IBM i Security Tips
Carol Woodbury, Editor
May 2011

The Epsilon Breach and its Effects on your Organization
by Brian Hole
Special Guest Contributor

Epsilon is a part of Alliance Data Systems Corporation. It discovered a data breach on March 30th and announced it on April 1st.  

 

According to Epsilon "The affected clients are appropriately 2 percent of their total clients."  Approximately 110 clients' email databases were breached including JP Morgan Chase, Best Buy, Walgreens, and more.   

 

The compromised data included the combination of customer name and email address.  To date there has been no disclosure on how many records were stolen, however it can be inferred from the customer list it was a lot.   

 

No big deal right?  It's just email.  It's not credit card or social security numbers.  Wrong.  

 

Your security team should be reviewing incidents like this and ensuring that your corporate data is protected.  Let's explore the effects of this breach on your organization.


SECURITY NEWSSTAND
Michaels Breach Bigger than Reported  

 

Michael Stores initially reported that a scheme, in which point-of-sale pads customers use to key in their personal identification numbers, was isolated to Chicago, but on Tuesday the arts and crafts supplies retailer issued a statement that said nearly 90 stores in 20 states, stretching from Rhode Island to Washington, were affected.


 

Recent Database Breaches Teach Security Lessons -- The Hard Way    

If a hack successfully queries and exports hundreds of thousands -- or even millions -- of customers' records, you have a major problem that's likely to cost your company millions of dollars in notifications, incident investigation/recovery, and lost business.

Read the Complete Article

 

Verizon Data Breach Report: Bad Guys Target Low-Hanging Fruit     

Cybercriminals steering away from big caches of data, using simpler tactics to crack smaller enterprises.

 
SkyView Partners Products

SkyView Partners is dedicated to providing software to help you simplify and automate your security administration tasks and solve your compliance requirements.

SkyView Risk Assessor - Automated vulnerability reporting.
  •   Security begins with an assessment. Find out your system's vulnerabilities lie, receive an explanation of the issues and suggestions on where to start with SkyView Risk Assessor.
SkyView Policy Minder - Automated security policy compliance reporting.
  • Find out whether your system's security configuration is in compliance with your security policies and automate security administration tasks for the IBM i with SkyView Policy Minder

SkyView Audit Journal Reporter - Automated security event reporting. 

  • Get pre-defined auditor-ready reports are provided, allowing you to have the security and compliance reports you need without having to understand the complexities of the IBM i audit journal with SkyView Audit Journal Reporter.  
In This Issue
* The Epsilon Breach and its Affects on your Organization
* Michaels Breach Bigger than Reported
* Recent Database Breaches Teach Security Lessons -- The Hard Way
* Verizon Data Breach Report: Bad Guys Target Low-Hanging Fruit
* SkyView Partners Products

Webinar Recording

Simplifying IBM i Security Administration Tasks

 

 by Carol Woodbury 

How many IBM i security administration tasks do you regularly perform? such as  
  • discovering and managing inactive profiles,  
  • detecting changes to system values (along with who made the change),
  • discovering who or what process has deleted an object or created a program into a production library.
  • and many more 

Watch Carol Woodbury as she demonstrates how you can automate many of these every day security administration tasks.

 

Click Here to Watch: 

Simplifying IBM i Security Administration Tasks



Testimonials

"I was very comfortable with SkyView from the beginning. They walked me through the processes involved in assessing the current system and identifying the problem, and provided a roadmap and user training documents. It was easy to work with them and they made the changes solid and painless. "

"All Risk Assessor reports were very useful and we benefited by saving a lot of time in achieving a monthly in-depth assessment of our IBM i security versus performing a manual examination and maintenance on our own."

"The level of detail covered by Policy Minder is impressive. The ability to check compliance is great, but the fact that you can, for example, create a template for user profile settings and see who has more authority than they should, or create a library and file policy template and see whether these files are secured appropriately, or discover newly created profiles, libraries and files, makes this a tool that you quickly begin to rely on from a systems management point of view."

"The professional services that we have received from SkyView Partners regarding i-Series security are un-paralleled. The knowledge base, system models, project planning & impact analysis that Carol Woodbury brings in conjunction with the auditing capabilities of Risk Assessor and policy compliance aspects of Policy Minder have been the cornerstone of our i-Series security project. I can't imagine us getting as far as we have without Carol's expertise and guidance."

Follow us on Twitter      Find us on Facebook
  SkyView Partners is an IBM Advanced Business Partner