|
|
Database and Application Data Security
Perimeter security is no longer enough to protect your business from information leaks and breaches. Even with state-of-the-art network security, sensitive data is still vulnerable in transit and at rest. GlobalSCAPE partners with industry leading security companies to deliver comprehensive information security solutions.
Key Benefits
- Encryption and Key Management - Encrypt data locally at the database or application. Use a centralized key manager to generate, distribute, rotate, revoke, and delete keys. Straightforward, secure key management enables encryption and allows only authorized users to access sensitive data. Application performance is not degraded because encryption takes place on the database rather than an external system such as a hardware security module (HSM). In addition, the system works properly even if there is a temporary problem with the connection to the HSM.
- Tokenization of Sensitive Data – Tokenization generates format-preserving tokens and inserts them in place of the sensitive data, then encrypts the original data and stores the cipher text in a central data vault. Encryption and tokenization are perfect companions to strong perimeter and firewall protection – even if the bad guys manage to get in, as long as the sensitive data is encrypted or tokenized no matter where it rests (and the keys are inaccessible), it will be useless to them.
- PCI DSS Compliance - Encrypt credit card numbers without changing your pre-defined file layout, your application screens, or your reports. Rotate keys easily and specify how keys will be handled (unsafe keys equal unsafe data).
- Reduction of PCI DSS Audit Scope - By using tokens as substitutes for credit card information, applications never require access to tokens’ underlying value. The tokens are then considered "out of scope" and do not need to be audited for PCI DSS compliance. This benefit can reduce the workload and costs of a PCI DSS audit.
- Complete Transparency to Applications - By replacing sensitive data with tokens in the same format as the original data, no changes are necessary to the data store schema for the tokenized data, and any applications that use the data do not require programming changes. This reduces the time and effort necessary to bring existing systems into PCI DSS compliance.
- Multi-Platform and Multi-Database Support - Supports all major operating systems including Windows, Linux, Solaris, z/OS, HP-UX; and all major databases including Microsoft SQL Server, Oracle, and IBM DB2.
|