IT风险管理和解决方案卜宪录Enterprise Solution ManagerCISSP CISA ISO27001LAAgenda1赛门铁克的IT风险管理报告2赛门铁克的IT风险管理解决方案3交流The Trusted Environment2Copyright©2007 SITC. All rights reserved1
IT风险管理日益重要•IT是许多业务运营和交易不可或缺的部分。•技术发展变化非常之快,IT风险也是如此。•识别、衡量、分析和管理IT 风险需要专门的知识和技能。The Trusted Environment3按照业务流程划分的IT风险The Trusted Environment4Copyright©2007 SITC. All rights reserved2
IT风险管理的三个手段PeopleIT风险管理TechnologyProcessThe Trusted Environment5不同角色对遵从IT风险的认识The Trusted Environment6Copyright©2007 SITC. All rights reserved3
技术的有效性The Trusted Environment7流程的有效性The Trusted Environment8Copyright©2007 SITC. All rights reserved4
流程与技术有效性对比The Trusted Environment9IT风险的4个来源The Trusted Environment10Copyright©2007 SITC. All rights reserved5
安全和可用性风险The Trusted Environment11性能和遵从性风险The Trusted Environment12Copyright©2007 SITC. All rights reserved6
赛门铁克面管理IT 风险遵从可用性确保充分有效控制保持系统正常运行实现自动证据收集确保业务迅速恢复IT 策略与自然灾害与外部法规系统故障信息IT基础设施内部与外部应用响应恶意威胁时间抵御恶意代码侵入优化系统资源保持重要信息流通确保正确配置安全性能The Trusted Environment13企业信息安全和策略遵从遵从确保充分有效控制实现自动证据收集IT 策略与外部法规信息IT基础设施内部与外部恶意威胁抵御恶意代码侵入保持重要信息流通安全The Trusted Environment14Copyright©2007 SITC. All rights reserved7
Security -基础架构安全及信息安全•针对恶意行为提供实时防护信息安全安全基础架构手机便携电脑台式电脑文件服务器应用服务器邮件服务器数据库服务器The Trusted Environment15分析、审计及法规遵从策略管理安全管理安全漏洞管理信息管理事件& 日志管理!i信息安全基础架构安全手机便携电脑台式电脑文件服务器应用服务器邮件服务器数据库服务器The Trusted Environment16Copyright©2007 SITC. All rights reserved8
Security ——基础架构安全策略管理安全管理安全漏洞管理信息管理事件& 日志管理!i信息安全基础架构安全手机便携电脑台式电脑文件服务器应用服务器邮件服务器数据库服务器The Trusted Environment17Symantec Client Security –完整的端点保护•统一的Agent:支持多种设备,防护多种恶意威胁•统一管理:集中的策略、事件和报告管理CrimewareSpyWareWormVirusWindowsSymbianLaptopDesktopSmartphoneDevicePCPCThe Trusted Environment18Copyright©2007 SITC. All rights reserved9
Symantec 端点策略遵从过程Step 1确定接入网络的端点配置Step 4持续监视遵从性✗Step 2遵从性检查Step 3Patch基于策略检查结果强制QuarantineVirtual DesktopThe Trusted Environment19Symantec Critical System Protection •Close back doors •Restrict apps & O/S (block ports)behaviors•Limit network •Protect systems from NetworkExploitconnectivity by buffer overflowapplicationProtectionPrevention•Intrusion prevention for •Restrict traffic flow day-zero attacksinbound and outboundSymantec Critical System Protection •Monitor logs, system •Lock down settings & user configuration & settingsauth for security •Enforce security policySystemAuditing &events•De-escalate user •Consolidate & forward ControlsAlertingprivilegeslogs for archival •Prevent removable •Smart event response media usefor quick actionThe Trusted Environment20Copyright©2007 SITC. All rights reserved10
Security ——信息安全策略管理安全管理安全漏洞管理信息管理事件& 日志管理!i信息安全基础架构安全ClientClientClientCritical SystemCritical SystemCl Systemritical SystemCriticaSecuritySecuritySecurityProtectionProtectionProtectionProtection手机便携电脑台式电脑文件服务器应用服务器邮件服务器数据库服务器The Trusted Environment21企业信息的存在形式•数据库中的结构化信息•电子邮件与文件服务器中的非结构化信息–源代码、员工和客户记录等文件服务器信息处理服务器数据库服务器The Trusted Environment22Copyright©2007 SITC. All rights reserved11
