PGP Command Line Technology Overview
|
|
|
- Daisy Merritt
- 10 years ago
- Views:
Transcription
1 PGP White Paper June 2008 PGP Command Line Technology Overview Version 1.1
2 2 Table of Contents TABLE OF CONTENTS...2 EXECUTIVE SUMMARY...3 CHOOSING THE RIGHT SOLUTION...4 DATA: ALWAYS IN TRANSIT... 4 Session Encryption... 4 File Encryption... 4 A STANDARD SOLUTION APPROACH... 5 PGP Command Line... 5 REAL-LIFE USE CASES... 7 ACS... 7 Bertelsmann... 7 DeKalb Medical Center... 7 PHNS... 7 Rule Financial... 8 Texas State Bank... 8 SECURING AUTOMATED BUSINESS PROCESSES...8 GLOBALCPG CORPORATION... 8 DAILY TRANSMISSION TO EXTERNAL TRADING PARTNERS... 9 PGP Command Line Integration... 9 Scripting...10 INTERNAL NETWORK TRANSFER OF DAILY FINANCIAL RESULTS...10 PGP Command Line Integration...11 Scripting...11 TAPE BACKUP TRANSPORT TO OFFSITE STORAGE...12 PGP Command Line Integration...12 Scripting...13 DATA DISTRIBUTION TO PARTNERS WITHOUT ENCRYPTION SOFTWARE...15 PGP Command Line Integration...15 Scripting...16 CONCLUSION...17 Additional Resources...17
3 3 Executive Summary Data transfer and processing systems form the circulatory system of most organizations, exchanging large volumes of information between internal systems, suppliers, and customers. But legacy data transfer and processing systems are especially prone to security breaches because traditional file transfer and protocols have no built-in security. For organizations that must securely exchange large volumes of information, PGP Command Line can protect business-critical data easily and with little impact on existing systems. PGP Command Line can also be used to protect large volumes of information stored on servers and backup media from unauthorized access. This Technology Overview presents examples of ways that PGP Command Line can be used to encrypt data in automated business processes. The white paper is intended for IT managers and technical implementers who are responsible for developing, managing, and securing business processes. Sample scripts show how easily organizations can integrate PGP Command Line. If you have more complex requirements, PGP Corporation and its partners can help you plan the technology upgrade and guide you through the process.
4 4 Choosing the Right Solution Automated business processes that store and forward critical information are becoming more and more risky. Malicious code, hacks, and internal compromises can quickly turn a corporate asset into a liability. Whether mishandled, lost, stolen, or intercepted, data can become your worst enemy. Lost backup tapes, stolen computers, and misused privileges all represent common data security breaches. The rise in identity theft has turned these breaches from purely internal matters into incidents with significant financial and legal ramifications. Breaches are often widely publicized, hurting the organization s reputation; the TJX credit card breach that affected over 100 million accounts is just one example. 1 And the average cost of a compromised record is $197, according to a 2007 study 2. In other words, a privacy breach will reduce your organization s profits, may cost you your job, and could even mean the end of your organization itself. The risk of security breaches has led many organizations to reconsider how they handle data in transit and at rest. Data: Always In Transit Data is often described as in transit or at rest; however, this categorization is less than perfect. Data is almost always in transit, whether transferred via FTP over the Internet, stored in a storage area network (SAN), or archived on a backup tape in a delivery truck en route to offsite storage. Data commonly referred to as at rest is often actually waiting to be transferred. Different means of encryption have commonly been used to protect data in transit and data at rest. These methods include session and file encryption. Session Encryption To protect data being transferred over networks, temporary encryption keys used only for the session are generated and used to encrypt a transfer from the origin to the destination. Common session encryption technologies include IPSec or SSL VPN connections, SSH or SFTP network transfers, and HTTPS Web-based transfers. Although the data is protected in transit with these methods, it remains unencrypted before and after transfer, presenting a potential target for a breach. Another risk of session encryption is that temporary files and backups may still be found on a disk drive, even if deleted. File Encryption The alternative to session encryption is to encrypt the data at rest instead of in its transit session. In other words: encrypt the files, not the transmission, to better protect it from compromise in the event of accidental loss or theft. Common strategies include file encryption (or archive encryption) that 1 2 A Chronology of Data Breaches, Privacy Rights Clearinghouse, Annual Study: U.S. Cost of a Data Breach, November 2007, The Ponemon Institute,
5 5 uses OpenPGP, PKCS#7, or proprietary password encryption. File encryption secures data both at rest and n transit, which safeguards the information against a breach of the servers and interception over the wire. A Standard Solution Approach We have shown that file encryption is superior to session encryption because it protects the data in more circumstances. This is why the security market offers a multitude of file encryption solutions. To choose the file encryption solution that is best for your organization, evaluate the various offerings on how well they fulfill these four major requirements: Support standards-based encryption and file formats Proprietary formats hinder the broad acceptance of encryption. Having a standards-based solution ensures that you can securely exchange information with present and future partners, and that you can still access archived data for many years to come. Easily integrate with existing processes Your organization may use a variety of applications to manage and process sensitive information. Choose an encryption solution that is flexible enough to integrate with both new and legacy applications. Support a broad set of platforms Your organization may use a variety of digital platforms that process sensitive information. Choose an encryption tool that supports a heterogeneous set of platforms and operating systems, especially if the applications that you use run on systems as diverse as Windows servers, UNIX workstations, and midrange or mainframe systems. You should also consider which platforms you may need to support in the next five years. Provide advanced key management To protect private keys and preserve access to encrypted data, the encryption solution must include advanced key management technologies such as central key storage and key splitting. Central key storage lets you avoid having to touch each system when keys change or additional servers join the system; storing keys centrally is especially important if your encryption solution connects several systems. Key splitting controls the access to and use of private keys for operational security. It is often used to protect critical non-personal keys for corporate access, such as archiving, e-discovery, or data recovery. With key splitting, a number of authorized key holders each receive a key share. A minimum number of key shares, also called a threshold, must be met to reconstitute a key and make it available for use. Other advanced key management technologies that you may require in your solution include methods for ensuring corporate access to encrypted data if required by policy or regulatory mandates, even in the event that a private key is lost. PGP Command Line PGP Command Line is a file encryption solution that fulfills all four of the requirements and is designed for flexibility. It is ideal for use with batch processing, network transfer, and backup applications. Standards-based encryption and file formats. PGP Command Line uses standards-based OpenPGP (IETF RFC 2440) cryptography to compress, encrypt, and digitally sign files and directories. The software also encrypts s in OpenPGP and S/MIME format. Built on the PGP Software Development Kit (PGP SDK), PGP Command Line uses the same core
