EdgeWave Authorized ProPartnerInternet Usage Reports

iPrism Web Filter


Why Reporting is Critical

Today's organizations depend on the Internet more than ever, whether for research, e-commerce transactions, speedy communications or all three. But the Internet can deliver increasingly sophisticated threats as well. Some of these threats are external, from spyware, malware and phishing and some are internal, through employee abuse or negligence. You may have written a solid and binding Acceptable Use Policy (AUP) or Security Policy but how can you know if your users are abiding by the policies?

There is also the very real threat of customer data exposure or the loss of company intellectual property, which can occur via Internet protocols. These varied and emerging threats are why you acquired an Internet filtering solution in the first place. The ability to protect your organization by enforcing your policies and securing your sensitive and proprietary data is also dependent on strong and accurate internet usage reporting.

Another important part of managing Internet access has to do with your organization's need to comply with regulatory requirements such as the Sarbanes Oxley Act (SOX) or HIPAA. You may be in total compliance with the regulations that govern your activities, but the only way to demonstrate it is through accurate and thorough Internet usage reporting. In addition, comprehensive reporting can mitigate threats and is critical in the following areas:

iPrism Web Filter Reporting Features:

Accurate Filtering Means Accurate Reporting
Most software-based solutions use "pass-by" filtering technology. The trouble with pass-by is that it can be overwhelmed when Internet traffic is high, resulting in missed packets. If a packet slips past your filtering solution, so does the opportunity to report on it because, from the solution's perspective, the event never occurred. However, the reality is that the event did occur and because of this scenario you have introduced doubt into the accuracy of your reporting.

With iPrism's next-generation kernel-level filtering and transparent bridge deployment, you no longer have to worry about missed packets and you can ensure that your reports are generated from accurate and reliable data, and presented in a meaningful format.

Comprehensive Reporting That's Easy-to-Use

iPrism's on-box reporting package includes tools such as the Report Wizard that make obtaining and presenting the information you need easy and intuitive. Using the Report Wizard, you can create a report from scratch or use a pre-existing report template. The Wizard walks you through all the necessary steps from the criteria you want to apply through to a finished report. You can create reports for multiple types of traffic including HTTP, IM and P2P so you are assured thorough reporting coverage of your entire organization.

Tabular Views Mean Drill-Down Efficiency

The iPrism reporting package is the only solution that offers tabular reporting views as you drill down. This means that you can create a report, drill-down to a different view, and access your previous view via tabs along the top of the screen. This unique feature gives you the maximum flexibility to explore your data dynamically, without running multiple reports or losing unsaved reports. It also allows you to quickly compare data between multiple reports.

Drill-down Reporting View

Drill-down Reporting View

Real-Time Monitoring (RTM)

With this features you can monitor your traffic on-demand, whether HTTP, IM or P2P. And you can configure RTM to monitor all or per-user traffic or only those critical events occurring outside of your acceptable use policy or security policies. In those cases, RTM becomes an important diagnostic tool, helping you determine where security holes have opened and where policy violations are occurring

iPrism Report Guide

The iPrism report guide is a detailed look at the iPrism reporting package and its components. Learn how to use the power of iPrism reporting to build and present precise, reliable and useful reports on all of your organization's Internet activity. In addition, you can monitor your Internet traffic in real-time and in multiple views. The iPrism robust reporting package is unrivalled in its comprehensiveness... plus, it's all on-box!

iPrism Web Filter Aggregate Reporting:

On-Premises Reporting with Enterprise Reporting Server (ERS)
Accurate and secure Internet filtering is a vital part of managing your organization's Internet access. But the only way to ensure that your Acceptable Use and Security Policies are being reliably enforced is through fast, comprehensive and archivable reporting. The iPrism Enterprise Reporting Server (ERS for iPrism) takes reporting to a whole new level. Designed for the requirements of distributed networks in education, corporations and professional organizations with multiple iPrism Web Filter deployments, ERS for iPrism delivers accurate detailed reports at speeds unrivalled by any other solution in the industry.

iPrism Web Filter comes with on-box web usage reporting. Where just one iPrism is deployed or in multiple deployments that don't require centralized reporting, the included reporting will be sufficient to meet your needs.

