IBM has announced the release of comprehensive solutions for helping to combat Web application attacks and to secure the integrity of data processed by Web applications, as part of its ongoing strategy to deliver security solutions designed to address today’s most significant security risks.
As threats and attacks increasingly target Web applications, many enterprises have been forced to take a reactive approach to security with point products that address only pieces of Web application security and add to the complexity of security operations. IBM has brought together the breadth of its offerings designed to deliver end-to-end Web application security that includes security-rich code development, vulnerability management, real-time blocking of attacks, dedicated security and performance for Web services, and access management.
IBM’s integration of its Web application security offerings can help enable enterprises to combat these types of attacks. The latest component of the solution, IBM Proventia SiteProtector 8.0, integrates a consolidated security management system with Rational AppScan, a solution for Web application vulnerability and secure code testing; and IBM’s recently announced Web application protection module for network and host intrusion prevention systems.
Because Web applications often rely on Web services and service oriented architecture (SOA), IBM has integrated the security and governance features of the purpose-built WebSphere DataPower SOA Appliances with the centralised management of Tivoli Security Policy Manager. The combination of Tivoli Security Policy Manager and WebSphere DataPower SOA Appliances can help to enable enterprise architects and security operations to align business and IT by centrally managing and enforcing security policies for Web services resources across multiple policy enforcement points.
IBM SiteProtector 8.0 is also a key offering in IBM’s Information Infrastructure portfolio, announced last week. Other offerings include Proventia Server for Windows 2008 – helping organisations harness the security and compliance challenges in the heterogeneous data centre, encrypted disk support for the System Storage DS5000; as well as IBM Tivoli Identity Manager 5.1 featuring role management for more effective enforcement of SOD, and Tivoli Security Information and Event Manager’s NERC module, security products that help improve security with little productivity impact.