6 6 cryptographic libraries that are built into other PGP products. PGP Command Line also supports commonly used file compression methods: Zip, BZip2, and ZLib. Data encrypted with PGP Command Line can be decrypted by using other PGP Command Line clients or PGP Desktop software. For users without PGP Command Line or PGP Desktop software, PGP Command Line can generate Self-Decrypting Archives (SDAs). SDAs are archives encrypted with a passphrase that can be opened by users without PGP software. Because SDAs use symmetric encryption, the encryption passphrase must be communicated to the intended recipient out of band, for example by phone, fax, or short message service (SMS). With PGP Command Line, SDAs can be created for execution on any supported platform, allowing encrypted files to be easily transferred for use on both desktop and server platforms (for example, by creating an SDA on Sun Solaris to be decrypted on Windows XP). Easy applications integration. PGP Command Line runs as a shell-based executable. PGP Command Line is accessible from a variety of scripting languages, including UNIX scripts, Windows batch scripts, PERL, and other scripting tools and applications that can call an executable and pass arguments. This functionality allows PGP Command Line to be easily integrated into a wide variety of applications, such as enterprise backup applications. Broad platform support. PGP Command Line is available on a broad range of enterprise server platforms. In addition to these platforms, any version of PGP Command Line can be used to create SDAs that run on another supported platform (for example, an SDA created on AIX runs and decrypts on Windows 2003). PGP Command Line 9.8 is currently available for the following operating systems: 3 Windows Vista (all 32-bit and 64-bit editions) Windows 2003 (SP2) Windows XP (SP2, 32-bit and 64-bit editions) Windows 2000 (SP4) HP-UX 11i or above (PA-RISC and Itanium) IBM AIX 5.2 and 5.3 Red Hat Enterprise Linux 3.0 or above (x86 and x86_64) Sun Solaris 9 (SPARC only) and 10 (SPARC, x86, and x86_64) Fedora Core 6 and above (x86_64 only) Apple Mac OS X 10.4 and 10.5 (Universal Binary) IBM System iseries 4 IBM System zseries 5 3 Please visit for updates on supported operating systems. 4 Support for IBM System i available soon. Please check the PGP website. 5 Support for IBM System z available soon. Please check the PGP website.
7 7 Advanced key management. PGP Command Line enhances private key security by supporting key splitting. Additionally, PGP Command Line ensures long-term accessibility to encrypted data with Additional Decryption Key (ADK) technology. PGP Command Line can associate ADKs with PGP keys at the time of original key generation. When information is encrypted to a PGP key with an assigned ADK, PGP Command Line will also encrypt information to the ADK. In the event that a private key is lost or access to encrypted data is required by policy or regulations, an ADK can regain access to and decrypt information. Real-life use cases The following concise examples show how some customers in the financial, health care, and services industries use PGP Command Line. Many of these customers use PGP Command Line as an integrated part of the PGP Encryption Platform and use a range of PGP solutions. ACS Customer confidence and regulatory compliance are essential to the success of Affiliated Computer Services, Inc. (ACS). A Fortune 500 business process and information technology outsourcer, ACS handles high volumes of sensitive corporate and customer data for clients in more than 100 countries. To provide additional security, ACS purchased licenses of PGP Command Line for 150 servers to secure communication between systems. Bertelsmann A global media company with 97,000 employees in 60 countries, Bertelsmann needed a scalable, cost-effective encryption solution to protect sensitive data and comply with national and regional data privacy laws. As the foundation of its enterprise data protection strategy, Bertelsmann chose the PGP Encryption Platform to deliver encryption across the enterprise. The Bertelsmann subsidiary Bookspan, a U.S. book club, uses PGP Command Line to protect its file transfers with partners. DeKalb Medical Center DeKalb Medical Center must comply with federal regulations designed to protect the privacy of patient records. As part of its enterprise data protection strategy, DeKalb Medical Center chose the PGP Encryption Platform to meet all its encryption needs. DeKalb Medical Center decided to phase out its VPN solution for its FTP server transmissions with partners and replace it with PGP Command Line encryption. PHNS A business process outsourcer for health care providers, PHNS needed an enterprise data protection strategy to help comply with industry and government regulations protecting patient privacy and financial records. PHNS chose the PGP Encryption Platform approach to deploy and manage multiple encryption applications cost-effectively with centralized policy and key management. PGP Command Line protects confidential server-to-server communications in backend patient record and financial management applications.
8 8 Rule Financial With customers throughout the United Kingdom and Europe, Rule Financial needs to protect sensitive data and comply with relevant industry regulations. The financial services company selected PGP Command Line to secure transactions between banks and brokers. PGP encryption now forms the core of Rule Financial s enterprise data protection strategy to defend customer and business partner data wherever it goes. Texas State Bank To comply with data privacy regulations and improve its business processes, Texas State Bank chose the PGP Encryption Platform as the foundation of its enterprise data protection strategy. PGP Command Line protects server-to-server transactions among Texas State Bank, its IT outsourcing subsidiary, and its parent organization, BBVA. Securing Automated Business Processes Because PGP Command Line is a scripting and shell-based encryption application, it can integrate quickly with both off-the-shelf applications and custom scripts. PGP Command Line also provides the advanced key management options that enterprises require for critical automated business process applications, such as securing multisite FTP transfers and encrypting backup tapes for offsite storage. To illustrate how PGP Command Line meets multiple transfer, storage, and backup encryption requirements, the following scenario presents an example of a mid-sized business with a variety of encryption requirements. This hypothetical example of GlobalCPG Corporation includes the experiences of real-life PGP customers, without revealing any customer s confidential encryption strategies, policies, or procedures. GlobalCPG Corporation GlobalCPG Corporation is a midsized electronic consumer goods manufacturing company with 750 employees. 6 As a subsidiary of a publicly traded conglomerate, GlobalCPG must meet the same stringent reporting and compliance requirements as its parent company. GlobalCPG has customers and distributors throughout the world, and it must protect both business and individual data. GlobalCPG has recently begun to develop a customer relationship management (CRM) system that tracks consumers to help it better understand consumer satisfaction and preferences. GlobalCPG decided to adopt data encryption technology to address regulatory compliance and protect its sensitive corporate and customer data, even in the event of loss or theft. With three business applications and processes to secure, GlobalCPG deployed PGP Command Line in these ways: 6 GlobalCPG Corporation is not meant to represent a real company and is used here to demonstrate typical business scenarios.