数据库系统的信息风险•保持所有SQL活动的跟踪–数据库服务器零开销SELECT Credit_Card, FROM CustomersAuditSQL 审计PoliciesFile ServerMessaging ServerDatabase ServerThe Trusted Environment23数据库系统的信息风险•探测来自内部或外部潜在的威胁–欺骗策略和历史交易信息SELECT Credit_Card, FROM CustomersFraud欺骗监测PoliciesAuditSQL 审计PoliciesDatabase ServerThe Trusted Environment24Copyright©2007 SITC. All rights reserved12
数据库系统的信息风险•监测机密信息的泄漏–基于策略SELECT Credit_Card, FROM CustomersExtrusionData LeakagePoliciesSymantecFraudDatabaseFraud DetectionPoliciesSecurityAuditSQL Audit TrailPoliciesFile ServerMessaging ServerDatabase ServerThe Trusted Environment25Security ——安全管理策略管理安全管理安全漏洞管理信息管理事件& 日志管理!i信息安全Database SecurityMail SecurityWeb Security基础架构安全ClientClientClientCritical SystemCritical SystemCritical SystemCritical SystemSecuritySecuritySecurityProtectionProtectionProtectionProtection手机便携电脑台式电脑文件服务器应用服务器邮件服务器数据库服务器The Trusted Environment26Copyright©2007 SITC. All rights reserved13
管理安全事件SSIM!!Help Desk10101010101010101010101i101010101010101010101011010101010101010101010110101010101010101010101ii10101010E10v10e10n10t101010110101M010a10n10a10g10e10d10101Legal Dept1010101010101010101010110101010101010101010101ii10101010&10 1L01o01g01010101101010S10e10c10u10r1i0t10y10101!10101010101010101010101!10101010101010101010101SecurityCompliance10101D01a01t0a10b101a01s0e1010110101S010e10r1v010101010101icesAnalysts1010101010101010101010110101010101010101010101Information SecurityClientWebMailDatabaseSecuritySecuritySecuritySecuritySecurity FoundationClientClientCrystemCritical SystemCritical Systemitical SCritical SystemNetworkClientSecurProtectionProtectionitySecurityProtectionProtectionSecuritySecurityCell PhoneLaptopDesktopFile ServerApplication ServerMessaging ServerDatabase ServerThe Trusted Environment27通过归档进行的信息管理1010101010101010101010110101010101010101010101101010101010101010101011010101归010101档01010101011010101010101010101010110101010101010101010101保存1010101010101010101010110101010101010101010101信息安全The Trusted Environment28Copyright©2007 SITC. All rights reserved14
归档:信息存储、保留和搜索Exchange9安全SMTP101010101010101010101019合理化Enterprise Vault101010101010101010101019保留t t法规遵从Lotus Notes101010101010101010101019过期处理存档应用10101010101010101010101itSharePoint9面向未来10101010101010101010101保存101010101010101010101019索引文件101010101010101010101019分类10101010101010101010101IIM数据搜索应用主存储二级存储三级存储The Trusted Environment29安全漏洞管理101010101010101010101011010101010101010101010110101010安10101全01010101011010101010101010101010110101010配10101置010101010110101010101010101010101101010数10101据0101库0101010110101010101010101010101信息安全安全基础架构手机便携电脑台式电脑文件服务器应用服务器信息处理服务器数据库服务器The Trusted Environment30Copyright©2007 SITC. All rights reserved15
确保系统遵从安全策略检测选择标准报告补救策略违反BindView/CCSESM包括I vrs siIixrclCIS、NSA …Covers Windows、UNIX、Linux、Oracle、SQL等的技术标准The Trusted Environment31Security ——全面的安全解决方案策略管理安全理安全漏洞管理信息管理事件& 日志管理!iBindViewSSIMEnterprise VaultESM信息安全Database SecurityMail SecurityWeb Security基础架构安全ClientClientClientCritical SystemCritical SystemCCritical Systemritical SystemSecuritySecuritySecurityProtectionProtectionProtectionProtection手机便携电脑台式电脑文件服务器应用服务器邮件服务器数据库服务器The Trusted Environment32Copyright©2007 SITC. All rights reserved16
