universal information security -...

4
In transit, in storage, transparently, for all users. Universal information security TM PGP Corporation The recognized worldwide leader in secure messaging and information storage, PGP Corporation develops solutions used by business, govern- ment, individuals, and cryptography experts to secure confidential information.

Upload: lamtuyen

Post on 29-Jul-2018

215 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Universal information security - download.pgp.comdownload.pgp.com/pdfs/PGP_Corp_Brochure_FL_030908.pdf · PGP Principle 3: Innovation Raising the standard and expectation for true

In transit,

in storage,

transparently,

for all users.

Universal information security

TM

PGP Corporation

The recognized worldwide leader in

secure messaging and information

storage, PGP Corporation develops

solutions used by business, govern-

ment, individuals, and cryptography

experts to secure confidential

information.

Page 2: Universal information security - download.pgp.comdownload.pgp.com/pdfs/PGP_Corp_Brochure_FL_030908.pdf · PGP Principle 3: Innovation Raising the standard and expectation for true

Raising the standard for universal information security

Protecting information assets is critical

Today's executives and managers are increasingly concernedabout protecting information assets and intellectual propertyas well as customer and employee information. Yet mostinformation now is created, exchanged, and stored electron-ically. Unlike their paper predecessors, digital assets cannotbe simply locked in a drawer. Protecting these assetsmeans literally securing every computer both inside theorganization and among colleagues, partners, and customers.The question is how to enforce two-way security policy forall users and keep the flow of information from slowing to a trickle.

failing to do so. This risk is compounded by the unprecedent-ed level of electronic integration with partners, suppliers,outsourcers, and customers, where highly proprietary infor-mation is routinely communicated through the Internet, oftenwith no security precautions of any kind.

Regulatory issues affecting security

Managing electronic information has become a visible andhighly regulated activity, regardless of industry. There arenow significant corporate risks involved in not meeting thecomplex regulatory requirements for information securityand privacy. In the United States, for example, HIPAA,Gramm-Leach-Bliley, and Sarbanes-Oxley legislation hasaltered the governance landscape; similarly, the EU PrivacyDirective affects all organizations doing business withEuropean Union members. Creating, implementing, andenforcing corporate security policies governing email hasbecome critical to mitigating corporate risk as well as individ-ual risk for executives. Yet to achieve tangible executive andcorporate protection, policy must be universally applied andenforced. A “most of the time” answer is no longer enough.

Our technology vision

From the start, PGP Corporation envisioned a new technologythat would eliminate the barriers to achieving truly universal,enterprise-wide messaging security. PGP Corporation’s newSelf-Managing Security Architecture is the first architectureto shift the burden of protecting critical information assetsfrom users’ computers to the network—automatically andtransparently. PGP Universal dramatically changes howorganizations think about information security, allowing themto secure all their information assets in a practical, transpar-ent, and cost-effective manner. This architecture is highlyflexible and in the future will also address enterprise securityneeds for instant messaging, mobile devices, data storage,and other technologies at the network protocol level.

PGP Principle 1: Continuity

Extending the proven PGP technology foundation with

a new architecture that dramatically changes how

organizations think about information security

Despite widespread awareness of security risks posed byunsecured email, only 5 to 15 percent of corporate desktopshave secure-messaging capability.1 How many users con-form to corporate security policy—and how often—is noteven known. This threat is compounded by the challenge oftechnology itself: large numbers of machines, multiple loca-tions, mobile users, wireless networks, and the distributednature of email systems.

At the same time, companies are under increasing pressurefrom customers and government regulations to guaranteeinformation security—and are facing significant liability for

1 GartnerGroup, 2003

Page 3: Universal information security - download.pgp.comdownload.pgp.com/pdfs/PGP_Corp_Brochure_FL_030908.pdf · PGP Principle 3: Innovation Raising the standard and expectation for true

PGP Principle 2: Relationship

Changing the way people conduct business by provid-

ing transparent, automatic, two-way secure messaging

What if all your informationassets were secure?

PGP Universal Server deployed in External Mode (PGP Universal Server/ EXT) secures all messages entering and leaving the organization;

PGP Universal Server deployed in Internal Mode (PGP Universal Server/ INT) also secures all email on internal mail servers.