9 9 Daily transmission to external trading partners Encrypt EDI data transmissions for supplychain integration. Internal network transfer of daily financial results Encrypt data exchange between internal heterogeneous systems. Tape backup encryption Encrypt individual files by using a split PGP key. Data distribution to partners without encryption software Create a Self-Decrypting Archive on IBM System z to run and decrypt on Windows XP platforms that do not have PGP Command Line installed. Daily File Transmission to External Partners GlobalCPG tightly integrates its manufacturing supply chain through daily Electronic Data Interchange (EDI) with its trading partners to order shipments of raw material and parts. The EDI data is generated on a Windows 2003 server, where it is encrypted and copied to a file transfer server that sends the files to the trading partners via FTP. The entire process is fully automated. GlobalCPG chose to encrypt the data in the OpenPGP format because OpenPGP is a widely accepted, easy-to-implement industry standard. PGP Command Line Integration Figure 1 illustrates the role of PGP Command Line in the EDI supply chain application processing. Following successful transfer, the encrypted files will be securely deleted. Figure 1: Encrypting EDI data for transmission to trading partners
10 10 Scripting The following script calls illustrate the use of PGP Command Line to encrypt files with the OpenPGP standard and perform secure deletion. Pre-backup encryption PGP --e ~/edi_data/*xml -r Trading Partner ABC Corporation ERP o ABC_EDI.pgp Encrypt all XML files in temporary Finance data directory Encrypt to trading partner ABC Corporation s ERP system key Specify output archive filename After the encrypted files are transferred, a subsequent Windows batch script calls PGP Command Line to perform a secure wipe of all temporary files used for the transfer: the XML data files and the PGP-encrypted file. Post-backup file wipe Pgp wipe *xml *pgp --wipe-passes 5 Initiates secure file deletion Wipes all temporary and output files Performs 5 wipe passes, exceeding military-grade requirements for secure file deletion After receiving the encrypted files, ABC Corp. will route the encrypted XML files to an ERP system. The system will use PGP Command Line to decrypt the files temporarily for processing, and to subsequently perform a secure wipe of the decrypted files. Internal Network Transfer of Daily Financial Results At the end of each business day, all subsidiaries of GlobalCPG s parent company transfer details of the day s business. This data is used to create an executive dashboard and monitor large customer accounts laterally across subsidiaries. The data source and target systems run on different platforms, including Windows, UNIX, and mid-range systems. Although the FTP transfers are made over a VPN connection, the data sets are used by the sales and finance departments and remain on the departmental servers until removed at the end of each quarter. Because financial information is transferred between departments and stored on systems for months, encrypting the data ensures that only authorized applications or administrators have access to it before GlobalCPG s parent company reports financial results. Encrypting this data is part of the compliance programs at GlobalCPG and its parent company.
11 11 PGP Command Line Integration When integrating PGP Command Line, GlobalCPG considered and implemented these two requirements: Multiple files should be compressed and stored in a single encrypted archive. Following successful transfer, the encrypted files should be securely deleted. Figure 2: Encrypting daily financial results for corporate parent To create a single archive, PGP Command Line s PGP Zip function stores files and directories in a single encrypted archive with commonly used compression. PGP Command Line supports encryption and decryption of PGP Zip archives, as do PGP Desktop and PGP Whole Disk Encryption products. Scripting The following script calls illustrate the use of PGP Command Line to encrypt files in a PGP Zip archive and perform secure deletion. Pre-transfer encryption PGP --e ~/finance_data/*xml -r Parent Sales r Parent Finance o upload.pgp --archive Encrypt all XML files Encrypt to both the parent Specify output Create the in temporary Finance corporation s Sales and archive filename archive as a PGP data directory Finance keys Zip file After the encrypted files are transferred, a subsequent UNIX Shell Script calls PGP Command Line to perform a secure wipe of all temporary files used for the transfer: the XML data files and the encrypted PGP Zip file.
12 12 Post-transfer file wipe pgp wipe *xml *pgp wipe-passes 5 Initiates secure file deletion Wipes all temporary and output files Performs 5 wipe passes, exceeding military-grade requirements for secure file deletion After transfer of the encrypted files, the file transfer systems of GlobalCPG s parent company will route the encrypted XML files to the target ERP systems. The systems will use PGP Command Line to decrypt the files temporarily for processing and subsequently perform a secure wipe of the decrypted files. Tape Backup Transport to Offsite Storage Each week, GlobalCPG sends a backup of databases running on the AIX platform to an offsite storage facility. This process is part of the organization s business continuity and compliance programs. In the hours before the weekly tape backup, database data is prepared for backup, generating large database files stored in a staging directory. The contents of this staging directory are then transferred to tape. The entire process is automated using a UNIX shell script. PGP Command Line Integration When integrating PGP Command Line, GlobalCPG considered and implemented these three requirements: Database backup files must be encrypted individually. Following successful tape backup, all temporary files must be securely deleted. Decryption of encrypted backups requires key splitting among at least two of the five IT administrators who are authorized to request retrieval of backups from the offsite storage vendor. Figure 3: Encrypting tape backups for offsite storage When performing encryption, PGP Command Line will by default encrypt individual files and output a new encrypted file with the.pgp extension. Encrypting to a split PGP key does not require special
13 13 configuration; however, during decryption, the prerequisite number of key shares must be available to reconstitute the key and perform decryption. Scripting The following script calls illustrate the use of PGP Command Line to create split keys, encrypt files, perform secure deletion, and decrypt files using a split PGP key. Split tape backup encryption key Initiate a key split operation for the tape backup key Set threshold of 2 keys Create a share each for Admins 1 & 2 pgp --split-key "GlobalCPG Corp DB Tape Backup" --threshold 5 --share "1:Admin1" - -share "1:Admin2" --share "1:Admin3" --share "1:Admin4" --share "1:Admin5" -- passphrase k49cxk5 force Create a share each for Admins 3, 4, & 5 Provide backup key passphrase and authorize split Five administrators are provided with one key share each. With a threshold for reconstitution of two key shares, two administrators will be required to authorize decryption using GlobalCPG s tape backup encryption key. Pre-backup encryption pgp --e ~/db_backup/* --recipient "GlobalCPG Corp DB Tape Backup" Encrypt all files in temporary backup directory Encrypt to GlobalCPG s tape backup encryption key Post-backup file wipe pgp - wipe *csv *exe --wipe-passes 5 Initiates secure file deletion Wipes all temporary and output files Performs 5 wipe passes, exceeding military-grade requirements for secure file deletion 7 Once backups are committed to tape, they are stored and then transferred by a delivery agent to an offsite storage facility. When a backup tape is needed, it is delivered to GlobalCPG. The needed backup files are copied from the tape and then prepared for decryption by authorized administrators. 7 The U.S. Department of Defense M standard specifies wiping equivalent to 3 passes with PGP Command Line.
