Unified security management and opera小站tion and maintenance audit soluti空場on for banking industry
Industry pain points and needs

With the development of the Inter得不net, people's demand for online sh熱如opping and e-commerce is increasing, w匠麗hich urges the banking industry to vigo為分rously develop online business a又區nd provide financial services to 習麗the public through Internet channels 有街such as mobile payment and online會玩 banking. At the same time, how校動 to ensure the normal operatio畫區n of these infrastructure assets and t章睡he non disclosure of core data, It has好下 become a big problem in the bankin好木g industry to avoid unauthorized acc工白ess by internal personnel and intrusion歌城 and attack by external hackers.月民 A bank is a national joint-stock c可習ommercial bank approved by the CBRC. 司答With the implementation of cross 雜些regional development strategy, conti微下nuous expansion of business and con個場tinuous development and growth 雨笑of scale, once a business interrup身視tion accident occurs, even in a 黑呢very short time, it will cause制睡 great losses; The large amount of t時大ransaction data stored in the dat錯友abase not only involves economic 路員interests, but also contains pe友海rsonal privacy information. Once l門件eaked, it will cause irreparab低南le damage to the bank's reputati醫愛on. The risks and threats of i分火t information technology are increasi工畫ng day by day. How to ensure th睡的e stable and safe operation of the wh近通ole IT system has also become an ur件花gent challenge for decision-make師是rs and management.

Industry demand
In order to ensure the safety of東唱 the financial industry, the CBRC has a頻站lso strengthened the supervision of ba機行nks, issued various conditions and gui暗工dance documents to guide the informatio水靜n security construction and standar線冷dization of banks, so as to tak如謝e precautions and prevent data s現女ecurity incidents. It focuses on t內房he operation and maintenance operation場好al risk management, which requires 一行the unit to keep records of all operati國行ons in the background of the data cent話他er. The CBRC found many problems in t動能he risk assessment of the infor子海mation technology risk supervision and什為 inspection of the commercial 煙章bank, mainly as follows:

1. Account sharing and cross Man話子agement: since multiple mainte靜男nance personnel use one account for兵我 operation and maintenance at 和請the same time, in case of misoper懂快ation, the specific operator cannot be 麗你determined;

2. Authorization management: for hi土請gh authority accounts, there is no 花在good control method for authori話來ty. As long as the network is 麗多accessible and has a user name and pa技湖ssword, you can log in and operate the 你但background of the data center at any 美師time;

3. Operation behavior control: th農都e operation and maintenance personnel湖見 (maintenance agent) are opaque to the文森 background operation of the data ce輛農nter. The person in charge of the i民歌nformation center does not know他吃 who did what operation in the bac歌從kground at what time, and there is no 計行good monitoring method;

4. Data leakage: protocols such as RD劇吃P and FTP have disk mapping fun在放ction. If the transmission control of m數數aintenance protocol cannot be well cont筆畫rolled, the core confidential data has 事妹the risk of foreign exchange;

5. The source of database access 黃弟is complex, and it is difficult 數銀to determine the real visitors o一司f database operation;

6. The log record information of the d月冷atabase system is incomplete, an能購d the violation events cannot be fou個北nd in time and accurately;

7. The database operation process is co影說mpletely in the "dark box", so it is d看音ifficult to understand the detai裡放ls.


Our programme
Unified access entrance
Establish a unified secure operation an報離d maintenance access platform, 飛到provide a unified operation and main劇熱tenance operation portal for the core房腦 business system, and realize 動海single sign on. All operation 能校and maintenance personnel firs小少t log in to the unified operation 都西and maintenance platform to carry暗姐 out operation and maintenance o道靜n the system to realize unified a弟外ccess control and management;
Centralized account management
Realize centralized and role-based m計討aster-slave account management, establi工學sh one-to-one correspondence betw開訊een natural persons and equipmen短弟t accounts, uniformly manage equipmen什煙t accounts and modify passwords看人 regularly;
Strict authority control
Reasonably allocate the specific c議是onditions of users' use of resources 放我in the business system, realize th河公e legal access of different users 場線to different parts of entity resource火厭s, and eliminate illegal access a學舞nd unauthorized access. The auth中制ority of each operation and maintenanc機城e personnel shall be effectively co音得ntrolled, and the policy shall be deta黑嗎iled to the accessible equipment and年要 available account;
Improve post audit
Fully track and record the process樹民 of operation and maintenance, 嗎還and completely save all logs of oper動技ation and maintenance; Make stati劇又stics on natural person's acce習購ss to resources. In case of safety acci少訊dent, it can be defined as fau訊了lt and responsibility tracking; Au人問dit and handle the login process and事離 operation behavior of personn舞歌el, and establish and improve the 照黑complete audit of the "natural person →技知 resource" access process; Provide a有化udit platform and audit data for錢坐 regulatory authorities. The a老答udit provides a complete view 費空of videos and commands, and can provide快算 fast and accurate search and po照低sitioning;
Scheme high availability
The device bypass deployment does not n文頻eed to change the existing netw信來ork topology, supports dual machine 道動hot standby, cluster and distribute師雨d deployment, and improves the reli湖外ability of the platform. There i拍費s no need to install any agent on the離器 business system, which does not affec術間t the business.
Customer Benefits
Meet compliance
1. Meet the compliance audit require呢笑ments of it internal control, 東讀Sox, COBIT, insurance and other laws音如 and regulations; 2. Provide the ban美又king regulatory department with the au山影dit report of operation and maintenan是街ce management and the original and ac長舞curate operation and maintenance 中動log; 3. Help to improve the orga業林nization's it internal control and 用村audit system, so that the organizatio舊相n can successfully pass the IT audi北人t.
Reduce safety risks, fast fault loc民文ation and responsibility tracking
1. The technology of Fortress host 電空is adopted to avoid the direct connecti畫大on of illegal terminals and uns說站afe terminals to core resources, and re自多duce the impact of Trojans, spies and i風她nternal security threats on core r書好esources; 2. In case of safety accide鐵照nt, responsibility identificat南刀ion and safety event tracking can be c到外arried out quickly and accurately 話雜through playback of operation records要農; 3. As a third-party independe近年nt operation and maintenance audit船媽 management equipment, it realiz生土es the separation of use right窗海, management right and supervision rig討還ht; At the same time, it also helps 筆說supervisors obtain effective technical哥兵 means and improve the bank's it inter了少nal control mechanism.
Classic cases
  • Zhejiang Chouzhou commercial bank
  • Anbang insurance
  • Orient Securities
  • Founder futures
  • Everbright Futures
  • Hang Seng electron
  • GF Futures
  • Minsheng securities
  • Tianhong fund
  • China Merchants Bank
  • Bank of East Asia
  • People's Bank of China
  • China Development Bank
  • Citic Trust
  • Zheshang Bank
  • Ping An insurance
  • People's Insurance
  • Shanghai Dongfang fortune Futures Co., 輛也Ltd
  • Shangmeng Business Service Co., Ltd秒好
  • Shanghai paipaidai Financial Informat國不ion Service Co., Ltd
Copyright © 2019 All Rights Res不木erved Designed
Hangzhou pldsec Network Technology 個飛Co