However, if your organization has multiple locations, each requiring an individual Internet filtering solution, ERS for iPrism is the web usage reporting solution you've been looking for. ERS delivers aggregate network reporting at phenomenal speeds and with pinpoint accuracy for an unlimited number of iPrism Web Filters. ERS for iPrism allows you to generate cumulative reports that cover your entire distributed network in minutes. Or, you can easily drill-down to individual users as necessary. No other solution gives you the visibility into your system-wide Internet usage that ERS for iPrism provides.

Here's how ERS helps you support your corporate AUP and Security Policy:

  • ERS supports over 100 million events generated per day from all iPrisms. You won't worry about hitting a threshhold when you need enterprise-wide results.
  • ERS contains storage capacity for more than 2 billion web access and IM/P2P events. You can generate reports that cover long-term usage and retain reports previously run, which can help elucidate trends and usage by location, individual user, or across your entire organization.
  • ERS can generate reports faster than any other competitive solution. Depending upon your environment and the report selected, your reports are ready for viewing up to 50X times faster than any other solution on the market. You won't waste your valuable IT resources waiting for even large enterprise-wide reports - ERS delivers them within minutes.
  • ERS provides reporting flexibility that allows you to schedule mutliple reports to run any time you choose, while easily generating on-demand reports at the same time. This gives you instant access to a multitude of on-demand reports and leaves standing reports to run as scheduled.
  • ERS failover features reach a new level in data protection. It has a dual-power supply so data cannot be lost under even the most adverse conditions. The hot-swappable RAID 10 hard drives mean your data is always protected because you never have to power down to solve problems.
  • The new ERS graphical user interface makes choosing report templates easy. It supports all of iPrism's report types so you won't spend time hunting for the report you need - each iPrism report type is easily accessible from the GUI.
  • With the unified ERS interface, you can see log acquisition status and statistics such as last event time, total number of events and more, for any or all iPrism appliances deployed throughout your organization's locations.
  • ERS automatically indexes the database every night you can generate previous-day reports. This feature allows next-day reporting across all your iPrism deployments organization-wide.
  • Although ERS enables system-wide reporting on multiple deployments of iPrism, you can still generate on-box reports from individual iPrisms whenever you choose.

Employee Monitoring:

When employees engage in non-work related activities during work hours, productivity loss is just one of the consequences. The media is full of stories of companies that have had to pay huge settlements because employees downloaded offensive materials from the Internet that threatened other employees. Other issues such as loss of intellectual property or compromising sensitive customer data can result in lost revenue or huge fines if regulatory requirements are breached. There's no question that failing to implement some sort of employee monitoring of Web behavior at work, can result in significant losses.

First Step is an Acceptable Use Policy

An essential part of any employee monitoring strategy is a strong and comprehensive Acceptable Use Policy (AUP). With a signed policy in place, employees are agreeing to abide by company policies and acknowledging that they will be subject to monitoring. A strong AUP protects your company and also puts employees on notice that their activities during work hours are open to examination.

How Tough Should You be with Employee Monitoring?

Employers should have some discretion when embarking on employee monitoring. A system of monitoring employees that takes into account employee morale, building company loyalty and other factors that can affect retention should be considered. You may want a system in place that gives some groups greater leeway than others because of job function or seniority. Or, you may want to give all employees more latitude during their lunch hours and breaks. A strategy for employee monitoring should include a solution that will give you the flexibility you need to enhance your work environment while helping enforce your AUP.

iPrism is the Answer

The iPrism Web Filter is the award-winning appliance-based filtering solution that gives you the enforcement power you want and the flexibility you need. With iPrism, you get the employee internet monitoring tools necessary to enforce your AUP and assure that your sensitive data and intellectual property are protected from employee threats whether intentional or accidental. iPrism's powerful h-series appliances include models that can handle any size organization with any size pipeline so that Web performance is never an issue. Its flexible configurations allow you to give access to groups and individuals as you choose, delivering a solution that easily conforms to your company's requirements. Comprehensive drill down reporting takes you from an overview of your entire company's Internet activity down to individual users within seconds. You can also monitor employees and your bandwidth usage as it occurs with real time reporting. Employee monitoring of Internet activity is now a given. The iPrism Web Filter gives you the power and flexibility to enforce your AUP and support your overall business goals.

