Components of a secure IT and communication infrastructure
INTERNET / EXTRANET / INTRANET
- Client and Mobile Security: protection against malware, host firewalls and IDS/IPS, strong authentication, hard disc encryption, secure communication
- Secure Connections to Partner Sites and Subsidiaries: site-to-site VPN through mesh or hub-and-spoke architectures
- Desktop Protection and User Awareness: protection against malware, host firewalls and IDS/IPS, strong authentication, hard disc/file encryption
- Data exchange platform: easy and secure information and data exchange with different business partners
NETWORK ZONES and DMZ SECURITY
- Secure E-Mail and Data Exchange: centralized encryption of e-mails on a mail gateway and/or the user mail clients.
Data exchange platforms for secure exchange of confidential files with partners and/or mobile users.
- WES – Web Entry Security for Internet and E-Commerce Services: secure proxies with authentication enforcement based upon different authentication schemes supported by XML firewalls and header filters.
- IAM – Identity and Access Management: authentication platforms in combination with a uniform identity management.
- Network Zoning, DMZ and Transport Security: flexible and scalable network architectures with secure zones in internet and perimeters.
- Traffic Content Inspection and Intrusion Prevention: protection against malware and hackers through malware filters, URL filters, intrusion detection and intrusion prevention systems (IDS/IPS) based upon proxy or bridge.
BUSINESS and CORE APPLICATIONS
- Directories and Identity Management: Centralized management of digital identities, their credentials, roles and attributes through identity management systems and the associated directory services.
- PKI – Public Key Infrastructure: issuing and management of digital certificates, Smart Cards and other tokens through PKI systems in co-operation with IAM systems.
- Access Control and Protection of Business Applications: protection of company applications through authentication platforms in co-operation with IAM systems and network/host firewalls.
- Database Encryption and Protection: protection of data base contents through encryption, access control and hardware security modules (HSM) for secure key management.
SECURITY MANAGEMENT
- Vulnerability and Patch Management: system security monitoring and control with reference to current threats posed by malware and exploits.
- SIEM – Security Information and Event Management: collection and correlation of log data. System and application status monitoring and alerting
- Configuration and Security Management: centralized IT security infrastructure management.