Friday, November 12, 2010

The PCI Security Standards Council Updates PCI DSS (V2.0)

Changes are logging-focused & intended to help businesses improve compliance and security

The PCI Security Standards Council (XYPRO is a member) officially unveiled updated versions of compliance with changes meant to clarify the requirements organizations face. The changes are coming as a direct result of the feedback the PCI Security Standards Council has received, and should help your business with its security and compliance efforts.  

The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.

The key revisions cover areas such as log management and scoping the environment to understand where cardholders reside.  In fact, the council is pushing hard for centralized logging, stating that:

“If you don’t use a centralized logging facility your auditors will have to look in more places, and chances are, if they have to look in more than one place...you’ll wind up missing some of this stuff.  It is a "proven fact that every time we find a breach, it’s always found in the log.”

This change also coincides with HP adding XYGATE Merged Audit Software with every new NonStop server order. 

This centralization of NonStop Audit can also be sent Off-box to a centralized logging facility like HP's CLW and Arcsight offerings, meeting the Centralized Logging Facility requirement at the Enterprise Level.

There were also revisions meant to enable organizations to develop a risk-based assessment approach based on their specific business circumstances as well as changes designed to appeal to small merchants to simplify their compliance efforts.

The new versions will become effective Jan. 1. For more information, you can click here

For more information about the XYGATE Solution, visit www.xypro.com.

Wednesday, November 3, 2010

CTUG 2010

The much anticipated CTUG (Canadian Tandem User Group) has come and gone and, as expected, was a great success for all in attendance. Content for this year’s event was excellent with a great update from Randy Meyer on the state of HP NonStop, growth, and technology advancements. It is always great to hear from the proverbial “Horse’s Mouth” and also reassuring that HP NonStop is not only surviving, but thriving!

Naresh Bangia of AJB Software delivered an interesting and informative presentation on the exciting results of their port of .NET to NonStop. With a “Live” demo which included a “drag and drop” example of NonStop code to Windows that executed perfectly on both OS’s! All this with a weak signal on a mobile wireless internet stick that required some comedic and creative physical positioning within the conference room to maintain connectivity.

Jim Johnson of the Standish group also presented on their recent paper “Roadmap to the Megaplex” covering the overall CTUG theme of Modernization and showed just how profitable modernizing applications and utilities can be.

As always, the Q and A session highlighted some interesting facts and brought up many discussion points. Dick Bird, Michelle Bates, and Randy Meyer all provided answers which inevitably lead to more questions. The end to the Q and A session was achieved only by the enticement of the much anticipated CTUG prize draw where all 20 partners who participated in the “Passport to Prizes” program, HP Canada, and CTUG had donated fabulous gifts as appreciation to those attending the event.

XYPRO was among the 9 partner presentations which were held throughout the day and Kevin Boham provided modernizing insight on Security for the NonStop to an attentive and interactive audience.

CTUG and XYPRO were glad to welcome those out of province attendees from Quebec as well as the many faithful and new from Ontario. Their attendance from near and far indicates the continued need for NonStop events such as CTUG. With attendance nearing 140, CTUG had exceeded its capacity and were glad the Fire Marshalls didn’t pay an unexpected visit.

The day’s closing reception also kept the majority of attendees into the evening for some socializing, good food, and drinks to cap off an excellent day.

More indicative of the continued commitment to NonStop was the record attendance for the education day where CTUG had 44 registered students for a one-day class on Java Servlets/NSJSP in the NonStop.

As a CTUG board member as well as a Partner for the event, I now have the short term opportunity to decompress after months of planning and executing. …short term as XYPRO is planning their next attendance at a regional event… NENUG in the Boston area on November 9th.

Barry Forbes

XYPRO Technologies, Director of Sales, Eastern USA and Canada
President, CTUG

Thursday, October 7, 2010

San Jose – let’s not forget the way...

Well, the Big Event is over. The vendors have packed up their booths, the booze is all gone, and the HP product managers, developers, and execs are safely home in their remote offices.  And even though the weather was almost the same, everyone in attendance overwhelmingly preferred San Jose to that other city.  The HP NonStop Symposium and EXPO turned out to exceed everyone's expectations not only in terms of Customer attendance but also HP and Partner involvement.

Yes, this was the biggest and best NonStop event in years (and with a killer Tandem-style beer bust) where we proved beyond a doubt that there is still life in the NonStop family and the platform that runs mission critical applications for the world's largest companies. This year we were also able to spend time with customers that we have not seen in a while and the attitude was very much like the old (ITUG) days. Far more Europeans, Latin Americans and Asian customers were present than at HPTF in 2009 – several of whom were actively seeking tools to aid PCI compliance projects.

There were dozens of business and technical sessions, including standing-room-only customer how-to's, NonStop software and hardware roadmaps, and presentations from Vendor Partners. PCI compliance was a common theme throughout the event and it’s only going to increase.  Packed presentations by end-users Netherlands-based Equens and Wells Fargo Bank and HP’s Karen Copeland and Wendy Bartlett show just how in tune the NonStop Community is with PCI Compliance.  That illustrates just how much of our mission critical and confidential information is trusted to a NonStop!  It's amazing how much customers are willing to share their experiences because of the pride they have in their NonStop server applications tuned to perfection, secure and protected from disaster.