14 14 Decryption with split keys The third administrator authenticates pgp --cache-passphrase "Admin3" --passphrase b6s3v2 --passphrase-cache Cache the passphrase of the third administrator Provide the passphrase Enable passphrase caching The fifth administrator authenticates pgp --cache-passphrase "Admin5" --passphrase 8gmas2 --passphrase-cache Cache the passphrase of the fifth administrator Provide the passphrase Enable passphrase caching After each administrator provides the passphrase to his/her private key, key reconstitution can be performed and tape backups recovered. Recover Tape Backup Key Join the tape backup key with two out of five shares Provide backup key passphrase pgp --join-key "GlobalCPG Corp DB Tape Backup" --passphrase k49cxk5 --share "Share-3-Admin3.shf" --share "Share-5-Admin3.shf" --force Use the third share to authorize join Use the fifth share to authorize join Authorize join Decrypt Backups pgp --decrypt ~/db_backup/* --passphrase k49cxk5 Decrypt all files in temporary backup directory Provide the passphrase for the GlobalCPG s tape backup encryption key Once the tape backup encryption key is reconstituted, it can be used immediately for decrypting backups.
15 15 Data Distribution to Partners without Encryption Software GlobalCPG has outsourced the sales and claims functions for its extended warranty program to a third party. This warranty service bureau contacts new customers, sells extended warranties, and settles claims. GlobalCPG exports records of new customers from its mainframe system and delivers them to the warranty service bureau on a CD-R in various CSV files, which are simple textbased files that are easily imported into a wide range of applications. GlobalCPG uses PGP Command Line encryption to protect customer data both in transit and when not in use. Because the service bureau does not have a PGP Command Line license, GlobalCPG creates an SDA that can be decrypted without the use of PGP software. PGP Command Line Integration When integrating PGP Command Line, GlobalCPG considered and implemented these three requirements: Multiple files should be stored in a single encrypted archive. The SDA generated on IBM System z must be executable on the service bureau s Windows XP systems. Figure 4: Encrypting customer lists for use by business partner PGP Command Line SDAs can be generated for any of the platforms supported. Instead of using asymmetric encryption, PGP Command Line SDAs use passphrase-based symmetric encryption that requires the passphrase to be shared with the authorized recipient(s) to allow decryption. GlobalCPG shares the decryption passphrase out-of-band during a phone conversation with the service bureau rather than delivering the passphrase via the same means as the physical media, eliminating a potential risk.
16 16 Scripting The following script calls illustrate the use of PGP Command Line to encrypt files into a Windows XP SDA. Creating SDAs Pgp --e *.csv sda -o csvs.exe --symmetric-passphrase sdf@3r4*@dj --targetplatform win32 Perform Create a Self- Set the passphrase for Create an executable encryption of all Decrypting Archive encryption to sdf@3r4*@!dj archive for Microsoft CSV files (SDA) named Windows csvs.exe The customer lists are encrypted and packaged into a PGP SDA and output as a Windows EXE. Example of Decryption on Windows XP The recipient of the encrypted SDA launches the file on Microsoft Windows XP. The shared passphrase (the same passphrase used to encrypt the archive) is then used to decrypt the SDA and the encrypted CSV files.
17 17 Conclusion Adding encryption to business applications and processes allows organizations to address risk mitigation, compliance, and the potential consequences of a security breach. With PGP Command Line, integrating encryption is a matter of adding a few lines of command line calls. Most importantly, PGP Command Line addresses four critical requirements for adding encryption to critical processes: Standards-based encryption Easily integrated Broad platform support Advanced key management From tape backup to batch FTP transfers and distribution of sensitive materials to partners, PGP Command Line provides enterprises with robust encryption capabilities for their automated data processing applications. Learn more about PGP Command Line and other PGP encryption solutions by contacting a PGP representative. Additional information is also available on the PGP website: Additional Resources To learn more about PGP Command Line and the use of encryption, obtain the following technical and business white papers: Encrypting Business Transactions with PGP Command Line Transport Layer Security (TLS) & Encryption: Complementary Security Tools These white papers are in the PGP Library:
18 18 PGP Corporation 200 Jefferson Drive Menlo Park, CA 94025, USA Tel: Fax: Sales: Support: Website: PGP Corporation All rights reserved. No part of this document may be reproduced, stored in a retrieval system, or transmitted in any form by any means without the prior written approval of PGP Corporation. The information described in this document may be protected by one or more U.S. patents, foreign patents, or pending applications. PGP and the PGP logo are registered trademarks of PGP Corporation. Product and brand names used in the document may be trademarks or registered trademarks of their respective owners. Any such trademarks or registered trademarks are the sole property of their respective owners. The information in this document is provided as is without warranty of any kind, either express or implied, including, but not limited to, the implied warranties of merchantability, fitness for a particular purpose, or non-infringement. This document could include technical inaccuracies or typographical errors. All strategic and product statements in this document are subject to change at PGP Corporation's sole discretion, including the right to alter or cancel features, functionality, or release dates. Changes to this document may be made at any time without notice.
