Why Reporting is Critical
Today's organizations depend on the Internet more than ever,
whether for research, e-commerce transactions, speedy communications
or all three. But the Internet can deliver increasingly sophisticated
threats as well. Some of these threats are external, from spyware,
malware and phishing and some are internal, through employee
abuse or negligence. You may have written a solid and binding
Acceptable Use Policy (AUP) or Security Policy but how can you
know if your users are abiding by the policies?There is also
the very real threat of customer data exposure or the loss of
company intellectual property, which can occur via Internet
protocols. These varied and emerging threats are why you acquired
an Internet filtering solution in the first place. The ability
to protect your organization by enforcing your policies and
securing your sensitive and proprietary data is also dependent
on strong and accurate internet usage reporting.
Another important part of managing Internet access has to
do with your organization's need to comply with regulatory requirements
such as the Sarbanes Oxley Act (SOX) or HIPAA. You may be in
total compliance with the regulations that govern your activities,
but the only way to demonstrate it is through accurate and thorough
Internet usage reporting. In addition, comprehensive reporting
can mitigate threats and is critical in the following areas:
- Productivity - Employees who use non-business
related, high bandwidth sites on the Internet can directly
affect your bottom line. iPrism comprehensive on-box Internet
usage reporting gives you both instant and long-term views
of all Internet activity across your organization. Drill-down
reporting allows you to isolate to a group or a single user
so you can spot productivity problems and address them before
they get out-of-hand. You will also be able to identify
users who are non-compliant with your AUP and Security Policy.
- Security - Inadvertent downloading by users is
the primary way spyware, malware and phishing can invade
and damage your network. Unauthorized use of IM and P2P
applications are also prime doorways for exploits. iPrism
allows you to monitor and report on all Internet protocols
across your entire organization so you can pinpoint problems
instantly, whether intentional or through employee negligence.
- Liability - Your AUP may prohibit employees from
accessing sites that are inappropriate but you have no way
of enforcing your rules without visibility into online behavior.
Employees who flout your AUP put your entire organization
at risk. Huge payouts resulting from lawsuits that started
with objectionable Internet content can damage your organization's
financial well-being and ruin its reputations. iPrism gives
you technology to control online behavior and the transparency
to spot issues before they cause damage with Internet usage
reports.
- Network Resources - The Internet is rife with
sites that consume large amounts of bandwidth and most of
them are non-business related. Instead of being frustrated
at the drain on your resources, iPrism reporting shows you
where your network is being impeded and slowed by bandwidth-intensive
activities such as Internet media services. iPrism can also
provide a view of your Internet activity that gives you
a better understanding of how your network is being utilized.
This sort of information can be valuable when it comes to
purchasing new equipment, adjusting your AUP and Security
Policies to be more effective, or dealing with emerging
threats.
iPrism Web Filter Reporting Features:
Most software-based solutions use "pass-by" filtering
technology. The trouble with pass-by is that it can
be overwhelmed when Internet traffic is high, resulting
in missed packets. If a packet slips past your filtering
solution, so does the opportunity to report on it because,
from the solution's perspective, the event never occurred.
However, the reality is that the event did occur and
because of this scenario you have introduced doubt into
the accuracy of your reporting.
With iPrism's next-generation kernel-level filtering
and transparent bridge deployment, you no longer have
to worry about missed packets and you can ensure that
your reports are generated from accurate and reliable
data, and presented in a meaningful format.
Comprehensive Reporting That's Easy-to-Use
iPrism's on-box reporting package includes tools
such as the Report Wizard that make obtaining and presenting
the information you need easy and intuitive. Using the
Report Wizard, you can create a report from scratch
or use a pre-existing report template. The Wizard walks
you through all the necessary steps from the criteria
you want to apply through to a finished report. You
can create reports for multiple types of traffic including
HTTP, IM and P2P so you are assured thorough reporting
coverage of your entire organization.
Tabular Views Mean Drill-Down Efficiency
The iPrism reporting package is the only solution
that offers tabular reporting views as you drill down.
This means that you can create a report, drill-down
to a different view, and access your previous view via
tabs along the top of the screen. This unique feature
gives you the maximum flexibility to explore your data
dynamically, without running multiple reports or losing
unsaved reports. It also allows you to quickly compare
data between multiple reports.