PGP Universal

PGP Universal is a new product line built on trusted andproven PGP technology. Its network proxy- and protocol-based approach provides full end-to-end security in a waythat overcomes current deployment, management, usability,and cost objections. PGP Universal is powerful, flexible, and cost-effective enough to allow companies to transitionfrom securing a few individuals to protecting all their infor-mation assets.

concentrate on business requirements without the burdenof learning and adhering to security policy or using desktop-oriented solutions.

Low-cost adoption and deployment

By eliminating user (software, support, and training) costand minimizing IT (deployment and management) expensewithout adding to existing IT infrastructure costs, PGPUniversal enables comprehensive solutions at a low cost.PGP Universal technology makes wide deployment of securemessaging practical.

Comprehensive, self-managing solution

PGP Universal is entirely automatic and policy-managed,operating without the need for either ongoing IT or userintervention. PGP Universal’s Self-Managing SecurityArchitecture provides central security policy management;automatic key generation and life cycle management; andautomatic encryption, decryption, and digital signatures.

Two-way policy enforcement

PGP Universal allows companies to communicate securelywith all external suppliers, partners, outsourcers, and cus-tomers. By using the PGP Universal Satellite feature, securitypolicy can be extended to all users, even those outside theorganization, enabling two-way policy enforcement on bothoutbound and inbound email messages.

Internet emailclient

email server

emailserver

PGP Universal Web Messenger

emailclient

email clients PGP UniversalServer/INT

PGP UniversalServer/EXT

PGP Universal Satellite

Transparent, universal coverage

PGP Universal removes the need for the user to beinvolved in security policy, achieving uniform policy enforce-ment throughout the extended enterprise. By moving email security from the client to the network, PGP Universalmakes it practical to extend the solution quickly and cost-effectively to up to 100 percent of users—both inside andoutside the organization. PGP Universal allows users to

Page 4: Universal information security - download.pgp.comdownload.pgp.com/pdfs/PGP_Corp_Brochure_FL_030908.pdf · PGP Principle 3: Innovation Raising the standard and expectation for true

PGP Principle 3: Innovation

Raising the standard and expectation for true universal

information security—including all information assets,

no matter where they reside

TM

© 2003 PGP Corporation CBUS030823

Recipients without keys

Security policy often fails when no recipient key can befound. To ensure outbound messages are sent and receivedsecurely, PGP Universal Server retains the original outboundmessage and sends an "in-the-clear" email notifying the recip-ient that a secure message is available. This PGP UniversalWeb Messenger feature allows a recipient to use a Webbrowser to create a secure session via https, and retrieveand reply to the message. PGP Universal Web Messengeruses full public/private key encryption and offers both “first-time-good” and “out-of-band” authentication options.

PGP Desktop

PGP Desktop, based on the same trusted PGP technology,secures information assets at the desktop level. PGPDesktop is for business, government, and individuals thatwant to allow or require users to create and manage theirown keys, decide which recipients must by policy receivesecure messages, and protect stored information withstrong encryption.

PGP Personal

Individuals using mainstream email and instant messagingapplications through consumer ISPs need a reliable solutionto protect confidential email and stored information. PGPCorporation personal solutions provide the same core capa-bilities as PGP Desktop.

PGP Mobile

PGP Corporation mobile solutions provide capabilities similarto PGP Desktop for Palm OS- and Windows CE-baseddevices. These solutions encrypt and secure important data

on handheld devices—passwords, account information,email, calendars, and contacts.

Proven technology

PGP technology has been in use for more than ten years,and PGP Corporation is the recognized worldwide leader insecure-messaging and information-storage solutions. PGPproducts are used by a broad base of enterprises, business-es, governments, individuals, and cryptography experts tosecure proprietary and confidential information. PGPCorporation remains committed to standards-based, non-proprietary technologies and to releasing product sourcecode for peer review.

Ongoing commitment

PGP Corporation was formed in June 2002 with the reacqui-sition of PGP assets by a team of PGP veterans and securitytechnology experts. The Company was founded with thevision of technical innovation, expanding widely acceptedPGP technology and products to meet the security needs oftoday’s enterprises. PGP Corporation is dedicated to raisingthe standard and expectation of information security—makingpossible what was previously impossible: the security of allinformation assets, no matter where they reside.

PGP®—It’s Universal

PGP Corporation3460 West Bayshore RoadPalo Alto, CA 94303 USATel: +1 650 319 9000 Fax: +1 650 319 9001www.pgp.com

Complete family of integrated solutions