PGP Command Line Version 10.0 Release Notes
PGP Command Line Version 10.0 Release Notes Thank you for using this PGP Corporation product. These Release Notes contain important information regarding this release of PGP Command Line. PGP Corporation
Enterprise Data Protection
PGP White Paper June 2007 Enterprise Data Protection Version 1.0 PGP White Paper Enterprise Data Protection 2 Table of Contents EXECUTIVE SUMMARY...3 PROTECTING DATA EVERYWHERE IT GOES...4 THE EVOLUTION
PGP Command Line Version 10.2 Release Notes
PGP Command Line Version 10.2 Release Notes Thank you for using this Symantec Corporation product. These Release Notes contain important information regarding this release of PGP Command Line. Symantec
PGP Command Line Version 10.3 Release Notes
PGP Command Line Version 10.3 Release Notes Page 1 of 6 PGP Command Line Version 10.3 Release Notes Thank you for using this Symantec Corporation product. These Release Notes contain important information
Deploying PGP Encryption and Compression for z/os Batch Data Protection to (FIPS-140) Compliance
Deploying PGP Encryption and Compression for z/os Batch Data Protection to (FIPS-140) Compliance Patrick Townsend Software Diversified Services/Townsend Security August 9, 2011 Session Number 9347 PGP
IBM Lotus Protector for Mail Encryption. User's Guide
IBM Lotus Protector for Mail Encryption User's Guide Version Information Lotus Protector for Mail Encryption User's Guide. Lotus Protector for Mail Encryption Version 2.1.0. Released December 2010. This
Omniquad Exchange Archiving
Omniquad Exchange Archiving Deployment and Administrator Guide Manual version 3.1.2 Revision Date: 20 May 2013 Copyright 2012 Omniquad Ltd. All rights reserved. Omniquad Ltd Crown House 72 Hammersmith
Securing Data Stored On Tape With Encryption: How To Choose the Right Encryption Key Management Solution
Securing Data Stored On Tape With Encryption: How To Choose the Right Encryption Key Management Solution NOTICE This Technology Brief may contain proprietary information protected by copyright. Information
Email Archiving User Guide Outlook Plugin. Manual version 3.1
Email Archiving User Guide Outlook Plugin Manual version 3.1 Copyright 2012 Omniquad Ltd. All rights reserved. Omniquad Ltd Crown House 72 Hammersmith Road Hammersmith London W14 8TH United Kingdom Omniquad
IBM Tivoli Directory Integrator
IBM Tivoli Directory Integrator Synchronize data across multiple repositories Highlights Transforms, moves and synchronizes generic as well as identity data residing in heterogeneous directories, databases,
Healthcare Compliance Solutions
Privacy Compliance Healthcare Compliance Solutions Trust and privacy are essential for building meaningful human relationships. Let Protected Trust be your Safe Harbor The U.S. Department of Health and
March 2005. PGP White Paper. Transport Layer Security (TLS) & Encryption: Complementary Security Tools
March 2005 PGP White Paper Transport Layer Security (TLS) & Encryption: Complementary Security Tools PGP White Paper TLS & Encryption 1 Table of Contents INTRODUCTION... 2 HISTORY OF TRANSPORT LAYER SECURITY...
Attaining PCI Compliance Using The PGP Encryption Platform
PGP White Paper June 2008 Attaining PCI Compliance Using The PGP Encryption Platform 2 Table of Contents TABLE OF CONTENTS...2 EXECUTIVE SUMMARY...3 OBJECTIVE: AVOID THE TJX...4 THE PCI STANDARD...5 OVERVIEW...
Alliance AES Encryption for IBM i Solution Brief
Encryption & Tokenization Alliance AES Encryption for IBM i Solution Brief A Complete AES Encryption Solution Alliance AES Encryption for IBM i provides AES encryption for sensitive data everywhere it
Five Truths. About Enterprise Data Protection THE BEST WAY TO SECURE YOUR DATA AND YOUR BUSINESS DEFENDING THE DATA CMYK 100 68 0 12
Five Truths About Enterprise Data Protection THE BEST WAY TO SECURE YOUR DATA AND YOUR BUSINESS DEFENDING THE DATA CMYK 100 68 0 12 1. Business data is everywhere and it s on the move. Data has always
Symantec Backup Exec 11d for Windows Servers New Encryption Capabilities
WHITE PAPER: ENTERPRISE SECURITY Symantec Backup Exec 11d for Windows Servers New Encryption Capabilities White Paper: Enterprise Security Symantec Backup Exec 11d for Windows Servers Contents Executive
How To Use Attix5 Pro For A Fraction Of The Cost Of A Backup
Service Overview Business Cloud Backup Techgate s Business Cloud Backup service is a secure, fully automated set and forget solution, powered by Attix5, and is ideal for organisations with limited in-house
Guidelines on use of encryption to protect person identifiable and sensitive information
Guidelines on use of encryption to protect person identifiable and sensitive information 1. Introduction David Nicholson, NHS Chief Executive, has directed that there should be no transfers of unencrypted
IBM Lotus Protector for Mail Encryption
IBM Lotus Protector for Mail Encryption Server Upgrade Guide 2.1.1 Version Information Lotus Protector for Mail Encryption Server Upgrade Guide. Lotus Protector for Mail Encryption Server Version 2.1.1.
PGP Universal Server 2.5 SmartLine DeviceLock 6.2
PGP Integration Guide October 2007 PGP Universal Server 2.5 SmartLine DeviceLock 6.2 Version 1.0 2 Table of Contents INTRODUCTION...3 STRUCTURE...3 CAVEATS...4 POLICY OVERVIEW...4 SPAN OF CONTROL...4 COMPUTER
IBM Application Hosting EDI Services Expedite software adds Secure Sockets Layer TCP/IP support
Software Announcement June 1, 2004 Services Expedite software adds Secure Sockets Layer TCP/IP support Overview Services Expedite software for Microsoft Windows, AIX, and OS/400 is being enhanced to support
2 Installing Privileged User Manager 2.3
NetIQ Privileged User Manager 2.3.2 Release Notes January, 2013 1 Documentation The following sources provide information about Privileged User Manager: Privileged User Manager 2.3 Documentation Site (http://www.novell.com/documentation/
Is online backup right for your business? Eight reasons to consider protecting your data with a hybrid backup solution
PARTNER BRIEF: IS ONLINE BACKUP RIGHT FOR YOUR BUSINESS?........................................ Is online backup right for your business? Eight reasons to consider protecting your data with a hybrid Who
nwstor Storage Security Solution 1. Executive Summary 2. Need for Data Security 3. Solution: nwstor isav Storage Security Appliances 4.
