New from Aveksa — RSA take note

Opinion
Jun 21, 20112 mins

Aveksa just announced version 5.0 of its suite of Access Governance automation solutions, and there’s a lot of meat in this release.

New product capabilities include data access governance for Windows File Shares and SharePoint, application server and Oracle RAC (Real Application Clusters) clustering for effectively unlimited scalability, and VMware certification to enable virtualized datacenters and private cloud-readiness.

In order to encompass all of this governance and to improve access and scalability, Aveksa now provides XMDB (the Access Management Database), a new architectural concept, in which the access repository, due to its expanded scope and scale, now serves as the authoritative source for user access within the enterprise. They compare it to a Configuration Management Database (which provides a full picture of configuration information for IT operations, aiding IT with its tasks of managing and controlling IT infrastructure). Aveksa believes that XMDB empowers business users to properly see user access, manage entitlements, and respond to access lifecycle events and changes.

ANALYSIS: Cloud computing makes IT access governance messier

In a Windows environment, Aveksa’s new Data Access Governance module provides enterprises with the ability to easily implement access management and governance for unstructured data, including Microsoft SharePoint and Windows file shares. Clients will be able to:

• Gain visibility of ownership and user entitlements for Windows Servers, file shares and Microsoft SharePoint sites;

• Automate data access certification processes for the lines-of-business, including identification of business owners;

• Remediate inappropriate access and put in place a consistent methodology for group-based access to file shares and SharePoint;

• Enable a closed-loop validation process for change to data access permissions;

• Determine whether access policy and control objectives are being met;

• Manage data access risk and provide auditable evidence of compliance.

The folks from Aveksa were quick to point out to me that two recent big news data breaches — the WikiLeaks case and the RSA mess — could have been prevented by using tools such as those in this release, and I heartily agree.

Rock solid, scalable data access governance is something every organization with resources to protect needs to have, and needs to have right now. It’s one of the only effective tools available to combat both spear phishing and insider breaches.