Internal Security
Check Point and NetIQ
Today businesses are constantly forced to open access to their internal networks, leaving their resources more vulnerable than ever to security breaches and policy violations. To establish a safe and reliable communication between the Internet and the internal networks, companies need a solution that enables them to quickly identify and categorize threats and promptly respond to them, minimizing the overall exposure time.
To protect the internal resources, a comprehensive event monitoring and reporting solution should be in place together with an internal security gateway that blocks the spread of worms and attacks inside the network and provides network zone segmentation. It should offer policy-based security event management for the enterprise that is designed specifically to protect the confidential data in an increasingly complex and insecure business world. This solution should leverage advanced data collection, correlation, intrusion protection, monitoring, and reporting capabilities to deliver comprehensive security incident management across heterogeneous network devices.
With this type of event monitoring and reporting solution in place, the Check Point InterSpect internal security gateway receives a constant feed of information, ensuring the flow of legitimate network traffic while blocking any malicious attacks and quarantining the source from where they emanate. InterSpect can work in three in-line operating modes (bridge, switch, and router mode) allowing it to be deployed in various topologies. It can bridge one or more network segments to the backbone and thus be invisible to the IP network. As a switch, it can act as a multi-port bridge, bridging all ports together to make one zone. As a router, it enables every active port to be configured with its own IP address.
By combining Check Point InterSpect and NetIQ Security Manager, customers are able to proactively monitor and protect their internal resources. This combination also ensures compliance from all security sensors and tools. It alerts you about important issues, such as non-compliant firewall configurations or outdated virus signatures and vulnerability tests.
Benefits
- Stops the spread of worms, viruses, trojans, and DoS attacks that other technologies miss
- Assesses policy compliance and the impact of planned or unanticipated network events
- Identifies and prioritizes critical threats to resolve risks and events before they become crises
- Improves security knowledge by delivering an automated infrastructure that builds internal security knowledge for deployment and customization
- Increases protection levels and ensures layered defenses are in place to maximize the security posture
- Collects and correlates real-time and archived data from all security systems and devices to achieve true incident lifecycle management.
- Helps corporations comply with regulatory acts such as HIPPA and GLBA
NetIQ Security Manager
NetIQ Security Manager is a comprehensive security incident management solution for heterogeneous enterprise environments. By consolidating security data from across the enterprise and utilizing advanced correlation, intrusion protection, powerful visualization, and advanced reporting (including trending and forensics capabilities), NetIQ Security Manager enables the identification and response to key security incidents-all through a central security console.
NetIQ Security Manager reduces detection times through its real-time monitoring for security breaches and policy violations, as well as its extensive notification capabilities. It also optimizes reaction times with automated responses and security knowledge.
Customers can quickly resolve issues by combining the out-of-the-box NetIQ Knowledge Base with security knowledge specific to their company. NetIQ boosts operational performance and improves ROI by centralizing customer's best-of-breed security products into a central security console, enabling real-time notification and automated response to suspicious activity.
Check Point InterSpect
Check Point InterSpect is an internal security gateway that blocks the spread of worms and attacks inside the network and provides network zone segmentation. InterSpect is built specifically for internal network security and based on proven Check Point security technologies-INSPECT, Stateful Inspection, Application Intelligence, and SMART (Security Management Architecture).
Benefits
- Intelligent Worm Defender blocks the spread of worms and attacks inside the network.
- Network zone segmentation separates the internal network into organizational security zones.
- Quarantine of suspicious computers isolates attacks and compromised devices.
- LAN protocol protection provides the deepest and most comprehensive support for Microsoft and other LAN protocols.
- Pre-emptive attack protection provides proactive defenses against vulnerabilities and attacks before they are exploited.
- Endpoint security integration enforces endpoint security policies.
- Integrated SMART Management is scalable, easy to use, and easy to manage.