RSA ClearTrust Web Access Management Enhancing control. Widening access. Driving e-business growth. Identity Management Authentication Centralized Security Policy SSO Access Management
RSA ClearTrust Web access management software is designed to empower you to manage user identities and access policies with a high degree of precision, flexibility and control. Equally important, this standards-based solution positions you to securely deliver a new generation of high-value Web services and federated identity management solutions all while helping to reduce your infrastructure costs.
How do you catch the next wave of e-business growth? Web services will drive growth Now that the first wave of e-business growth has ebbed, enterprises are pausing to take stock and align themselves with the most promising opportunities. Wherever they turn, there's a growing consensus that two related technologies Web services and identity management hold the key to e-business growth. Standards-based, modular and reusable, Web services make it easier for enterprises to exchange information and transact business within and across organizational boundaries. Yet, Web services also pose a challenge: By exposing business processes more widely, they create a need to manage user identities far more effectively than was possible in the past but first, enterprises must master identity management Traditional approaches to identity management which rely on disparate identity management systems and result in each user having multiple electronic identities do not meet enterprise requirements for security, scalability or cost-effectiveness. In addition, disparate systems make it difficult to manage user access privileges with the precision, flexibility and end-user convenience that e-business requires. Clearly, there has to be a better way. RSA Security puts you on the right path RSA ClearTrust Web access management is designed to help you surmount these challenges. Based on the award-winning RSA ClearTrust software, this solution brings together powerful capabilities for centrally managing user identities and user privileges across multiple applications and domains. In turn, you are better able to achieve several related e-business goals: Establish trusted online identities so that all the parties to a transaction know with a high degree of certainty whom they are dealing with. Enhance access control to enforce business policy, establish accountability and protect Web-based resources from misuse by external and internal users. Reduce costs by consolidating redundant infrastructure and streamlining business processes and administration. Align with emerging standards for Web services and federated identity management so you are well positioned to deliver a new generation of highvalue, Web-based offerings to an expanded market. 1
Delivering identity and access management RSA ClearTrust software is engineered to address four broad areas of e-business enablement: Identity Management Authentication Policy Management Web Access Management Web Single Sign-on Identity Management: One user, one identity Identity management involves the intelligent use of digital identities and includes managing the full life cycle of an identity from creation and maintenance to termination while also enforcing authentication and Web access policies. RSA ClearTrust software is designed to enable you to create and manage a single, trusted electronic identity for each user, drawing data from existing identity data stores, such as an LDAPbased employee directory or an SQL database of customer information. By deploying an enterprise-wide solution that is engineered to be centralized and highly scalable, you enhance your ability to manage electronic identities for a rapidly growing user base while also providing a more convenient user experience. Authentication Policy Management: May I come in? RSA ClearTrust software is designed to help you enhance security and reduce infrastructure costs by replacing multiple, application-specific authentication schemes with centralized authentication policy management. Administrators can create policies that span many applications and encompass multiple external audiences. The RSA ClearTrust solution is engineered to support popular authentication methods including passwords, X.509 digital certificates, tokens, smart cards and custom methods. Leveraging your existing authentication investments including RSA Security authentication solutions you can apply different levels of protection, based on the sensitivity of the resource. (See Awesome Authentication Capabilities, opposite.) Web Access Management: What can I see and do? RSA ClearTrust software enables centralized management of user access privileges and policies, giving you fine-grained control over the resources an individual can access once he or she is inside your network. User privileges can be flexibly defined based on multiple criteria, such as the individual s identity or group relationship to your organization (employee, customer, supplier) or user attributes such as an individual s account balance, job title, division or geographical location. By making it easier for users to access the resources that are most relevant to their needs, RSA ClearTrust software enhances user self-service, while also protecting your business from the risk of exposing sensitive information. Access Management
Awesome Authentication Capabilities To complement the RSA ClearTrust authentication policy management capabilities, RSA Security offers a range of user authentication solutions, addressing diverse requirements for security, scalability, mobility and total cost of ownership. Some examples: SSO RSA SecurID two-factor technology is the run-away industry leader in strong authentication. The RSA Keon family of digital certificate management products are designed to provide industrystandard capabilities and extensive value-added features for managing online identities using X.509 digital certificates. Our zero-footprint RSA Mobile solution is designed to convert existing access devices (such as mobile phones and PDAs) into secure authenticators, thus bringing scalable, cost-effective two-factor authentication to B2C environments. RSA Keon Web Passport is designed to allow users to access their electronic credentials from any Web browser, enabling anytime, anywhere e-business. RSA Smart Badging solutions help reduce infrastructure costs by consolidating multiple applications for physical and network security onto a single device. Web SSO: One authentication, please. We re all familiar with the problems posed by multiple electronic identities, whether in an enterprise or a B2C setting. Multiple usernames and passwords constitute a barrier to user productivity, a burden to the help desk which handles password resets and a security risk: to keep track of their passwords, people often employ easy-to-defeat methods, such as using a password that can be easily guessed or using the same password for several applications. RSA ClearTrust technology is designed to address these challenges by providing Web single sign-on (SSO). With Web SSO, a user can access multiple applications within an intranet/extranet or navigate across multiple sites and domains including partner and affiliate sites while authenticating only once. 3 By enhancing the user experience, SSO increases customer/partner satisfaction and contributes to higher retention rates for external audiences. Equally important, by reducing reliance on multiple usernames and passwords, SSO eliminates a weak link in your security strategy and reduces support costs related to password administration.
