Getting Started with IBM i Security

IBM i (OS/400, i5/OS)
Typography
  • Smaller Small Medium Big Bigger
  • Default Helvetica Segoe Georgia Times

It's a growing concern.

 

Data security, while always a business concern, rose to critical prominence after 2012. The year was a record-breaker in both size and scope of breaches; there were massive distributed-denial-of-service (DDoS) attacks against financial institutions, not to mention the shocking incident at the South Carolina Internal Revenue Service, a breach that spanned several months and resulted in 44 systems being compromised.

The tools hackers use to orchestrate their efforts have also evolved considerably—cybercriminals are leveraging cloud technology to make their botnets more powerful, and the proliferation of exploit kits has made it much easier to spread malware.

While the IBM i platform excels at preventing threats like DDoS attacks, it is important to consider all types of risk and how to best mitigate them.

IBM i comes with a built-in security facility, tempting operators to forgo other solutions. But concerns exist over whether these controls are correctly implemented. Are they enough to prevent today's sophisticated attacks? And what can IT do to prevent other issues, such as threats coming from inside the organization?

What IBM i Does Well

The good news for organizations with IBM Power Systems servers running IBM i (AS/400, System i, iSeries) is that the platform has numerous built-in features for safeguarding against a myriad of common threats, including:

• Object-level authorization controls

• Intrusion detection and prevention system (IDS)

• Security audit journal

• System history log

• Virus-resistant architecture

IBM i's IDS is a powerful tool that guards against external attacks, such as hacking, malware, and DDoS attacks. Administrators can set up traffic thresholds and have the IDS automatically send notifications when traffic exceeds the predefined amount. In fact, the IDS works so well that some believe it's the only thing they need to prevent costly data leaks.

However, few if any systems are ever completely bulletproof. One of the factors that made the South Carolina data breach unique is that the attackers did not have to hack the organization's systems to gain access to information. They had legitimate user account credentials, which is also what allowed them to stay under the radar for so long.

 

As a result of these more sophisticated attacks, IT professionals must build layers of security into their IBM i systems to protect against threats that come from both inside and outside of their organizations.

 

Insider Threat: Filling in the Security Gaps

The "insider security threat" made international head-lines when former National Security Agency contractor, Edward Snowden, leaked data about the organization's PRISM program. Such incidents are not isolated to government agencies, and there should be concerns for the majority of companies.

The Ponemon Institute's 2013 Cost of a Data Breach survey revealed that incidents caused by external criminals or insider malicious activity resulted in the most expenses—an average per capita cost of $157, compared with those caused by system glitches ($122) and human error ($117).

 

Because these breaches are orchestrated for the specific purpose of gaining access to sensitive information, they can incur costs ranging from compliance fines and legal settlements, to profit decline from damaged reputations.

 

Not all users are going to sell valuable intellectual property, but it highlights the need to implement user access and system monitoring tools. Additionally, it's not only about safeguarding mission-critical assets against data thieves—the IT department must also protect users from themselves. Not everyone inside of an organization is equally aware of how to handle sensitive data, and this can lead to information making its way onto unapproved platforms.

0 0
PowerTech is your security expert in managing evolving compliance and data privacy threats with automated security solutions for IBM Midrange Servers. Our ServerProven security solutions are straightforward and save your valuable IT resources, giving you ongoing protection and peace of mind.
 
Because IBM Power System (iSeries and AS/400) servers are used to host particularly sensitive corporate data, it is imperative that you practice proactive compliance security. As an IBM Advanced Business Partner with over 1,000 customers worldwide, PowerTech understands corporate vulnerability and the risks associated with data privacy and access control.
 
Eden Prairie, Minnesota-based PowerTech Group was founded by security experts in 1996. In 2004, PowerTech was awarded the prestigious Industry Driver APEX Award from iSeries NEWS. That same year, PowerTech also won the APEX award as the Editor’s Choice in the Security category. PowerTech is also the only iSeries security company to have been recognized as a finalist in the IBM Beacon awards.
 

The PowerTech security solutions provide definitive security coverage for iSeries and AS/400 systems.


BLOG COMMENTS POWERED BY DISQUS

LATEST COMMENTS

Support MC Press Online

$

Book Reviews

Resource Center

  •  

  • LANSA Business users want new applications now. Market and regulatory pressures require faster application updates and delivery into production. Your IBM i developers may be approaching retirement, and you see no sure way to fill their positions with experienced developers. In addition, you may be caught between maintaining your existing applications and the uncertainty of moving to something new.

  • The MC Resource Centers bring you the widest selection of white papers, trial software, and on-demand webcasts for you to choose from. >> Review the list of White Papers, Trial Software or On-Demand Webcast at the MC Press Resource Center. >> Add the items to yru Cart and complet he checkout process and submit

  • SB Profound WC 5536Join us for this hour-long webcast that will explore:

  • Fortra IT managers hoping to find new IBM i talent are discovering that the pool of experienced RPG programmers and operators or administrators with intimate knowledge of the operating system and the applications that run on it is small. This begs the question: How will you manage the platform that supports such a big part of your business? This guide offers strategies and software suggestions to help you plan IT staffing and resources and smooth the transition after your AS/400 talent retires. Read on to learn: