|
An effective application that reduces the internal security information risksA complex computer system requires a complex and effective protection directly proportional to it. The security system is influenced by several factors, the system is more vulnerable and at risk. All this shows that risks can be significantly reduced only by an IT security solution that takes account of patterns and activity of the company. The biggest risk is reflected in the authorized user. To ensure effective protection including information with utmost confidentiality is required close monitoring of the documents and processes that manage these data. Addressing the issue of computer security company is based on monitoring data streams. ISeeSec is a novel solution for effectively protecting the digital property. It is the key to consistently enforcing information security policies of organizations. ISee's special Behaviour Pattern Analysis technology allows for real time intervention, self-adaptive operation, and prevention. File protectionIndividual, group and organizational definitions are set up as to who is authorized to access what network and local files and directories in what way and at what time, and the mode and level of access is also controlled. ISeeSec is capable of blocking activities like file opening, printing, copy to clipboard or insertion into a file, saving as new file, or exporting into a different file format. Application protectionCentral definitions regulate who can launch which network or local applications at what time, and also control access modes and levels. Based on its proprietary software inventory ISeeSec continuously monitors - and if necessary - blocks running unlisted applications, such as launching new installations, or opening a file with a data management software not allowed by policy. Time spent on different applications is measured and logged. ISeeSec also monitors the security of the operating system, watches the soft spots regarding internal threatens. Output protectionISeeSec allows monitoring and managing activities for all input and output peripheries. Central definitions regulate who can write data to what peripheries (printer, CD, floppy, hard disk, etc.) at what time. ISeeSec logs keyboard punches and searches for keywords. Screen shots are forwarded to monitoring staff in a real time mode when an incident happens. E-mail activities are controlled, potentially not permitted addresses are identified, and attaching files are selectively permitted in case of using web-based (free) mailing systems. Main featuresBehavior patterns: Personalized protection profilesISeeSec allows for defining complex system rules, so called Behaviour Patterns for individuals, groups and organizations. Behaviour Patterns define the totality of individual user or group activities that are deviant or worth considering from the security point of view. ISeeSec includes an easy-to-use editing screen for profile definition. Automated procedures:Control hundreds of users ISeeSec has an own event description language that allows for creating full value automated operations. In practice, information security policy is engineered into complex sentences, elementary relations like 'if such and such OR such and such happens, do such and such'. Automated alert, intervention and prevention procedures enable a limited number of staff to control systems of high user numbers in a continuous manner. Reenactment:Who, what, how and when As defined in Behaviour Patterns, ISeeSec creates detailed logs of computer activities under protection. The log file is stored centrally in a Relational Database Management System, thus required tabulations; event flow re-enactments are created for later analysis. The system includes a special playback module where recorded screenshots are played, forwarded, rewound and enlarged just like on a VCR. How you benefit?ISeeSec makes areas of organizational and information security transparent and centrally managed that heretofore have been controlled only through paper based provisions, adherence to which lacked appropriate tools. The product is recommended for corporations and organizations that administer classified information in the following categories of secret:
|



