Sarbanes-Oxley ComplianceHow do you auditing and reporting on machine-to-machine interactions in a SOA? | |
The Problem: Knowing Which Machine Accessed What, WhenThe financial controls and reporting required by the Sarbanes-Oxley Act of 2002 (SOX), forces companies to rethink how they govern their IT processes. In particular, section 404 requires every publicly registered company to demonstrate the effectiveness of their internal control structures and reporting procedures. This requires identity and access infrastructure that can both control and validate user-machine interactions as well as SOA-based machine-machine interactions. Because SOA transactions can span multiple intermediaries, transports and identity domains this is difficult to implement in practice. Solution: SOA Auditing and ReportingSection 404 requires effective and demonstrable internal control structures and reporting procedures for financial information in all publicly registered companies. This requires: A framework for controlling and auditing who accesses financial information. Layer 7 Value: SOA GovernanceThrough the SecureSpan Firewall and VPN, Layer 7 can uniquely satisfy Sarbanes-Oxley requirements for SOA. The SecureSpan Firewall can extend existing identity systems to Web services including identity information for machines. The SecureSpan Firewall and VPN working in concert can provision and manage PKI to SOA consumers and provide an extensive evidence trail for distributed cross-domain authentications. For managing and auditing access decisions in a SOA, the SecureSpan Firewall can be deployed as either hardware or software, managing any number of cascading SOAP and non-SOAP Web services. Access decisions can be based on URL, URI, SOAPAction or user defined XML element and can be orchestrated with other policy instructions defined inside the SecureSpan Firewall or an external policy store. To protect the integrity of financial information passed across a multi-hop SOA transaction, the SecureSpan Firewall and VPN product line provides the seamless definition, application and enforcement of XML / SOAP encryption and signing using a simple graphical user interface. To protect against compromises including message spoofing (man-in-the-middle attacks) or session hijacking (replay attacks), the SecureSpan Firewall automatically negotiates cryptographic keys each security session with the SecureSpan XML VPN Client or any WS-SecureConversation compliant client application.
Share: | More | ResourcesWhite Paper: Download PDF | 6Kb
Download PDF | 196Kb
Solution Brief: Download PDF | 208Kb
Download PDF | 196 Kb
Solution Brief: Download PDF | 208 Kb |