShield."
The RSA Solution for Cloud Security and Compliance and the RSA SecurBook
for solution deployment best practices will be available in Q4 2010. In
addition, strategic services from the RSA Security Practice of EMC
Consulting can guide customers on the approach best suited to their
business and operational objectives. |