레이블이 Data Leak Prevention인 게시물을 표시합니다. 모든 게시물 표시
레이블이 Data Leak Prevention인 게시물을 표시합니다. 모든 게시물 표시

2015년 2월 22일 일요일

Security & work productivity improvement with Cloud storage based network separation

Security & work productivity improvement with

Cloud storage based network separation



Realization of network separation environment with NetID ‘ClouDoc’…

Enhanced work efficiency by supporting Smartwork

(Written by : Reporter Seon Ae Kim / Photo: Reporter Goo Ryong Kim)
Incheon Metropolitan City Office of Education
















Incheon Metropolitan City Office of Education introduced network separation environment as one of the ways of supporting safe, happy schools. That is to establish safe education environment by protecting student personal information and important information from intellectual cyber attack. Especially Incheon Metropolitan City Office of Education could enhance user convenience and security strengthening effect through white list based internet interruption policy.


Review on logical network separation for student personal information

Incheon Metropolitan City Office of Education needed a method to manage their work systematically and prevent information leakage as outsourced personnel were changing frequently. They had reviewed physical network separation to manage outsourced personnel PC. But they decided to construct logical network separation in need of protection for student personal information and internal information about education and administration stored in PC or the system.



After reviewing physical network separation and SBC-BCB type logical network separation technologies, Incheon Metropolitan City Office of Education concluded that logical network separation was suitable to the environment of the Office of Education. Afterwards, although we reviewed the logical network separation solution from various angles, we could not find a solution suitable to the requirements of the Incheon Office of Education.

Inchon Office of Education wanted network separation environment adopting a Cloud storage concept. They desired to realize the environment to access information safely for work execution at the outside as well as to protect important information from hacking. Necessary was a method to store data in the central storage and to connect with the internet when accessing the data.


Application of white list based internet interruption policy



Incheon Office of Education searched for the system optimized for the Office of Education work with the assembly of Electronic Document Management System (ECM), Document Centralization, and Desk Top Virtualization (VDI). As the Incheon Office of Education had already been equipped with work management system and electronic payment system, they mainly reviewed the products enabling to realize white list based internet contact permission/interruption policy.

As ECM or document centralization products supplied in the country had no internet network separation function, and VDI was to separate internet and work network using a virtual PC, they did not match with their demand to permit internet connection only when necessary. It was likely that a CBC type network separation solution took considerable time to convert to work network and internet network in the actual work environment and caused delay of work productivity.
Incheon Office of Education decided that ‘NetworkLock’ function provided by NetID ‘ClouDoc’ could meet all network separation requirements. NetworkLock is normally away from internet connection and waiting for work network connection. When contacting the internet site permitted by the manager, NetworkLock functions to connect to the internet.


Officer Kyo Kwon Jin made clear that, “NetworkLock function was a core function to help realized optimized network separation environment for Incheon Office of Education, requiring collaboration through internet connection with specific government organizations related. While we maintained almost similar environment to existing work using a ClouDoc NetworkLock function, we could accomplish network separation reformation.”

 

Supports Smartwork environment as well as security

 
Incheon Office of Education substantially obtained the effect of network separation during reorganization after the inauguration of new superintendent of education. As important information was stored in individual staff’s PCs in the existing environment and such information was not managed properly, reorganization would have required considerable time and efforts to rearrange information management system. However, as all important information was stored in the central server under the network separation project, when access policy of authority to approach the relevant information was changed, we could proceed with our work safely and conveniently even in the renewed organization environment.

 
Also, as we did not need to deliver data by email or USB, and the information accessible within authority could be approached whenever and wherever, collaboration with external organizations or work outside of the Office of Education could be done easily. Further, even in case of faulty PCs in use, as we can work at another PC without PC backup, it is also advantageous to ensure work continuity.