Solutions that work the way your business works RSA ClearTrust technology has been well proven in many enterprise environments. It is designed to provide powerful, flexible capabilities for managing user identities and Web access policies in alignment with your business processes and in harmony with your existing e-business infrastructure. Key features include: RSA ClearTrust Smart Rules RSA ClearTrust Smart Rules functionality is designed to further accelerate deployment by enabling you to quickly translate business rules into Web access management policies that are applicable to user properties, such as job role, geographic location or account balance. Using native language and Boolean constructs and drawing on existing data and automatic updates RSA ClearTrust Smart Rules technology makes it possible to build access policies in a quick and efficient manner. Enterprise integration RSA ClearTrust software is engineered to offer out-of-the box interoperability with leading vendors Web applications and infrastructure products. This feature is intended to speed deployment, reduce deployment costs and help ensure investment protection for your current environment. The software also provides the scalability and raw throughput needed to support very large user populations spanning multiple organizations. Support for widely used directories and databases The RSA ClearTrust product is designed to support leading databases and LDAP-compliant directory servers as its data store. As a result, you can leverage your existing user identity repositories, with no need to change existing data structures or schemas. Centralized Security Policy An award-winning management console A powerful, intuitive Web-based graphical user interface simplifies user and policy management for your administrators. This self-teaching interface allows users with little experience to quickly master administrative tasks. In turn, your organization can quickly benefit from an RSA ClearTrust solution. Delegated administration You can easily delegate user and policy management to business units and external organizations in a multi-tier and granular fashion. This moves appropriate aspects of decision-making closer to the end user while also distributing administrative costs.
A leader in standards for federated identity management To provide a superb experience for Web users, enterprises realize they must be able to manage and federate (share) user information from disparate online sources and across enterprise boundaries. Yet, to earn user trust, they must do so in a way that is highly secure, convenient and respectful of the individual s preferences for privacy and information sharing. As a founding member of the multi-industry Liberty Alliance, RSA Security has been instrumental in establishing an open standard for federated network identity. RSA Security is also a significant contributor to the OASIS standards body, specifically with regards to SAML (security assertions markup language), the standard for securely exchanging user authentication and authorization information across the Web. In addition, RSA Security is a co-author, along with Microsoft and others, of additional Web services security specifications, including: WS-Trust, WS-SecurityPolicy and WS-SecureConversation. With RSA ClearTrust Web access management, Lehman Brothers is able to quickly deploy strategic, revenue-generating extranet initiatives securely and easily. The manageability of RSA ClearTrust technology allows us to rapidly scale our extranet without being overwhelmed by administration. Dave Macolina Vice President Internet Services Lehman Brothers
Reducing costs and risk while driving growth Reduce infrastructure costs In most cases, cost reduction is the most immediate benefit of an RSA ClearTrust solution. By implementing a unified solution for user privilege management, you can eliminate the expense of creating and managing disparate identity management, authentication management and access management schemes for individual applications. The savings in password administration alone can be considerable. Reduce business process costs By enabling secure, self-service capabilities you can dramatically reduce internal process business costs as well as the cost of managing thousands or even millions of external relationships. Taking advantage of delegated administration, one of our customers a portal that Reduce the risks of e-business RSA ClearTrust Web access management solutions help reduce the vulnerability of your mission-critical information and applications. For example, identity management and authentication services make it more difficult for anonymous intruders to gain entry and commit illicit acts. Additionally, auditing and reporting capabilities provide accountability and thus discourage insiders from abusing the resources they are permitted to access. serves 2,500 companies requires only a handful of ROI internal administrators to support approximately 3,000 external administrators. They, in turn, support more than 300,000 end users, at little or no expense to the portal provider.
