Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > What components should an application security management system (ASMS) have?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What components should an application security management system (ASMS) have?

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 12 September 2006
My company would like to buy an application security management system (ASMS), which would control our security processes and manage our Web-based applications. Ideally, the system would implement online registration for different online applications, including Internet, intranet or extranet. It's important that the ASMS system provides single sign-on features for both internal authenticated users and external users. Is there a product out there that will satisfy our needs?

>
There are three different components that you should incorporate in any application security management system (ASMS): an authentication method to verify and allow access for legitimate users, an application-level firewall to protect your Web sites and a single sign-on (SSO) product.

That's a pretty tall order for one product. You may want to take a look at a combination of some of the following products, each of which has one or more of the elements you require.

A flexible Web authentication product is NetSwift iGate from SafeNet Inc. This product is a hardware appliance that sits between your Web server and your firewall. Users then need a token and a PIN to access Web-based applications. The product can control external access to your Web applications, as in an extranet, or it can also function with corporate intranets. The product is only meant for accessing Web applications, not an entire company's network, but this authentication tool would still be compatible with many of your existing applications. NetSwift iGate uses SSL for all connections but isn't an SSL VPN, which is a yet another authentication option you might want to consider.

If you're in need of an SSL-VPN tool, consider using an Aventail Corp. product as their line can be fine-tuned to allow access to only selected portions of your Web applications. You can then customize your access controls as you see fit. Aventail products can also be integrated into Active Directory, and are then compatible with Windows environments. However, because an SSL VPN enables only remote or external access, to meet your internal needs, the network will have to be combined with another product.

As for application-level firewalls, Breach Security Inc.'s BreachGate WebDefend offers application-level security for Web programs. This product uses a series of threat-detection engines to analyze and look for malicious traffic, even after it has passed through your firewalls and intrusion detection systems (IDS). The engines use a variety of techniques to match threat signatures, analyze HTTP protocol misuse and check for known Web and application attacks.

In terms of the SSO piece of your setup, a suitable lightweight product is OneSign from Imprivata Inc. This device is a hardware-based SSO product. Unlike traditional SSO products, which use software modules installed on existing servers, this is a stand-alone device. Depending on the size of your organization -- Imprivata's products are geared toward SMBs -- these highly customizable products may be what you're looking for. As new applications are developed, they can be added to the product via its Web-based interface.

However, before jumping into a range of products, it would be best to carefully evaluate your needs, your organization's size and the compatibility of these products with each other, your network and your Web servers.

For more information:

  • Attend our Identity and Access Management Security School and learn the keys to establishing a more effective identity and access management plan.
  • Learn how SSO can help enterprises.

  • BROWSE BY TAG
    Identity Management and Access Control,   Enterprise Single Sign-On (SSO),   Enterprise Identity and Access Management,   User Authentication Services,   Application and Platform Security,   Application Firewall Security,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Identity Management and Access Control
    Is Identity Management as a Service (IDaaS) a good idea?
    How to log in to multiple servers with federated single sign-on (SSO)
    How to confirm the receipt of an email with security protocols
    Learn about enterprise strategy for server virtualization single sign-on
    Employee information security awareness training for new IAM systems
    Can you combine RFID tag technology with GPS to track stolen goods?
    Is there a free enterprise-caliber password-management tool?
    Cryptosystem attacks that do not involve obtaining the decryption key
    Can any firm or organization get a digital signature certificate?
    Should the CTO have domain administrator access?

    Enterprise Single Sign-On (SSO)
    How to log in to multiple servers with federated single sign-on (SSO)
    Security on a budget: How to make the most of authentication tools
    Best Identity and Access Management Products
    Changing times for identity management
    Kerberos configuration as an authentication system for single sign-on
    How to use single sign-on for Web access control to prevent malware
    Learn about enterprise strategy for server virtualization single sign-on
    Enterprise single sign-on: Easing the authentication process
    Exploring authentication methods: How to develop secure systems
    User provisioning and SSO for PeopleSoft- and Unix-based products
    Enterprise Single Sign-On (SSO) Research

    Application Firewall Security
    Web application firewall use goes beyond compliance, company finds
    Best Application Security Products
    Common PCI questions: Web application firewalls or source code review?
    IT pros find corporate firewall rules tough to navigate
    PCI compliance requirement 1: Firewalls
    Comparing an application proxy firewall and a gateway server firewall
    Citrix virtual desktop, app delivery controller includes security benefits
    How to choose between source code reviews or Web application firewalls
    Check Point adds virtual firewall appliance
    Web application firewall deployments gain traction

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    single sign-on  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts