|
|
||||||||||||||||||||
| Home > Data management / BI News > IBM mainframe encryption: The gold standard for security does an upgrade | |
| Data management / BI News: |
|
||
IT security is like spinach — necessary for well-being, but few enjoy it. However, the advent of business compliance is a rare opportunity to improve both security and the benefits derived from it. Thus, IBM's recent announcement of software for encrypting file formats on mainframe tapes and disks, is not merely another System z9 encryption story: It rounds out an IBM mainframe security solution that should set the standard for another generation of business-critical system security. IBM says its new System z9 z/OS software is specifically aimed to "help organizations … adhere to compliance laws." Over the last 30 years, at the least, customers have testified that the IBM mainframe is the "gold standard" for IT security, one that users depend on to protect their most trusted computer-based information assets. The new announcement shows that IBM senses the new difficulties and opportunities of security, and is moving proactively to answer customer needs. So what is the impact of business compliance on security, and why is IBM's response appropriate? Business compliance and security In IT terms, business compliance is primarily about ensuring rapid access to information required by regulatory or legal authorities — all kinds of information, and access no matter how old the data is. Business compliance impacts an environment in which the main focus of security has been the prevention of access to key proprietary information by unauthorized users. Enterprises may have accomplished prevention by disguising data (encryption), by erasing data as soon as possible, by removing data as soon as possible to a secure facility (archiving), or by controlling access to the data (access control, firewalls, and so on). In other words, security has emphasized keeping people outside a carefully chosen circle away from information; business compliance emphasizes giving new people outside that circle (and outside the enterprise) access to information. Table 1 below shows the evolution of security caused by the clash between security and business compliance concerns.
Note that the result of these changes is actually to make security better than before — with less performance overhead, more comprehensive and integrated across all enterprise information, more applicable to inter-organization communication, better integrated with risk management and disaster recovery. Thus, security is harder to do; but, once done, delivers more benefits. IBM's Response Table 2, below, shows the ways in which IBM System z9 is aiming to incorporate the needed changes in security.
In other words, IBM is extending System z9 security primarily by (a) integrating security with expanded business compliance and disaster recovery solutions in the servers and in the z/OS operating system and (b) expanding security offerings to improve performance and widen the scope of users employing IBM mainframe security (e.g., to more users outside the enterprise). Conclusions The bottom line is that while the mainframe is the gold-standard of security, it's not hack proof—and IBM is smart enough to know it. Take the time to make this upgrade. Big Blue has made it worth the effort.
This document is subject to copyright. No part of this publication may be reproduced by any method whatsoever without the prior written consent of Infostructure Associates. All trademarks are the property of their respective owners. While every care has been taken during the preparation of this document to ensure accurate information, the publishers cannot accept responsibility for any errors or omissions.
About Infostructure Associates Infostructure Associates is an affiliate of Valley View Ventures that aims to provide thought leadership and sound advice to both vendors and users of information technology. This document is the result of Infostructure Associates sponsored research. Infostructure Associates believes that its findings are objective and represent the best analysis available at the time of publication.
|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| About Us | Contact Us | For Advertisers | For Business Partners | Site Index | RSS |
|
|
|
|||||||