XYPRO specifically enjoyed an unprecedented amount of coverage at this event as we were lucky enough to have it take place right around the time our XYGATE Merged Audit software solution begins automatically shipping on all new H and J systems.  The interest level is extremely high and we are thrilled at the positive response!

Yes, a pleasant time was had by all and I hope that we remember it for a long time. The level of international customer attendance was inspiring!  The XYPRO customer dinner was very well received and we would like to thank everyone who attended.

It may seem a disappointment hearing that next year’s event will be part of the HP Software / Tech Forum conference at the Venetian hotel in Vegas, but your voices may have been heard. In his keynote, Winston Prather said that this event would be restructured to retain the strong community feel that this Symposium displayed. The big question is whether or not HP will be sending the same number of NonStop product managers and developers and it will be interesting to see how the big tent event achieves the incredible dynamic we all experienced in San Jose.  The amount of interaction with HP staff and customers was simply something we hadn't enjoyed in years and everyone seemed to revel in the long overdue opportunity. 

But hey, the next event is 9 months away and if customers take the time to communicate their preference - another NonStop Symposium in San Jose? You never know...




Lisa Partridge

Tuesday, September 28, 2010

ITUG 2010

ITUG 2010 (also called The Connect NonStop Symposium and Expo) opened with an amazing dinner hosted by XYPRO at Scotts seafood restaurant in San Jose.  Among the 130+ attendees was a real  cross-section of the HP NonStop community. Aussies, South Africans, South Americans, Asians, and Europeans joined the North Americans for a most amazing 3-course meal with dessert  and entertainment.

For those who managed to get out of bed on Tuesday, 499 other show attendees joined them at the San Jose convention center-and the mood was incredible. Everyone was happy to be back in San Jose at a NonStop show instead of in Las Vegas in the middle of Summer!

It was really heartwarming to some and interesting to others that even with HPTF (the heretofore-described show in Las Vegas), people came to this event.  I personally know of several NonStop customers who never intended to come to San Jose but went to Las Vegas. They determined the NonStop symposium was the place to be and are here with bells on and very happy they came.

The San Francisco bay area is in the middle of a heatwave, so people can close their eyes and pretend that they're in Vegas, then open them up to see dozens of NonStop product managers, developers, and execs who find it a lot more pleasant to drive the 5 miles down highway 280 from Cupertino than to take a 90-minute flight to Vegas after waiting an hour in the security line.

What happens in Vegas stays in Vegas, but what happens in San Jose has a big influence in Cupertino, helping build better products for the best computer system in the world. And isn't that a grand thing?

Lisa Partridge
XYPRO

Friday, September 17, 2010

XYGATE Software Exceeds Regulatory Auditing Requirements for HP NonStop Systems

State of the art auditing & compliance solution to ship with latest HP Integrity NonStop operating system

(September 14, 2010) Simi Valley, CA – XYPRO Technology Corporation, a leading provider of security software and services for HP NonStop server environments, today announced its audit and reporting solution, XYGATE Merged Audit (XMA) software, will be included in the HP NonStop Operating System Mission-Critical Edition software package.

This XMA software addition will allow customers to better monitor the state of their mission-critical systems.  XMA collects, filters, normalizes, and writes audit data from a variety of sources across dozens of systems in an HP NonStop system network.  The software then writes data to a consolidated NonStop SQL database.  These advances will allow security administrators to efficiently produce reports based on audit data from one or multiple sources, create real-time alerts for specific events, and feed many off-box central audit logging devices or SIEMs (Security Incident Event Monitor), such as the HP Compliance Log Warehouse (CLW), facilitating Integrity NonStop server participation in an Enterprise Security Program.

“Security has changed drastically over the last five years,” said Sheila Johnson, XYPRO’s CEO.   “Starting in September, customers who purchase new HP NonStop servers running on the J Series or H Series platform will receive XMA on their system.”

HP NonStop customers who wish to upgrade their existing systems can purchase an OS upgrade package that includes XMA software and entitles them to new versions of the product going forward.  XMA software also continues to be available for individual purchase and direct support from XYPRO.  

“In the current climate, many businesses are under increasing pressure to comply with regulatory audit standards – all while protecting their mission-critical data and resources,” said Randy Meyer, Director of NonStop Product Management, Strategy and Technology at HP. “HP is working with XYPRO to provide clients with solutions that simplify risk management and increase effectiveness of system monitoring in complex information security environments.”

“Bundling XMA software as part of the OS distribution provides customers with greater consistency, significant savings, comprehensive audit consolidation, and reporting,” said Lisa Partridge, XYPRO’s Vice President of Sales & Marketing.  “We are excited to work with HP to bring best-of-class security to the HP NonStop user community.”

