SlideShare ist ein Scribd-Unternehmen logo
1 von 2
Downloaden Sie, um offline zu lesen
S U C C E S S S T O R Y
Faysal Bank Protects Business-Critical
Banking Systems with NetIQ
Executive Summary
INDUSTRY DESCRIPTION
Faysal Bank Limited (Pakistan) offers
corporate, commercial, retail and Islamic
banking services in more than 260
branches in over 70 cities throughout
Pakistan. The company is a wholly
owned subsidiary of Ithmaar Bank B.S.C.,
listed on the Bahrain and Kuwait stock
exchanges.
BUSINESS SITUATION
To improve security, Faysal Bank
Ltd. wanted to improve its ability to
supervise IT administrators’activities.
The organization needed to monitor
critical systems supporting core banking,
credit card processing, and network
infrastructure.
THE NETIQ DIFFERENCE
NetIQ Sentinel Log Manager
consolidates logs from multiple systems
in real time, providing a clear, central
view of all activity, with the ability to
create detailed reports and set up event-
triggered alerts.
NETIQ PRODUCTS AND SERVICES
NetIQ® Sentinel™ Log Manager
Faysal Bank Ltd. employs approximately
4,000 people across more than 260
branches in Pakistan. The bank maintains
dozens of large databases, many of which
contain sensitive and business-critical
data. Of the 100 people on the IT team,
approximately 5 to 10 staff members
work directly on database administration.
Following internal best practices for
security, the IT management team gives
limited access rights to technical staff,
providing temporary full administrative
privileges only when necessary.
“We had introduced preventative controls
for security reasons, but it was difficult to
check that administrative privileges were
being used appropriately,”said Zahir Ali
Quettawalla, Head ITSRM, Faysal Bank Ltd.
“We needed a solution for monitoring
logs from multiple systems that would
present the information in a readable
format. The ability to review and query
the log data was vital: We did not want
to simply‘check the boxes’when it came
to complying with audit standards.”
The Solution
Following a thorough analysis of
security-monitoring solutions, Faysal
Bank Ltd. selected NetIQ® Sentinel™
Log Manager and worked with NDS, a
NetIQ partner, to deploy the solution.
“The NetIQ solution met almost all of
our log-monitoring requirements and
was considerably less costly than the
alternatives,”said Zahir Ali Quettawalla.
Faysal Bank Ltd. is now monitoring
logs for almost all of its critical
systems and user IDs, and is working
to develop reports and alerts
that will further improve visibility
and simplify compliance.
“NetIQ Sentinel Log Manager is a very
comprehensive tool, but it’s not humanly
possible to read every line of every
log,”said Zahir Ali Quettawalla.“We
are now working with NDS to create
consolidated reports and we are planning
to flag up suspicious activity using alerts
sent directly to BlackBerry devices.”
Worldwide Headquarters
1233 West Loop South, Suite 810
Houston, Texas 77027 USA
Worldwide: +1 713.548.1700
U.S. / Canada Toll Free: 888.323.6768
info@netiq.com
www.netiq.com
http://community.netiq.com
For a complete list of our offices
in North America, Europe, the
Middle East, Africa, Asia-Pacific
and Latin America, please visit
www.netiq.com/contacts.
Follow us:
Comprehensive reports enable IT
management to see at a glance
how and when users are using
administrator IDs. The reports
include the time and location of
access, and detailed information on
what commands users are running
with administrative privileges.
“With the NetIQ solution, we have a
complete record of user-generated
queries, which gives a very good idea
of what users are actually doing on
each database: which tables they
have accessed, which fields they have
changed, which values they have
updated,”said Zahir Ali Quettawalla.
With the log-monitoring solution
in place, Faysal Bank is now
embarking on a second phase.
“We have a system where users can
request access rights,”said Zahir Ali
Quettawalla.“An automated workflow
ensures approval by their line manager,
but there’s no easy way to check that
the requested access really fits that
person’s role. We are planning to deploy
Identity Manager from NetIQ to provide
full control over roles and access rights.”
The Results
A Clear View with Minimal Impact
Thanks to NetIQ Sentinel Log
Manager, Faysal Bank Ltd. now has a
clear view of administrator activity
across its most important databases.
“Administrators understand that they
are now being monitored by the NetIQ
solution, and that any out-of-the-
ordinary activities, whether accidental
or deliberate, will be permanently
visible,”said Zahir Ali Quettawalla.
Business managers previously
had concerns about setting up
logs on critical systems for fear
of impacting performance. NetIQ
Sentinel Log Manager captures
logs in real time and with zero
performance impact. Likewise, the
solution has minimal impact on
the IT team’s workload, enabling
full monitoring and sophisticated
reporting at the touch of a button.
Bringing Risk under Control
The ability to monitor and report
on comprehensive administrator-
activity logs is of great value in
demonstrating proper IT governance.
“The business risk associated with
administrative access to databases is
now under control, thanks to NetIQ
Sentinel Log Manager,”said Zahir Ali
Quettawalla.“We can set up real-time
alerts for defined security events,
and we also have a full evidence
trail for all historical activities.”
Learn more today by contacting
your NetIQ partner or a local NetIQ
sales representative, or by visiting
www.netiq.com for contact
information in your area.
“The business risk
associated with
administrative access to
databases is now under
control, thanks to NetIQ
Sentinel Log Manager.”
Zahir Ali Quettawalla,
Head IT Security Risk Management
(ITSRM),
Faysal Bank Limited (Pakistan)
NetIQ, the NetIQ logo, and Sentinel Log Manager are trademarks or registered trademarks of NetIQ Corporation in the USA.
All other company and product names may be trademarks of their respective companies.
© 2012 NetIQ Corporation and its affiliates. All Rights Reserved.	 CSS90064FBU ST 11/12