 
Officer Kyo Kwon Jin explained that, “AS network separation has proceeded based on Cloud storage, and we could access necessary information whenever and wherever only with our own accounts, we could realize Smartwork environment. As an auditor or school inspector, who goes on frequent business trip to educational institutions, can do his task for himself at a school site, and he can finish his task with reduction in travel time, productivity and job satisfaction have increased.”
 
“Incheon Office of Education killed two rabbits-productivity and security-with the environment optimized network separation.”

 

Why did they proceed with the network separation project?

They needed a method to protect student personal information stored at the Incheon Office of Education. Besides, systematic management and protection method for important administration documents, which should not be released to outside illegally, were required. In the meantime, another necessity was to protect intranet mode from outsourced personnel stationed inside the Office of Education for IT system development, maintenance and repair.
 

How to make up Cloud storage based network separation environment.

 
Important information necessary for work was stored at the secure, safe central storage, and, according to authority access control policy, authorized person only could contact the information to proceed with the work. Basic work had to be done only in work network and normally internet contact was interrupted. When applicable information has to be transmitted to an outside organization, internet contact was possible only to the site where white list based security policy has already been permitted.
 
 

What is the effect of ClouDoc installation?

 
As user inconvenience increases under general network separation environments, field claims tend to congest. As network separation using ClouDoc allowed work process under the environment almost same as the existing work and internet contact was made rapidly, security was reinforced without affecting productivity. As it provides network separation environment based on Cloud storage, it is also effective in realizing Smartwork. As you can access your desired information using any PC anytime and anywhere and also an audit or superintendent of school with a lot of external business can immediately work outside, job satisfaction goes up.
 
 

 

2014년 10월 5일 일요일

How do you feel about Cloudoc after using it in your company?

 How do you feel about Cloudoc after using it in your company?





Selection of a proper solution for the purpose of the introduction of document centralization.




I wrote down opinions on how to select a document centralization solution from other articles in this blog.

Consequently, if a solution can be extended to the whole company from the first, the second, the third, up to the fourth, a customer may feel free to select the solution.


 

Customer who has introduced ClouDoc…


There is no business document in PC of the customer who has introduced ClouDoc. If PC is not workable due to software problems like physical disorder or malicious codes, you just need to replace it with another PC while resolving them.

 

 <Picture> Continuous business only with PC replacement


Who likes Cloudoc most? It is natural that corporate owners or management like it most. Because data dispersed in PC for the past time is accumulated in the center. In modern companies, documents are properties themselves.

   

 
 <Picture> Document centralization solution favored by management

 
  
 
 
If an employee of the company with document centralization left the office with a notebook, what would happen? Are office documents, CAD drawings, or program source codes in the notebook? As you may know, this kind of information leakage can be prevented in the company with ClouDoc.

Note) However, for a person who needs to work at home, a separate, safe function is arranged.



 
 
<Picture> What would happen if an employee in the company under document centralization system left the office with a notebook?





Effects of the introduction of ClouDoc solution




Consequently, 100% documents at maximum in all PCs can be stored in the center in the customer who has introduced ClouDoc. These stored documents are kept safely by several strong protective functions.


Note) The left picture below illustrates an example of the introduction of an fledgling stage of document centralization solution, while the right picture illustrates an example of the introduction of ClouDoc.

 
 
<Picture> ClouDoc document centralization like a solid safe!


Don’t you agree that documents stored and protected in the center can be led to productivity improvement and sales increase of your business?





<Picture>Accumulating documents are like money.

Build a happy company free from cash flow worries with document centralization!
 
 

 
 

How to find the best ‘document centralization solution’ for your company?

How to find the best ‘document centralization solution’ for your company?
 
 

Why Document centralization?
  
 
 Recently customers are looking at document centralization solution rather amicably.
Some customers are still in a nightmare of inconvenient and expensive initial document centralization solution, while some ClouDoc users add the number of users from the first, the second, the third, up to the fourth.
 
 In terms of a solution, document centralization solution tends to largely replace the following two solutions. 
 