Wednesday, September 8, 2010

From the CEO's Desk

We all know that the sun never sets on the HP NonStop server empire—especially in the financial industry. Worldwide, a large number of credit card and funds transfer transactions are either switched or cleared by NonStop servers. And since the bulk of those mission-critical NonStop servers protect their confidential information with XYPRO software, we felt that it was time that we had a seat at the payments processing table.

But rather than sitting back and listening, we wanted to have an active voice, to ensure that the needs of our users were addressed as new standards were implemented. To get that seat, XYPRO joined the PCI Security Standards Council as a participating member, which allows us to work with the Council to evolve the PCI Data Security Standard (DSS) and other payment card data protection standards.

Anyone who has read the PCI DSS knows that many of the requirements are aimed at so called “industry standard” servers and not big iron like the NonStop server. How many times have you been asked what anti-virus software is running on your server? Wouldn’t it be nice to stop hearing that question from your auditors?

In other news, the traditional NonStop Summit is back. Rather than hopping a plane to Las Vegas in summer, walking what seems like 4 miles from the hotel to the convention center every day, and fighting the crowds of gamblers and tchotchke divers hanging out at the Mandalay Bay, we get to be back among our own circle of friends just minutes from NonStop Central (or Cupertino, as Google Maps calls it). All of your favorite vendors have booths and are just as excited to be back in San Jose as I know all of you are. HP will be sending dozens of NonStop developers and product managers who can spend time with you to understand how to make their products better by meeting your needs.

In my last blog entry, I alluded to a number of exciting activities that I could not talk about—until now. If you’ve attended one or more Security SIGs, you’ll remember that the same requests get made over and over and every time HP recognizes that there are opportunities for improvement. Unfortunately, the development dollars just aren’t there to address every issue and HP needs to prioritize.

A substantial number of security upgrades have been made by HP, including longer passwords, better user management, a more secure password encryption algorithm, and so on. HP has been listening to you and over the past year, they quietly have been working to bundle selected third party products into the base NonStop OS.

At the summit, HP and XYPRO will jointly announce and demonstrate some of the most frequently requested security functionality being added to the NonStop OS at a low cost to customers. Current XYPRO customers don’t need to worry about past decisions or future support, since we have a migration path for you.

Watch for our press release later in September and be sure to drop by our booth at the Summit to see what’s cooking. If you just can’t wait, you can read Scott Uroff’s article in the July/August issue of Connect Magazine for a clue.

Before I close, I wanted to mention “The Most Significant Breach Of U.S. Military Computers Ever.” This has nothing to do with NonStop servers, or even HP. It began when an infected flash drive was inserted into a U.S. military laptop at a base in the Middle East. The flash drive's malicious computer code, placed there by a foreign intelligence agency, uploaded itself onto a network run by the U.S. Central Command. That code spread undetected on both classified and unclassified systems, establishing what amounted to a digital beachhead, from which data could be transferred to servers under foreign control.

It was a network administrator's worst fear: a rogue program operating silently, poised to deliver operational plans into the hands of an unknown adversary. There is only one protection against rogue software or a rogue user in the enterprise and that is encryption at a very granular level. It will take an attacker a lot longer to steal your information if they need to do it one small piece at a time as it is displayed on someone’s screen than if they can just download an entire unencrypted file in one shot.

Scott Uroff wrote an article in the January/February issue of The Connection magazine that can help you understand the importance of selecting the right encryption algorithm and how to properly implement it. If you have questions, Scott will be at the XYPRO booth and the Summit to answer them.

Don’t pick up an unknown flash drive and connect it to your network, but do come to the NonStop Summit. See you there!

Sheila Johnson
XYPRO, CEO

Friday, August 27, 2010

Product Spotlight: Safeguard PRO

SAFECOM is the original user interface to Safeguard, the native HP NonStop™ server security program. Both were developed at a time when highly trained HP NonStop technical staff managed HP NonStop security exclusively. However, today’s security requirements are not only more complex and scrutinized, but security is often managed by an information security department whose staff rarely consists of single-platform experts. Instead they are information security specialists with responsibilities across many different computer platforms.

Why Safeguard PRO?
Safeguard PRO brings together all the capabilities of the XYGATE Safeguard enhancement modules to offer you a single source for achieving your Safeguard-related security requirements. A friendly and intuitive user interface adds to the ease of use and allows the Security Administrator, whose responsibilities can span several computer platforms, to take care of the HP NonStop platform with ease.

What Do I Get with Safeguard Pro?
The XYGATE Safeguard PRO package consists of 5 integrated modules, each addressing specific Safeguard security requirements. Every aspect of Safeguard Administration, Audit, Authorization, and Authentication (including interfacing to LDAP) is enhanced and made efficient with XYGATE Safeguard PRO.

 XYPRO’s Safeguard PRO is an enhanced Safeguard manage¬ment, configuration and reporting package that extends the capabilities of Safeguard with unrivaled user authentication, password quality and object security power.

How Do I Learn More about Safeguard PRO?
Click here to learn more. You can download free product information and view a product demo.