管理IT风险–优化IT基础架构遵从可用性确保充分有效控制保持系统正常运行实现自动证据收集确保业务迅速恢复IT 策略与自然灾害与外部法规系统故障信息IT基础设施内部与外部应用响应恶意威胁时间抵御恶意代码侵入优化系统资源保持重要信息流通确保正确配置安全性能The Trusted Environment33数据中心基本部件数据库中间件应用网络存储服务器虚拟机器The Trusted Environment34Copyright©2007 SITC. All rights reserved17
数据中心的基础架构软件数据库中间件应用数据保护存储管理服务器管理应用性能 备份 文件系统 集群 调优建议 介质管理 卷管理 应用程序安装 告警 快照服务 复制服务 资源分配 故障根源分析 存档 多路径管理 配置管理 服务水平协议报告 资源管理网络存储服务器虚拟机器The Trusted Environment35数据中心复杂性所需的工具1012345678901234567890123456789+数据库中间件应用数据保护存储管理服务器管理应用性能NetWorkerECCSun SRMServiceGuardData ProtectorDLMAltirisAppManagerVantageGalaxyAppIQReiserFSSun ClusterEDMLVMClusterFrameOEMPathFinderArcServeNTCreekpathSAN NavigatorMSCS BackupSVMPolyservePatrolIntroscopeMedia MirrorOnHiCommandAperiHA-CMPTapASMGeoSpanFoglightJProbeDiskXtenderTPMShadowImageNetVaultMDTrueClusterUXQlustersDBArtisanSitrakaEmailXtenderSAN CopyInstantImageIBM TPM / TIOLiveVaultSVCSteelEyeDGIMOMTSMMirrorViewSnapViewBMCSyncSortLDMKickstartTopazPerformasureSAM-FSRetrRepliStorShadow CopyospectOCFSHP OpenViewN1 GridCCMSTivoliData MigratorTrueCopyFlashCopyCAUltrabacDFMHP UDCPACPatrolRSSDoubleTakeTimeFinderJumpstartTapewareUFSADS, SMSOptaneCorefirstNearStorePPRCExt3OpswareDLMZFSMarimbaSilkAppsightBrightStorSRDFSANFSBladelogicJFSTheGuardMobile BackupMPIOPowerPathGPTivoliFSeHealth网络存储服务器虚拟机器The Trusted Environment36Copyright©2007 SITC. All rights reserved18
赛门铁克数据中心基础构架数据库中间件应用赛门铁克数据中心基础构架VeritasVeritasVeritasVeritas3NetBackupStorage FoundationServer Foundationi—APM网络存储服务器虚拟机器The Trusted Environment37数据保护的转变-NBU无手自集可快备工动中恢速份备备自复恢份份动的复备备份份The Trusted Environment38Copyright©2007 SITC. All rights reserved19
存储管理的转变-Storage Foundation分集异统散中构一存存存管储储储理异构存储The Trusted Environment39服务器架构的转变-Server Foundation单主互N异机备备+构双/M主机并多机行机多双机机The Trusted Environment40Copyright©2007 SITC. All rights reserved20
应用性能管理的转变-I3升专工预级家具防式式式式性问问长能题题期优分分性化析析能监控The Trusted Environment413Symantec i方法提升性能INFORMINSIGHTEffective CommunicationInformationApplication Response Time SegmentationAlertingPerformanceKnowledgeClientNetworkWeb App DB StorageWarehouseServersServersServersReportingInformationINDEPTHDetailed Understanding of Technology ComponentsThe Trusted Environment42Copyright©2007 SITC. All rights reserved21
赛门铁克:全面管理IT 风险遵从可用性确保充分有效控制保持系统正常运行实现自动证据收集确保业务迅速恢复IT 策略与自然灾害与外部法规系统故障信息IT基础设施内部与外部应用响应恶意威胁时间抵御恶意代码侵入优化系统资源保持重要信息流通确保正确配置安全性能The Trusted Environment43赛门铁克与IT风险管理市场份额领先地位(全球,2005)FORRESTER WAVES: 领先厂商19安全软件市场第一(32%市场份额)企业级反间谍软件210安全内容管理市场第一(34%市场份额) 配置应用规划数据库管理311数据保护和恢复市场第一(45%市场份额) 信息归档软件产品412核心存储管理市场第一(30%市场份额) 企业级安全信息管理GARTNER 魔力象限: 领先厂商*“赛门铁克帮助我们保护IT环境,应对威胁5电子邮件主动归档的持续增长。我们需要一种解决方案能够6电子邮件安全分界促进企业运营进程而非阻碍其发展。我们7发现只有赛门铁克可以做到。”企业级防病毒8个人防火墙Robert Taylor, Fulton郡首席信息官The Trusted Environment44Copyright©2007 SITC. All rights reserved22
卜宪录Brian_Bu@ Solution ManagerCISSP CISA ISO27001LACopyright©2007 SITC. All rights reserved23