  • Replacement of the existing document management (EDMS) : For effective document centralization and utilization, Document centralization is better than existing EDMS.
  • Replacement of the existing drawing security and document security (DRM) : From the point of compatibility and management of CAD drawing application, document centralization is good for efficiency improvement.

 
 
In terms of utilization, there are many customers for the following purposes.
  •  Drawing security
  • Source code security
  • Malicious code prevention
  • Information leakage prevention from Cloud service or P2P
 
 
 
How to select a proper Document centralization solution
 
Functional development of the document centralization solution is awesome. In case of ClouDoc, vendors sometimes visit customers in person and bring good ideas to market in the shortest time.
Currently, document centralization solutions can be largely divided into three schedules.
  •  Schedule 1, Security only : Only a storage prohibition function is loaded. Central document drive uses the network storage like NAS.  
  • Schedule 2, Hooking & Exclusive explorer : Hooking the standard work environment allows the solution to provide separate environment.
  •  Schedule 3, Standard (window file system)type : Offer of a window file system drive allows all work available in standardized methods.
 As Schedule 1 provides a security function only, strictly speaking with no document management function, it will be excluded from this description.
 
What problems in Hooking, Schedule 2?
  •  Applications without Hooking not yet cannot be stored in the center. 
  • Applications with Hooking impossible (graphic tools like 3D CAD applications and Indesign) cannot be stored in the center.
    •  Despite the promotion to support CAD, actually they are stored in C: drive and backed up in the center! Latest version always exists in PC only.
    • - Hooking is impossible for applications, where input/output in file is not done like Outlook but input/output of some blocks are done frequently.
  •  When interlocking with period system and file attachment like groupware, ERP, and so on in the future is necessary, separate development cost is required: high cost structure.
 
 
Finally, how about Schedule 3? Window file system, the standard type of Schedule 3, is the best type in compatibility for customers. However, Schedule 3 also requires harsh verification before product selection.
 
  • Aren’t a lot of troubles happening in the existing customers?
    • Blue screen: No response/ Document disappears/ Input/output errors often occur in some applications/ …
  • How many persons can be accommodated in a server?
  • Is there any temporary file left in the local disk of PC?
  • Doesn’t it cause a lot of load on the network of the company?
  •  In case of the customer with many users, does it support an extendable architecture using L4 device or the like?
  •  Does it directly support input/output of CAD drawings to and from the center?
    •  In case of some products, CAD application can be stored only in the local disk at all times.
  •  What are the names of customers with over 1,000 users using Window explorer file system among existing references?
 <Picture> How to select a proper Document centralization solution
 
Interlocking with the other system

 
Let’s see again the interlocking with the other system mentioned in the above for a while.
In case of ClouDoc, document can be attached to the other system without separate development. To the contrary, attached document of the other system can be stored in the ClouDoc.
However, in case of document centralization system of a hooking type, separate development is necessary to attach a document to the other system. Will it be no wonder to spend additional cost for the development?
<Picture> Interlocking with the other system
 
 
 


 
  

2014년 9월 2일 화요일

ClouDoc frees your network from copy & move of large amount of data!

ClouDoc frees your network from copy & move of large amount of data!


  

Document Copy and Move at Microsoft Windows FileServer


In general users of Windows FileServer utilizes one of the following methods for connection to Window Explorer. 
  
 The above methods are commonly used for Windows FileServer. In this case, if a file or folder is copied or moved, all applicable files come down to PC and up again to the server, requiring network much.

 

Document Copy and Move at ClouDoc
 

To limit such use of network, ClouDoc offers Copy or Move methods in the server. User or administrator may need to copy or move files in at least some MBs or as many as some TBs, In this case this function will not allow the company network to be loaded at all.
 

  
<Picture> Network traffic state during document copy and move in the server

 

 

What kind of method do you want?

  
  
Except for the above functions, ClouDoc includes the following diverse functions, which is not provided by the existing file server.
 