CONTENTS 1. Executive Summary 2. Need for Data Security 3. Solution: nwstor isav Storage Security Appliances 4. Conclusion 1. EXECUTIVE SUMMARY The advantages of networked data storage technologies such
How Reflection Software Facilitates PCI DSS Compliance
Reflection How Reflection Software Facilitates PCI DSS Compliance How Reflection Software Facilitates PCI DSS Compliance How Reflection Software Facilitates PCI DSS Compliance In 2004, the major credit
MOVEIT CENTRAL: MANAGED FILE TRANSFER WORKFLOW ENGINE
MOVEIT CENTRAL: MANAGED FILE TRANSFER WORKFLOW ENGINE ABSTRACT Data workflows are truly the lifeblood of organizations today, yet the infrastructure supporting these workflows are typically less than ideal.
New Security Features
New Security Features BlackBerry 10 OS Version 10.3.1 Published: 2014-12-17 SWD-20141211141004210 Contents About this guide... 4 Advanced data at rest protection... 5 System requirements... 6 Managing
Linux. Managing security compliance
Linux Managing security compliance Linux Managing security compliance Note Before using this information and the product it supports, read the information in Notices on page 7. First Edition (December
Ensuring the security of your mobile business intelligence
IBM Software Business Analytics Cognos Business Intelligence Ensuring the security of your mobile business intelligence 2 Ensuring the security of your mobile business intelligence Contents 2 Executive
PGP Desktop Email Quick Start Guide version 9.6
What is PGP Desktop Email? PGP Desktop Email is part of the PGP Desktop family of products. You can use PGP Desktop Email to: Automatically and transparently encrypt, sign, decrypt, and verify email messages
Alliance Key Manager A Solution Brief for Technical Implementers
KEY MANAGEMENT Alliance Key Manager A Solution Brief for Technical Implementers Abstract This paper is designed to help technical managers, product managers, and developers understand how Alliance Key
Key Management Interoperability Protocol (KMIP)
(KMIP) Addressing the Need for Standardization in Enterprise Key Management Version 1.0, May 20, 2009 Copyright 2009 by the Organization for the Advancement of Structured Information Standards (OASIS).
BANKING SECURITY and COMPLIANCE
BANKING SECURITY and COMPLIANCE Cashing In On Banking Security and Compliance With awareness of data breaches at an all-time high, banking institutions are working hard to implement policies and solutions
Symantec Encryption Solutions for Email, Powered by PGP Technology
Symantec Encryption Solutions for Email, Powered by PGP Technology Data Sheet: Encryption The Problem with Email Are you worried that users are emailing sensitive information openly? According to Osterman
Symantec File Share Encryption Quick Start Guide Version 10.3
Symantec File Share Encryption Quick Start Guide Version 10.3 What is Symantec File Share Encryption? Symantec File Share Encryption is a software tool that provides multiple ways to protect and share
Product Brief. DC-Protect. Content based backup and recovery solution. By DATACENTERTECHNOLOGIES
Product Brief DC-Protect Content based backup and recovery solution By DATACENTERTECHNOLOGIES 2002 DATACENTERTECHNOLOGIES N.V. All rights reserved. This document contains information proprietary and confidential
What IT Auditors Need to Know About Secure Shell. SSH Communications Security
What IT Auditors Need to Know About Secure Shell SSH Communications Security Agenda Secure Shell Basics Security Risks Compliance Requirements Methods, Tools, Resources What is Secure Shell? A cryptographic
IBM DB2 CommonStore for Lotus Domino, Version 8.3
Delivering information on demand IBM DB2 CommonStore for Lotus Domino, Version 8.3 Highlights Controls long-term growth Delivers records management and performance of your integration, supporting corporate
2007 Microsoft Office System Document Encryption
2007 Microsoft Office System Document Encryption June 2007 Table of Contents Introduction 1 Benefits of Document Encryption 2 Microsoft 2007 Office system Document Encryption Improvements 5 End-User Microsoft
IBX Business Network Platform Information Security Controls. 2015-02- 20 Document Classification [Public]
IBX Business Network Platform Information Security Controls 2015-02- 20 Document Classification [Public] Table of Contents 1. General 2 2. Physical Security 2 3. Network Access Control 2 4. Operating System
GoAnywhere Director to GoAnywhere MFT Upgrade Guide. Version: 5.0.1 Publication Date: 07/09/2015
GoAnywhere Director to GoAnywhere MFT Upgrade Guide Version: 5.0.1 Publication Date: 07/09/2015 Copyright 2015 Linoma Software. All rights reserved. Information in this document is subject to change without
enicq 5 System Administrator s Guide
Vermont Oxford Network enicq 5 Documentation enicq 5 System Administrator s Guide Release 2.0 Published November 2014 2014 Vermont Oxford Network. All Rights Reserved. enicq 5 System Administrator s Guide
The Most Complete Data Protection Platform for MSPs
The Most Complete Data Protection Platform for MSPs I delivers the industry s most complete Data Protection Platform today. From an easy-to-use dashboard, MSPs can efficiently manage cloud backup, disaster
CimTrak Technical Summary. DETECT All changes across your IT environment. NOTIFY Receive instant notification that a change has occurred