Drill-down Reporting View

Real-Time Monitoring (RTM)
With this features you can monitor your traffic on-demand,
whether HTTP, IM or P2P. And you can configure RTM to
monitor all or per-user traffic or only those critical
events occurring outside of your acceptable use policy
or security policies. In those cases, RTM becomes an
important diagnostic tool, helping you determine where
security holes have opened and where policy violations
are occurring
iPrism Report Guide
The iPrism report guide is a detailed look at the
iPrism reporting package and its components. Learn how
to use the power of iPrism reporting to build and present
precise, reliable and useful reports on all of your
organization's Internet activity. In addition, you can
monitor your Internet traffic in real-time and in multiple
views. The iPrism robust reporting package is unrivalled
in its comprehensiveness... plus, it's all on-box!
iPrism Web Filter Aggregate Reporting:
On-Premises Reporting with Enterprise Reporting
Server (ERS)
Accurate and secure Internet filtering is a vital part
of managing your organization's Internet access. But
the only way to ensure that your Acceptable Use and
Security Policies are being reliably enforced is through
fast, comprehensive and archivable reporting. The iPrism
Enterprise Reporting Server (ERS for iPrism) takes reporting
to a whole new level. Designed for the requirements
of distributed networks in education, corporations and
professional organizations with multiple iPrism Web
Filter deployments, ERS for iPrism delivers accurate
detailed reports at speeds unrivalled by any other solution
in the industry.
iPrism Web Filter comes with on-box web usage reporting.
Where just one iPrism is deployed or in multiple deployments
that don't require centralized reporting, the included
reporting will be sufficient to meet your needs.
However, if your organization has multiple locations,
each requiring an individual Internet filtering solution,
ERS for iPrism is the web usage reporting solution you've
been looking for. ERS delivers aggregate network reporting
at phenomenal speeds and with pinpoint accuracy for
an unlimited number of iPrism Web Filters. ERS for iPrism
allows you to generate cumulative reports that cover
your entire distributed network in minutes. Or, you
can easily drill-down to individual users as necessary.
No other solution gives you the visibility into your
system-wide Internet usage that ERS for iPrism provides.
Here's how ERS helps you support your corporate
AUP and Security Policy:
- ERS supports over 100 million events generated
per day from all iPrisms. You won't worry about
hitting a threshhold when you need enterprise-wide
results.
- ERS contains storage capacity for more than
2 billion web access and IM/P2P events. You can
generate reports that cover long-term usage and
retain reports previously run, which can help elucidate
trends and usage by location, individual user, or
across your entire organization.
- ERS can generate reports faster than any other
competitive solution. Depending upon your environment
and the report selected, your reports are ready
for viewing up to 50X times faster than any other
solution on the market. You won't waste your valuable
IT resources waiting for even large enterprise-wide
reports - ERS delivers them within minutes.
- ERS provides reporting flexibility that allows
you to schedule mutliple reports to run any time
you choose, while easily generating on-demand reports
at the same time. This gives you instant access
to a multitude of on-demand reports and leaves standing
reports to run as scheduled.
- ERS failover features reach a new level in data
protection. It has a dual-power supply so data cannot
be lost under even the most adverse conditions.
The hot-swappable RAID 10 hard drives mean your
data is always protected because you never have
to power down to solve problems.
- The new ERS graphical user interface makes choosing
report templates easy. It supports all of iPrism's
report types so you won't spend time hunting for
the report you need - each iPrism report type is
easily accessible from the GUI.
- With the unified ERS interface, you can see
log acquisition status and statistics such as last
event time, total number of events and more, for
any or all iPrism appliances deployed throughout
your organization's locations.
- ERS automatically indexes the database every
night you can generate previous-day reports. This
feature allows next-day reporting across all your
iPrism deployments organization-wide.
- Although ERS enables system-wide reporting on
multiple deployments of iPrism, you can still generate
on-box reports from individual iPrisms whenever
you choose.
Employee Monitoring:
When employees engage in non-work related activities
during work hours, productivity loss is just one of
the consequences. The media is full of stories of companies
that have had to pay huge settlements because employees
downloaded offensive materials from the Internet that
threatened other employees. Other issues such as loss
of intellectual property or compromising sensitive customer
data can result in lost revenue or huge fines if regulatory
requirements are breached. There's no question that
failing to implement some sort of employee monitoring
of Web behavior at work, can result in significant losses.
First Step is an Acceptable Use Policy
An essential part of any employee monitoring strategy
is a strong and comprehensive Acceptable Use Policy
(AUP). With a signed policy in place, employees are
agreeing to abide by company policies and acknowledging
that they will be subject to monitoring. A strong AUP
protects your company and also puts employees on notice
that their activities during work hours are open to
examination.
How Tough Should You be with Employee Monitoring?
Employers should have some discretion when embarking
on employee monitoring. A system of monitoring employees
that takes into account employee morale, building company
loyalty and other factors that can affect retention
should be considered. You may want a system in place
that gives some groups greater leeway than others because
of job function or seniority. Or, you may want to give
all employees more latitude during their lunch hours
and breaks. A strategy for employee monitoring should
include a solution that will give you the flexibility
you need to enhance your work environment while helping
enforce your AUP.
iPrism is the Answer
The iPrism Web Filter is the award-winning appliance-based
filtering solution that gives you the enforcement power
you want and the flexibility you need. With iPrism,
you get the employee internet monitoring tools necessary
to enforce your AUP and assure that your sensitive data
and intellectual property are protected from employee
threats whether intentional or accidental. iPrism's
powerful h-series appliances include models that can
handle any size organization with any size pipeline
so that Web performance is never an issue. Its flexible
configurations allow you to give access to groups and
individuals as you choose, delivering a solution that
easily conforms to your company's requirements. Comprehensive
drill down reporting takes you from an overview of your
entire company's Internet activity down to individual
users within seconds. You can also monitor employees
and your bandwidth usage as it occurs with real time
reporting. Employee monitoring of Internet activity
is now a given. The iPrism Web Filter gives you the
power and flexibility to enforce your AUP and support
your overall business goals.
Regulatory Compliance:
Legislative
Regulations are Here to Stay
Regulatory legislation is here to stay because the
majority of data gathered and compiled by organizations
is now in electronic format. While this has made storage
and transmission of this information more efficient,
it has also provided more opportunities for data to
be lost, stolen or corrupted. In order to protect sensitive
customer and patient data and safeguard intellectual
property, the US Congress has passed a number of laws
governing how this data is to be secured. These laws
are applicable to almost every industry including financial
institutions, medical organizations, government entities
and businesses of all kinds. In addition to protecting
data, these organizations must be able to document that
they are in compliance.
The onus for assuring compliance typically falls
on IT professionals who must prove that their systems
and networks are secure and that client/patient data,
accurate financial statements, intellectual property
and other sensitive records can be secured and transmitted
in pristine condition and protected from internet-based
threats such as viruses and worms.
Some regulations provide detailed requirements for
the written security and privacy policies an organization
must provide, while other regulations are less specific,
requiring only that safeguards be "appropriate" depending
on the size of the organization and the type of activity
it conducts.
iPrism Web Filter Helps Your Organization Comply
with Regulations:
No matter what regulations govern your organization's
activities, the ability to protect your sensitive and
proprietary records is paramount to your fiscal health.
Lack of compliance carries serious consequences including
substantial fines and litigation that can directly affect
your bottom line. The iPrism Web Filter not only secures
your network against Internet-based threats to your
data from malware, P2P and IM, it provides comprehensive
drill-down and real time monitoring and reporting that
can help you document your compliance and consistently
stay within the boundaries of the legislation affecting
your organization
The following is a table that contains a list of
key regulations, the industries they affect and their
general policy requirements:
|
Regulation |
Industry |
Requirements |
|
HIPAA (Health Insurance Portability
and Accountability Act of 1996) |
Healthcare |
- Requires protection of confidentiality
and assures the integrity and availability
of all electronic protected health information
(EPHI) that is created, received, maintained
or transmitted
- Eligible entities must protect against
any reasonably anticipated threats or
hazards to the security or integrity
of such information
- Requires protection against any
reasonably anticipated uses or disclosures
of such information that are not permitted
or required by the Privacy Rule; and
- Organizations must ensure compliance
by their workforces
|
|
CIPA (Child Internet Protection Act) |
Schools and Libraries |
Schools and libraries subject to CIPA are
required to adopt and implement a policy
addressing minor Internet use as well as
the technology required to enforce the policy.
The policy and technology should address:
- Access by minors to inappropriate
matter on the Internet;
- The safety and security of minors
when using electronic mail, chat rooms,
and other forms of direct electronic
communications;
- Unauthorized access, including so-called
"hacking," and other unlawful activities
by minors online;
- Unauthorized disclosure, use, and
dissemination of personal information
regarding minors; and
- Restricting minors' access to materials
harmful to them.
Failure to comply can disqualify schools
and libraries from getting valuable e-Rate
funds to purchase technology
|
|
Sarbanes-Oxley Act (SOX) |
All Publicly
Traded Companies |
- Requires executives and auditors
to confirm the effectiveness of internal
controls for financial reporting.
- Ensures control of unauthorized
access to data or data deletion
- Requires robust access controls,
interoperable with enterprise authentication,
access and auditing
|
|
Gramm-Leach-Bliley Act (GLBA) |
Financial Services |
- Institutions governed by GLBA must
assure the security and confidentiality
of customer records and information
- They must protect against any anticipated
threats or hazards to the security or
integrity of such records
- They must protect against unauthorized
access to or use of such records or
information which could result in substantial
harm or inconvenience to any customer.
|
|
The Prioritizing Resources & Organization
for Intellectual Property Act |
All US Companies |
- In general, gives law enforcement
more latitude in enforcing intellectual
property (IP) laws
- Protects IP including pharmaceuticals
and manufactured goods, and artistic
works such as MP3 and video files or
other content transmitted electronically
as well as on hard media
- Organizations that are lax in securing
their networks from illegal downloads
face stiff penalties including criminal
charges and having their computer equipment
confiscated
|
|