  
  • Folders in the private document box or team document box in the server are shared by other persons or teams 
  • Files in the private document box or team document box in the server are shared by link mail or link itself, and the usage is limited by code, period, or time.
  • Search function on documents in the server is provided in connection with a special search engine.
  •  Automatic version management function is provided for documents stored in the server.
 
Besides, ClouDoc will provide intelligent document management function additionally instead of providing a simple file server.











 

2014년 8월 26일 화요일

ClouDoc protects documents of your company using its own security architecture.

ClouDoc protects documents of your company using its own security architecture.

 

Personal information leaks were largely reported in January 2014, and presidents of each relevant companies were resigned.

*  KB Kukmin Card : leaks of 53 million
*  Lotte Card : leaks of 26 million
*  NH Nonghyeop Card : leaks of 25 million
 
In the meantime, personal information leak accident of Shinhan Card was reported additionally in April.
 
Besides, many information leak accidents were reported. Among them the information leak accident only in the Agency for Defense Development was caused by a malignant code, while the rest by people. ClouDoc, equipped with information leak preventing measures by people as well as by malignant codes, is the Document Centralization Solution, 
 


<Figure> ClouDoc Security Architecture
 
 
Document Centralization Solution which uses PC disk locking
 
ClouDoc provides disk IO control(disk locking) functions for USB drive, CD/DVD drive, and network drive, as well as local disk for the designated applications. Especially, unlike other products, disk IO control is realized by using a characteristic value of application instead of application name or file name.
ClouDoc - Comparison of disk IO control(disk locking) methods
 
<Table> Comparison of disk IO control(disk locking) methods
 
‘Information leak prevention by malignant code’ by separating Networks
 
ClouDoc’s NetworkLock module provides Network separation function without additional hardware nor network infrastructure change. For information leak prevention, users are controlled to the minimum in the intranet or internet modes.
 
ClouDoc - User environment control under ClouDoc NetworkLock environment
 
<Figure> User environment control under ClouDoc NetworkLock environment
 
 
Only approved documents can be provided to partners.
 
ClouDoc provides the safe approval system for document exchange with partners. Only the approved documents can be delivered to outside, and the documents from outside are automatically moved to the applicable user drive for use.
 
Offer embedded approval system to export document
Documents in the central location can be exported after approval. Approved documents can be attached to 'email, messenger, or bulletin boards'. And they can be stored in the security drive area in local disk for outside work.
 
 ClouDoc - Two kinds of document exports
 <Table> Two kinds of document exports
 
Suggestion of the Knowledge management roadmap in the future safe security environment
 
ClouDoc is not just a solution to reinforce security environment only.
Customers adopting ClouDoc can gather documents in central server naturally as well as reinforce security system. Almost 100% task documents in staff’s PCs are gathered into the corporate owned storage.
 
ClouDoc strives to provide Knowledge management environment so that tremendous amount of documents accumulated in center can be used effectively for corporate work environment. And it will provide document management function suitable for the new internet era through continuous function update in the future. 

 









ClouDoc supports version management automatically even though you just open and save 'office and CAD documents'.

ClouDoc supports version management automatically even though you just open and save 'office and CAD documents'.


Does Window file server allow document version management?

Companies, which did not adopt document centralization solution, manage documents using NAS or window file servers. Some people may have thought that automatic management of previous versions would be preferable when Office documents and CAD drawings were stored in Window file server.
 

ClouDoc can cover version management of CAD drawings!
ClouDoc will cover document version management if document is stored. Kinds of applications to cover version management identified up to now are as follows:
  • MS Office
  • Illustrator
  • Photoshop
  • AutoCAD

You do not need to do separate work like check-out/check-in for version management. Only correction of the document and storage will allow version management.



<Picture> Office document, Graphic frame, CAD document version management
 

 

Take care of previous documents meticulously!



Documents in ClouDoc made out by application where version management is supported, can be recovered into the previous document anytime during storage period even after being overlapped. Thus, document overlapped by mistake can be used again. Your employee may experience the moment of happiness with the recovery of a previous document at least one time.