Welcome Guest. | Log In| Register | Membership Benefits
  • Email this page E-mail this page
  • |  Print Print this page
  • |   Bookmark and Share

Cisco, RSA Partner to Secure Data in Motion, at Rest

Partnership leverages data loss prevention framework unveiled by RSA last week

Apr 07, 2008 | 09:00 AM

By Tim Wilson
DarkReading

Two of the industry's best-known security vendors today revealed a partnership to integrate their products to help enterprises secure data as it moves around the enterprise.

EMC's RSA security unit said it will integrate its next-generation data loss prevention (DLP) product suite with Cisco's security tools to improve enterprises' ability to identify sensitive data as it moves across the network, set policies for securing it, and enforce those policies in the network and at the endpoint. (See RSA Takes Suite Approach to Data Leak Prevention.)

The two companies will also collaborate to integrate products for data center security, data encryption, key management, and PCI compliance. In addition to integrating their products, the vendors will develop joint services for helping enterprises to define and configure the technologies. The two companies will sell their respective technologies alongside each other, officials said.

"We think this may be a market-changing partnership, one that will create a whole new category of products," said Tom Corn, vice president of data security products at RSA.

"What we're doing is allow companies to decide what the best policies are for handling a particular type of data, and then enforce it," said Richard Palmer, senior vice president and general manager of security products at Cisco.

RSA last week rolled out its new DLP Suite, which can conduct deep packet inspection of data to help identify information that might be sensitive to the enterprise. The RSA suite focused primarily on data at rest, although there was a DLP Network product that is designed to monitor email data via a device that attaches to a spam port.

The Cisco partnership will help RSA to provide the means to track -- and potentially restrict or block -- the transmission of data across the enterprise network, officials said. The two companies are also looking at ways to integrate their respective methods for classifying sensitive data.

"We're still early in the collaboration, so there are a lot of things we could potentially do that we aren't ready to talk about yet," said Bob Gleichauf, Cisco's CTO.

Cisco's Security Agent (CSA) will likely be unified with DLP Endpoint, RSA's agent for enforcing data security policies at the end station, RSA officials said.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Palo Alto Networks Inc.


  • Subscribe to RSS










    Bugs
    ENTERPRISE VULNERABILITIES
    Vulnerability:suse linux
    Published:2010-01-22
    Severity:High
    Description:SUSE Linux Enterprise 10 SP3 (SLE10-SP3) configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:The URL validation functionality in Microsoft Internet Explorer 7 and 8 does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."
    Vulnerability:bind
    Published:2010-01-22
    Severity:Medium
    Description:ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.
    Vulnerability:ie
    Published:2010-01-22
    Severity:High
    Description:Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.


    Briefing Centers
    POWERFUL INFORMATION
    AT YOUR FINGERTIPS
    (SPONSORED LINKS)