Drive revenue growth An RSA Web Access Management solution can assist you in creating new revenue opportunities for your enterprise. Some examples: By reducing partnering costs, you can engage with more partners and widen your revenue stream. With enhanced security and accountability, you can move high-value transactions to the Web, benefiting from faster revenue recognition and lower transaction costs. By enhancing the user experience, you earn customer/partner loyalty and encourage repeat business, with virtually no costs of sales. Through new capabilities for sharing identity information, you can collaborate with affiliates to offer enhanced services, with premium pricing. Enhance compliance RSA ClearTrust Web access management is designed to enforce defined authentication and authorization policies and provide end-to-end auditing and reporting of all transactions. Serving as a proof of activity, the software is engineered to support nonrepudiation of online transactions and facilitates compliance with a wide range of regulations, such as the United States Health Insurance Portability and Accountability Act (HIPAA) and U.S. Federal Drug Administration 21 Code of Federal Regulation Part 11 (21 CFR Part 11) governing electronic records and signatures. 7 With RSA ClearTrust software, we have been able to enhance our users online experience by taking advantage of the solution s single sign-on capability, which allows users to move from sub-site to sub-site and application to application by signing on only once per session. In addition, because RSA ClearTrust software supports SSL-encrypted Web communications, it works seamlessly with our existing applications. Paul Martinello Director, System Development Credit Union Central of Ontario
The right expertise means faster time to results Developing an effective strategy for Web access management requires security expertise, technology expertise and business process expertise. RSA Security brings all three to your project. Our service professionals combine: In-depth knowledge of security policies and best practices, developed over the course of 20 years in the IT security industry; A deep understanding of key enabling technologies, such as directories, SSO and identity management; and Insight into the business processes that affect the management of user information, access rights and related policies. Building on this expertise, RSA Security offers a range of assessment and design services to ensure that your Web access management solution is fully aligned with your business strategy and goals. Moreover, integration, implementation, training and support services help facilitate a fast, focused deployment and smooth operation during the all-important first year of operation. Depending on your situation, we can provide expertise and resources through our professional services organization, our network of industry-leading consultants and systems integrators (CSIs) or a combination of the two. Let s get started today RSA Security welcomes the opportunity to discuss your Web access management challenges and to share with you some of the successes other enterprise customers have attained with these solutions. To learn more about RSA ClearTrust Web access management solutions or to contact an RSA Security account representative, please visit www.rsasecurity.com today.
RSA Security With more than 9,000 customers around the globe, RSA Security (NASDAQ: RSAS) is recognized as the strategic e-security partner to many of the largest and most successful companies leveraging the Internet to grow their businesses and improve their bottom line. RSA Security s comprehensive portfolio of e-security solutions including authentication, Web access management and developer toolkits helps organizations fully realize revenue opportunities while helping protect critical information against unauthorized access and other forms of malicious intent. RSA Security s strong reputation is built on its history of innovation and leadership, award-winning solutions and long-standing relationships with more than 1,000 technology partners. Our portal, MyBMC.org serves as the front door for doctors and other clinicians who need remote Web access to key clinical applications while they are away from the hospital. With RSA SecurID two-factor authentication and RSA ClearTrust Web access management, we have been able to strike the right balance between end-user convenience, security for sensitive patient records, and centralized control of user access privileges. Darren Dworkin Chief Technology Officer Boston Medical Center
ClearTrust, Keon, RSA, RSA Security, the RSA logo, SecurID and Smart Rules are registered trademarks or trademarks of RSA Security Inc. All other trademarks mentioned herein are the property of their respective owners. 2003 RSA Security Inc. All rights reserved. CTWAM BR 0203