SecureData Security, part of JSE-listed SecureData Holdings and the sub-Saharan distributor for RSA, the Security division of EMC, today announced that the latter's Adaptive Authentication solution and Data Loss Prevention (DLP) Suite, have been certified to meet the security requirements defined by the Common Criteria Evaluation and Validation Scheme (CCEVS).
Common Criteria is a globally accepted standard for evaluating the security features and capabilities of information technology products.
US federal agencies are increasingly offering online portals for both citizens and non-governmental organisations to access sensitive information and to advance the access and exchange of sensitive information across agencies.
However, external threats such as cyber attacks continue to increase and grow more sophisticated, creating a significant challenge for the safeguard of social security numbers, confidential intelligence reports and other sensitive data. In addition, insider risk can cause accidental leakage or misuse of sensitive data as it is collected, stored and shared. These external and internal threats can be mitigated by the RSA Adaptive Authentication solution and the RSA Data Loss Prevention Suite.
“RSA continuously works to provide organisations within the public and private sectors with solutions that meet key standards, including those that require third-party-validation," commented Sam Curry, Vice-President of Product Management at RSA. "Critical to this success are Common Criteria certifications that meet US federal agency requirements for the evaluation and purchase of information security technologies."
Common Criteria Certification
The CCEVS is an internationally recognised ISO standard (ISO/IEC15408) used by governments and other organisations to assess the security and assurance of technology products. Common Criteria certification provides assurance that the process of specification, implementation and evaluation of a computer security product has been conducted in a rigorous and standard manner.
In the United States, federal agencies mandate that all IT products purchased by the government for national security systems, which handle classified and some non-classified information, are Common Criteria certified.
To gain compliance, a product's security features are evaluated by an accredited commercial testing lab using Common Evaluation methodology. This is followed by an independent validation of evaluation results via Common Criteria authorised schemes, assessing the results of security evaluations conducted by licensed, independent labs. The resulting certification and validation report demonstrates conformance to Common Criteria.
Common Criteria Certified Solutions from RSA
* RSA Adaptive Authentication (on premise) is a risk-based authentication and fraud detection platform used by more than 8 000 organisations, authenticating over 250 million users, including many government agencies. Through risk indicators powered by the RSA Risk Engine, such as device identification, IP geo-location, behavioural profiling, and fraud data from the RSA eFraudNetwork community, Adaptive Authentication is able to protect government portals against advanced cyber threats.
* The RSA Data Loss Prevention (DLP) Suite helps uncover organisational risk associated with the loss of sensitive data and dynamically lowers that risk through policy-based remediation and enforcement of controls across the enterprise. The suite includes RSA Data Loss Prevention Endpoint, RSA Data Loss Prevention Network, and RSA Data Loss Prevention Datacentre - all managed by the RSA Data Loss Prevention Enterprise Manager.
* RSA Digital Certificate Solutions are interoperable modules designed to manage digital certificates and create an environment for authenticated, private and legally binding electronic communications and transactions.
Currently under official evaluation for Common Criteria Certification:
* RSA enVision platform
* RSA Access Manager
For further information, please contact Mark Linnell at tel. +27 11 790 2500; fax +27 11 790 2599; e-mail markl@securedata.co.za.
RSA
RSA, the Security Division of EMC, is the premier provider of security solutions for business acceleration, helping the world's leading organisations succeed by solving their most complex and sensitive security challenges. RSA's information-centric approach to security guards the integrity and confidentiality of information throughout its life cycle - no matter where it moves, who accesses it or how it is used.
RSA offers industry-leading solutions in identity assurance and access control, data loss prevention, encryption and key management, compliance and security information management and fraud protection. These solutions bring trust to millions of user identities, the transactions that they perform, and the data that is generated.
SecureData
SecureData is a specialist, value-added distributor of perimeter, application, network, endpoint, storage and identity information security solutions and risk management solutions for the African sub-continent and Indian Ocean islands. A cross-section of the available solutions from SecureData illustrates wide coverage of the following information security and risk management domains: business continuity, security appliances and devices, hardware authentication, identity and access management, security and vulnerability management, secure content management, threat management and security services.
SecureData's information security and risk management solutions include best-of-breed solutions, devices and appliances for the perimeter, data centres, applications, network, endpoints, messaging and Web. In addition, as a value-add to vendor, channel and customer, SecureData also provides a full complement of support, pre-sales and professional services around the solutions positioned in each discrete security vertical.
For more information, visit SecureData at http://www.securedata.co.za.
Editorial contacts