DETECT All changes across your IT environment With coverage for your servers, network devices, critical workstations, point of sale systems, and more, CimTrak has your infrastructure covered. CimTrak provides
WHITE PAPER. Managed File Transfer: When Data Loss Prevention Is Not Enough Moving Beyond Stopping Leaks and Protecting Email
WHITE PAPER Managed File Transfer: When Data Loss Prevention Is Not Enough Moving Beyond Stopping Leaks and Protecting Email EXECUTIVE SUMMARY Data Loss Prevention (DLP) monitoring products have greatly
System Requirements and Platform Support Guide
Foglight 5.6.7 System Requirements and Platform Support Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in
EMC DATA DOMAIN ENCRYPTION A Detailed Review
White Paper EMC DATA DOMAIN ENCRYPTION A Detailed Review Abstract The proliferation of publicized data loss, coupled with new governance and compliance regulations, is driving the need for customers to
bbc Overview Adobe Flash Media Rights Management Server September 2008 Version 1.5
bbc Overview Adobe Flash Media Rights Management Server September 2008 Version 1.5 2008 Adobe Systems Incorporated. All rights reserved. Adobe Flash Media Rights Management Server 1.5 Overview for Microsoft
Optimizing Backup & Recovery Performance with Distributed Deduplication
Optimizing Backup & Recovery Performance with Distributed Deduplication Using NetVault Backup with EMC DD Boost Written by: Shad Nelson Product Manager Dell Software Executive Summary Backup applications
IBM Enterprise Content Management Software Requirements
IBM Enterprise Content Management Software Requirements This document describes the software prerequisite requirements for the IBM Enterprise Content Management suite of products. Last Updated: May 31,
PN 00651. Connect:Enterprise Secure FTP Client Release Notes Version 1.2.00
PN 00651 Connect:Enterprise Secure FTP Client Release Notes Version 1.2.00 Connect:Enterprise Secure FTP Client Release Notes Version 1.2.00 First Edition This documentation was prepared to assist licensed
Software as a Service (SaaS) Requirements
Introduction Software as a Service (SaaS) Requirements Software as a Service (SaaS) is a software service model where an application is hosted as a service provided to customers across the Internet. By
MOVEIT: SECURE BY DESIGN BY JONATHAN LAMPE, GCIA, GSNA
MOVEIT: SECURE BY DESIGN BY JONATHAN LAMPE, GCIA, GSNA The MOVEit DMZ server, MOVEit clients, and FIPS 140-2 validated MOVEit cryptographic software products by Ipswitch File Transfer have been designed
CA ARCserve Backup for Windows
CA ARCserve Backup for Windows Agent for Microsoft SharePoint Server Guide r15 This documentation and any related computer software help programs (hereinafter referred to as the "Documentation") are for
data express DATA SHEET OVERVIEW
data express DATA SHEET OVERVIEW The reliability of IT systems is a key requirement of almost any organization. Unexpected failure of enterprise systems can be expensive and damaging to an organization.
PA-DSS Implementation Guide for. Sage MAS 90 and 200 ERP. Credit Card Processing
for Sage MAS 90 and 200 ERP Credit Card Processing Version 4.30.0.18 and 4.40.0.1 - January 28, 2010 Sage, the Sage logos and the Sage product and service names mentioned herein are registered trademarks
Attix5 Pro Overview. V7.x. An overview of the Attix5 Pro product suite.
Attix5 Pro Overview V7.x An overview of the Attix5 Pro product suite. Copyright notice and proprietary information This document is published by Attix5 or its local affiliated company, without any warranty.
MANAGED FILE TRANSFER: 10 STEPS TO PCI DSS COMPLIANCE
WHITE PAPER MANAGED FILE TRANSFER: 10 STEPS TO PCI DSS COMPLIANCE 1. OVERVIEW Do you want to design a file transfer process that is secure? Or one that is compliant? Of course, the answer is both. But
White Paper. BD Assurity Linc Software Security. Overview
Contents 1 Overview 2 System Architecture 3 Network Settings 4 Security Configurations 5 Data Privacy and Security Measures 6 Security Recommendations Overview This white paper provides information about
StreamServe Persuasion SP4 Encryption and Authentication
StreamServe Persuasion SP4 Encryption and Authentication User Guide Rev A StreamServe Persuasion SP4 Encryption and Authentication User Guide Rev A 2001-2009 STREAMSERVE, INC. ALL RIGHTS RESERVED United
Privacy + Security + Integrity
Privacy + Security + Integrity Docufree Corporation Data Security Checklist Security by Design Docufree is very proud of our security record and our staff works diligently to maintain the greatest levels
Citrix MetaFrame XP Security Standards and Deployment Scenarios
Citrix MetaFrame XP Security Standards and Deployment Scenarios Including Common Criteria Information MetaFrame XP Server for Windows with Feature Release 3 Citrix Systems, Inc. Information in this document
Ensuring HIPAA Compliance with AcclaimVault Online Backup and Archiving Services
Ensuring HIPAA Compliance with AcclaimVault Online Backup and Archiving Services 1 Contents 3 Introduction 5 The HIPAA Security Rule 7 HIPAA Compliance & AcclaimVault Backup 8 AcclaimVault Security and
IBM WebSphere Data Interchange V3.3
IBM Software Group IBM WebSphere Data Interchange V3.3 This presentation will present an overview of the WebSphere Data Interchange product. IBM Software Group Page 1 of 14 Agenda IBM Software Group Electronic
Oracle Business Intelligence Publisher. 1 Oracle Business Intelligence Publisher Certification. Certification Information 10g Release 3 (10.1.3.4.
Oracle Business Intelligence Publisher Certification Information 10g Release 3 (10.1.3.4.2) E12692-08 September 2011 This document outlines the certified hardware and software configurations for Oracle
StreamServe Persuasion SP5 Encryption and Authentication
StreamServe Persuasion SP5 Encryption and Authentication User Guide Rev A StreamServe Persuasion SP5 Encryption and Authentication User Guide Rev A 2001-2010 STREAMSERVE, INC. ALL RIGHTS RESERVED United
Solutions for Encrypting Data on Tape: Considerations and Best Practices
Solutions for Encrypting Data on Tape: Considerations and Best Practices NOTICE This white paper may contain proprietary information protected by copyright. Information in this white paper is subject to
DMZ Gateways: Secret Weapons for Data Security
A L I N O M A S O F T W A R E W H I T E P A P E R DMZ Gateways: Secret Weapons for Data Security A L I N O M A S O F T W A R E W H I T E P A P E R DMZ Gateways: Secret Weapons for Data Security EXECUTIVE
MOVEIT: SECURE, GUARANTEED FILE DELIVERY BY JONATHAN LAMPE, GCIA, GSNA
MOVEIT: SECURE, GUARANTEED FILE DELIVERY BY JONATHAN LAMPE, GCIA, GSNA The MOVEit line of secure managed file transfer software products by Ipswitch File Transfer consists of two flagship products, the
Reducing the cost and complexity of endpoint management
IBM Software Thought Leadership White Paper October 2014 Reducing the cost and complexity of endpoint management Discover how midsized organizations can improve endpoint security, patch compliance and
ensure prompt restart of critical applications and business activities in a timely manner following an emergency or disaster
Security Standards Symantec shall maintain administrative, technical, and physical safeguards for the Symantec Network designed to (i) protect the security and integrity of the Symantec Network, and (ii)
Generating and Installing SSL Certificates on the Cisco ISA500
Application Note Generating and Installing SSL Certificates on the Cisco ISA500 This application note describes how to generate and install SSL certificates on the Cisco ISA500 security appliance. It includes
MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE
WHITE PAPER MANAGED FILE TRANSFER: 10 STEPS TO SOX COMPLIANCE 1. OVERVIEW Do you want to design a file transfer process that is secure? Or one that is compliant? Of course, the answer is both. But it s
IBM Lotus Protector for Mail Encryption
IBM Lotus Protector for Mail Encryption for Windows User's Guide 2.1.1 Version Information Lotus Protector for Mail Encryption User's Guide. Lotus Protector for Mail Encryption Version 2.1.1. Released
Complying with PCI Data Security
Complying with PCI Data Security Solution BRIEF Retailers, financial institutions, data processors, and any other vendors that manage credit card holder data today must adhere to strict policies for ensuring
Sharing Secrets Using Encryption Facility
Sharing Secrets Using Encryption Facility Eysha S. Powers IBM Corporation Insert Custom Session QR if Desired Tuesday, August 11, 2015: 6:00pm 7:00pm Session Number 17624 Cryptography is used in a variety
Reduce your data storage footprint and tame the information explosion
IBM Software White paper December 2010 Reduce your data storage footprint and tame the information explosion 2 Reduce your data storage footprint and tame the information explosion Contents 2 Executive
IBM Campaign Version-independent Integration with IBM Engage Version 1 Release 3 April 8, 2016. Integration Guide IBM
IBM Campaign Version-independent Integration with IBM Engage Version 1 Release 3 April 8, 2016 Integration Guide IBM Note Before using this information and the product it supports, read the information
IBM Data Security Services for endpoint data protection endpoint encryption solution
Protecting data on endpoint devices and removable media IBM Data Security Services for endpoint data protection endpoint encryption solution Highlights Secure data on endpoint devices Reap benefits such
The basic groups of components are described below. Fig X- 1 shows the relationship between components on a network.
Elements of Email Email Components There are a number of software components used to produce, send and transfer email. These components can be broken down as clients or servers, although some components
DB2 Database Demonstration Program Version 9.7 Installation and Quick Reference Guide
DB2 Database Demonstration Program Version 9.7 Installation and Quick Reference Guide George Baklarz DB2 Worldwide Technical Sales Support IBM Toronto Laboratory DB2 Demonstration Program Version 9.7 Usage
IBM Maximo Asset Management Essentials
Enterprise asset capabilities for small and midsized organizations IBM Maximo Asset Essentials Highlights Leverage enterprise asset capabilities in a package specifically designed for small and midsized
Secure Email User Guide
Secure Email User Guide Transport Layer Security (TLS) Pretty Good Privacy (PGP) PDF Messenger 1 Contents 1 Introduction... 3 2 Transport Layer Security (TLS).4 3 Pretty Good Privacy (PGP).5 4 PDF Messenger...
DOCUMENTATION FILE BACKUP
DOCUMENTATION Copyright Notice The use and copying of this product is subject to a license agreement. Any other use is prohibited. No part of this publication may be reproduced, transmitted, transcribed,
Active Directory Rights Management Services integration (AD RMS)
MOSS Information Rights Management Ashish Bahuguna [email protected] Active Directory Rights Management Services integration (AD RMS) Agenda AD RMS Overview AD RMS Architecture Components MOSS
PGP Desktop Email Quick Start Guide Version 10.2
PGP Desktop Email Quick Start Guide Version 10.2 What is PGP Desktop Email? PGP Desktop Email is part of the PGP Desktop family of products. Use PGP Desktop Email to: Automatically and transparently encrypt,
RSA AUTHENTICATION AGENT SUPPORTED PLATFORMS
RSA AUTHENTICATION AGENT SUPPORTED PLATFORMS Web server authentication agents Version Description platform operating system rsa authentication agent 7.1 for Web for Apache 7.1 Apache 2.2 Apache 2.0 and
Only 8% of corporate laptop data is actually backed up to corporate servers. Pixius Advantage Outsourcing Managed Services
Pixius Advantage Outsourcing Managed Services Move forward with endpoint protection by understanding its unique requirements. As the number of information workers rises, so does the growth and importance
TIBCO ActiveMatrix BusinessWorks Plug-in for TIBCO Managed File Transfer Software Installation
TIBCO ActiveMatrix BusinessWorks Plug-in for TIBCO Managed File Transfer Software Installation Software Release 6.0 November 2015 Two-Second Advantage 2 Important Information SOME TIBCO SOFTWARE EMBEDS
Evolution from FTP to Secure File Transfer
IPSWITCH FILE TRANSFER WHITE PAPER Evolution from FTP to Secure File Transfer www.ipswitchft.com Do you know where your organization s confidential and sensitive files were transferred today? Are you sure
High Security Online Backup. A Cyphertite White Paper February, 2013. Cloud-Based Backup Storage Threat Models
A Cyphertite White Paper February, 2013 Cloud-Based Backup Storage Threat Models PG. 1 Definition of Terms Secrets Passphrase: The secrets passphrase is the passphrase used to decrypt the 2 encrypted 256-bit
Understanding Enterprise Cloud Governance
Understanding Enterprise Cloud Governance Maintaining control while delivering the agility of cloud computing Most large enterprises have a hybrid or multi-cloud environment comprised of a combination
Effective storage management and data protection for cloud computing
IBM Software Thought Leadership White Paper September 2010 Effective storage management and data protection for cloud computing Protecting data in private, public and hybrid environments 2 Effective storage
TIBCO Spotfire Server Migration. Migration Manual
TIBCO Spotfire Server Migration Migration Manual Revision date: 26 October 2012 Important Information SOME TIBCO SOFTWARE EMBEDS OR BUNDLES OTHER TIBCO SOFTWARE. USE OF SUCH EMBEDDED OR BUNDLED TIBCO SOFTWARE
