下载PDF
BeyondTrust > 实例探究 > Financial Firm Secures Its Private Cloud
BeyondTrust Logo

Financial Firm Secures Its Private Cloud

技术
  • 网络安全和隐私 - 身份认证管理
  • 基础设施即服务 (IaaS) - 云计算
  • 基础设施即服务 (IaaS) - 私有云
适用行业
  • 金融与保险
适用功能
  • 商业运营
用例
  • 网络安全
服务
  • 系统集成
  • 测试与认证
挑战
The financial institution was facing challenges in validating virtualization security, controlling access, and securely authenticating users. An internal security audit revealed that its VMware ESX systems, Red Hat Linux VM guests, and Solaris systems were configured with file-based methods of user authentication and access control. The staff responsible for user accounts lacked the expertise to manage and synchronize accounts for every type of operating system. The firm was using Active Directory 2003 R2 for its Windows servers. The administrators attempted to implement Active Directory authentication on their ESX hosts by using VMware’s configuration scripts. Although Active Directory’s Kerberos authentication provided single sign on, it provided only part of the desired solution.
关于客户
The customer is one of the world’s most recognizable financial institutions, serving businesses and other financial organizations throughout the United States and internationally. It provides a range of financial services that requires highly available and recoverable production information systems made possible through VMware virtualization. The firm has a comprehensive virtualization plan, selecting VMware Infrastructure 3 and VMware ESX bare-metal hypervisors to provide support for a majority of internal and external customer-facing deployment scenarios. By the end of 2009, more than 80 percent of the application servers would be VMs hosted in VMware and the infrastructure would span more than 30 ESX servers.
解决方案
The company began testing commercial AD-bridge software products that would support all the operating systems in its data center, including its VMware ESX servers. In addition to providing Kerberos authentication that is compatible with Active Directory, AD-bridge software also provides security policy management and audit and reporting functions. The firm chose PowerBroker Identity Services (PBIS) for its ability to integrate VMware ESX and other operating systems into Active Directory for access control and authentication, control security and sudo with group policies and Active Directory’s hierarchy of organizational units, audit access and activity on VMware ESX systems, and BeyondTrust’s exceptional support and professional service offerings. Moving completely to Active Directory for user management saved the institution significant time in provisioning new users.
运营影响
  • The firm was able to implement a hierarchical security policy across all its systems with both standard domain security policies and sudo policy configured for domain identities, allowing the firm to lock down its systems.
  • With PBIS’s features for auditing and compliance, the firm was able to validate its virtualization security with regular reporting and respond to security exceptions through consolidated event log analysis.
  • The firm was able to join 30-plus VMware 3.5 ESX Servers, 50-plus Red Hat guests, and additional Solaris and AIX systems to Active Directory.
数量效益
  • Reduced workload for server and identity administrators.
  • Streamlined logon processes for users.
  • Eliminated costs associated with password resets and user account turnover that would otherwise have required reconfiguring more than 30 VMware ESX systems on a 30-day schedule.

相关案例.

联系我们

欢迎与我们交流!

* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

Thank you for your message!
We will contact you soon.