Regulatory Compliance:
 

Legislative RegulationsLegislative Regulations are Here to Stay

Regulatory legislation is here to stay because the majority of data gathered and compiled by organizations is now in electronic format. While this has made storage and transmission of this information more efficient, it has also provided more opportunities for data to be lost, stolen or corrupted. In order to protect sensitive customer and patient data and safeguard intellectual property, the US Congress has passed a number of laws governing how this data is to be secured. These laws are applicable to almost every industry including financial institutions, medical organizations, government entities and businesses of all kinds. In addition to protecting data, these organizations must be able to document that they are in compliance.

The onus for assuring compliance typically falls on IT professionals who must prove that their systems and networks are secure and that client/patient data, accurate financial statements, intellectual property and other sensitive records can be secured and transmitted in pristine condition and protected from internet-based threats such as viruses and worms.

Some regulations provide detailed requirements for the written security and privacy policies an organization must provide, while other regulations are less specific, requiring only that safeguards be "appropriate" depending on the size of the organization and the type of activity it conducts.

iPrism Web Filter Helps Your Organization Comply with Regulations:

No matter what regulations govern your organization's activities, the ability to protect your sensitive and proprietary records is paramount to your fiscal health. Lack of compliance carries serious consequences including substantial fines and litigation that can directly affect your bottom line. The iPrism Web Filter not only secures your network against Internet-based threats to your data from malware, P2P and IM, it provides comprehensive drill-down and real time monitoring and reporting that can help you document your compliance and consistently stay within the boundaries of the legislation affecting your organization

The following is a table that contains a list of key regulations, the industries they affect and their general policy requirements:

Regulation Industry Requirements
HIPAA (Health Insurance Portability and Accountability Act of 1996) Healthcare
  • Requires protection of confidentiality and assures the integrity and availability of all electronic protected health information (EPHI) that is created, received, maintained or transmitted
  • Eligible entities must protect against any reasonably anticipated threats or hazards to the security or integrity of such information
  • Requires protection against any reasonably anticipated uses or disclosures of such information that are not permitted or required by the Privacy Rule; and
  • Organizations must ensure compliance by their workforces
CIPA (Child Internet Protection Act) Schools and Libraries Schools and libraries subject to CIPA are required to adopt and implement a policy addressing minor Internet use as well as the technology required to enforce the policy. The policy and technology should address:
  • Access by minors to inappropriate matter on the Internet;
  • The safety and security of minors when using electronic mail, chat rooms, and other forms of direct electronic communications;
  • Unauthorized access, including so-called "hacking," and other unlawful activities by minors online;
  • Unauthorized disclosure, use, and dissemination of personal information regarding minors; and
  • Restricting minors' access to materials harmful to them.

Failure to comply can disqualify schools and libraries from getting valuable e-Rate funds to purchase technology

Sarbanes-Oxley Act (SOX) All Publicly Traded Companies
  • Requires executives and auditors to confirm the effectiveness of internal controls for financial reporting.
  • Ensures control of unauthorized access to data or data deletion
  • Requires robust access controls, interoperable with enterprise authentication, access and auditing
Gramm-Leach-Bliley Act (GLBA) Financial Services
  • Institutions governed by GLBA must assure the security and confidentiality of customer records and information
  • They must protect against any anticipated threats or hazards to the security or integrity of such records
  • They must protect against unauthorized access to or use of such records or information which could result in substantial harm or inconvenience to any customer.
The Prioritizing Resources & Organization for Intellectual Property Act All US Companies
  • In general, gives law enforcement more latitude in enforcing intellectual property (IP) laws
  • Protects IP including pharmaceuticals and manufactured goods, and artistic works such as MP3 and video files or other content transmitted electronically as well as on hard media
  • Organizations that are lax in securing their networks from illegal downloads face stiff penalties including criminal charges and having their computer equipment confiscated