Weitere ähnliche Inhalte

Mehr von NetIQ

BrainShare 2014
BrainShare 2014 BrainShare 2014
BrainShare 2014 NetIQ
 
Paraca Inc.
Paraca Inc.Paraca Inc.
Paraca Inc.NetIQ
 
The University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity ManagerThe University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity ManagerNetIQ
 
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...NetIQ
 
Swisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User AccessSwisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User AccessNetIQ
 
Vodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQVodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQNetIQ
 
University of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log ManagerUniversity of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log ManagerNetIQ
 
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQNippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQNetIQ
 
Nexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations CenterNexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations CenterNetIQ
 
Netiq css huntington_bank
Netiq css huntington_bankNetiq css huntington_bank
Netiq css huntington_bankNetIQ
 
Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...NetIQ
 
NetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal UniversityNetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal UniversityNetIQ
 
Handelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQHandelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQNetIQ
 
Millions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQMillions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQNetIQ
 
bluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed Servicebluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed ServiceNetIQ
 
Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...NetIQ
 
Cloud Identity
Cloud IdentityCloud Identity
Cloud IdentityNetIQ
 
2014 Cyberthreat Defense Report
2014 Cyberthreat Defense Report2014 Cyberthreat Defense Report
2014 Cyberthreat Defense ReportNetIQ
 
Identity-Powered Security
Identity-Powered SecurityIdentity-Powered Security
Identity-Powered SecurityNetIQ
 
IT Disaster Recovery
IT Disaster RecoveryIT Disaster Recovery
IT Disaster RecoveryNetIQ
 

Mehr von NetIQ (20)

BrainShare 2014
BrainShare 2014 BrainShare 2014
BrainShare 2014
 
Paraca Inc.
Paraca Inc.Paraca Inc.
Paraca Inc.
 
The University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity ManagerThe University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity Manager
 
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
 
Swisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User AccessSwisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User Access
 
Vodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQVodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQ
 
University of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log ManagerUniversity of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log Manager
 
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQNippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQ
 
Nexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations CenterNexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations Center
 
Netiq css huntington_bank
Netiq css huntington_bankNetiq css huntington_bank
Netiq css huntington_bank
 
Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...
 
NetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal UniversityNetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal University
 
Handelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQHandelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQ
 
Millions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQMillions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQ
 
bluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed Servicebluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed Service
 
Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...
 
Cloud Identity
Cloud IdentityCloud Identity
Cloud Identity
 
2014 Cyberthreat Defense Report
2014 Cyberthreat Defense Report2014 Cyberthreat Defense Report
2014 Cyberthreat Defense Report
 
Identity-Powered Security
Identity-Powered SecurityIdentity-Powered Security
Identity-Powered Security
 
IT Disaster Recovery
IT Disaster RecoveryIT Disaster Recovery
IT Disaster Recovery
 

Kürzlich hochgeladen

Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfhans926745
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Scriptwesley chun
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessPixlogix Infotech
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 

Kürzlich hochgeladen (20)

Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 

Faysal Bank Protects Business-Critical Banking Systems with NetIQ

  • 1. S U C C E S S S T O R Y Faysal Bank Protects Business-Critical Banking Systems with NetIQ Executive Summary INDUSTRY DESCRIPTION Faysal Bank Limited (Pakistan) offers corporate, commercial, retail and Islamic banking services in more than 260 branches in over 70 cities throughout Pakistan. The company is a wholly owned subsidiary of Ithmaar Bank B.S.C., listed on the Bahrain and Kuwait stock exchanges. BUSINESS SITUATION To improve security, Faysal Bank Ltd. wanted to improve its ability to supervise IT administrators’activities. The organization needed to monitor critical systems supporting core banking, credit card processing, and network infrastructure. THE NETIQ DIFFERENCE NetIQ Sentinel Log Manager consolidates logs from multiple systems in real time, providing a clear, central view of all activity, with the ability to create detailed reports and set up event- triggered alerts. NETIQ PRODUCTS AND SERVICES NetIQ® Sentinel™ Log Manager Faysal Bank Ltd. employs approximately 4,000 people across more than 260 branches in Pakistan. The bank maintains dozens of large databases, many of which contain sensitive and business-critical data. Of the 100 people on the IT team, approximately 5 to 10 staff members work directly on database administration. Following internal best practices for security, the IT management team gives limited access rights to technical staff, providing temporary full administrative privileges only when necessary. “We had introduced preventative controls for security reasons, but it was difficult to check that administrative privileges were being used appropriately,”said Zahir Ali Quettawalla, Head ITSRM, Faysal Bank Ltd. “We needed a solution for monitoring logs from multiple systems that would present the information in a readable format. The ability to review and query the log data was vital: We did not want to simply‘check the boxes’when it came to complying with audit standards.” The Solution Following a thorough analysis of security-monitoring solutions, Faysal Bank Ltd. selected NetIQ® Sentinel™ Log Manager and worked with NDS, a NetIQ partner, to deploy the solution. “The NetIQ solution met almost all of our log-monitoring requirements and was considerably less costly than the alternatives,”said Zahir Ali Quettawalla. Faysal Bank Ltd. is now monitoring logs for almost all of its critical systems and user IDs, and is working to develop reports and alerts that will further improve visibility and simplify compliance. “NetIQ Sentinel Log Manager is a very comprehensive tool, but it’s not humanly possible to read every line of every log,”said Zahir Ali Quettawalla.“We are now working with NDS to create consolidated reports and we are planning to flag up suspicious activity using alerts sent directly to BlackBerry devices.”
  • 2. Worldwide Headquarters 1233 West Loop South, Suite 810 Houston, Texas 77027 USA Worldwide: +1 713.548.1700 U.S. / Canada Toll Free: 888.323.6768 info@netiq.com www.netiq.com http://community.netiq.com For a complete list of our offices in North America, Europe, the Middle East, Africa, Asia-Pacific and Latin America, please visit www.netiq.com/contacts. Follow us: Comprehensive reports enable IT management to see at a glance how and when users are using administrator IDs. The reports include the time and location of access, and detailed information on what commands users are running with administrative privileges. “With the NetIQ solution, we have a complete record of user-generated queries, which gives a very good idea of what users are actually doing on each database: which tables they have accessed, which fields they have changed, which values they have updated,”said Zahir Ali Quettawalla. With the log-monitoring solution in place, Faysal Bank is now embarking on a second phase. “We have a system where users can request access rights,”said Zahir Ali Quettawalla.“An automated workflow ensures approval by their line manager, but there’s no easy way to check that the requested access really fits that person’s role. We are planning to deploy Identity Manager from NetIQ to provide full control over roles and access rights.” The Results A Clear View with Minimal Impact Thanks to NetIQ Sentinel Log Manager, Faysal Bank Ltd. now has a clear view of administrator activity across its most important databases. “Administrators understand that they are now being monitored by the NetIQ solution, and that any out-of-the- ordinary activities, whether accidental or deliberate, will be permanently visible,”said Zahir Ali Quettawalla. Business managers previously had concerns about setting up logs on critical systems for fear of impacting performance. NetIQ Sentinel Log Manager captures logs in real time and with zero performance impact. Likewise, the solution has minimal impact on the IT team’s workload, enabling full monitoring and sophisticated reporting at the touch of a button. Bringing Risk under Control The ability to monitor and report on comprehensive administrator- activity logs is of great value in demonstrating proper IT governance. “The business risk associated with administrative access to databases is now under control, thanks to NetIQ Sentinel Log Manager,”said Zahir Ali Quettawalla.“We can set up real-time alerts for defined security events, and we also have a full evidence trail for all historical activities.” Learn more today by contacting your NetIQ partner or a local NetIQ sales representative, or by visiting www.netiq.com for contact information in your area. “The business risk associated with administrative access to databases is now under control, thanks to NetIQ Sentinel Log Manager.” Zahir Ali Quettawalla, Head IT Security Risk Management (ITSRM), Faysal Bank Limited (Pakistan) NetIQ, the NetIQ logo, and Sentinel Log Manager are trademarks or registered trademarks of NetIQ Corporation in the USA. All other company and product names may be trademarks of their respective companies. © 2012 NetIQ Corporation and its affiliates. All Rights Reserved. CSS90064FBU ST 11/12