The fastest, open, infrastructure-independent, advanced analytics SQL database
Securely access and analyze enterprise (and public) text, audio & video data
An intuitive hunt and investigation solution that decreases security incidents
User and entity behavioral analytics that augments existing security tools and empowers security operations teams to identify and respond to the threats that matter before data is stolen
Autonomous operations through a business lens
Intelligent automation for service desk, configuration, and asset management
SQL analytics solution handling large amounts of data for big data analytics
High-scale protection of sensitive data at rest, in motion, and in use across systems
Agile/DevOps management for continuous quality and delivery
Manage and track requirements from idea to deployment
Plan, track, orchestrate, and release complex applications across any environment
Enable all aspects of SCCM with enterprise grade scalability, security, and compliance
Automate deployments for continuous delivery with drag-and-drop simplicity
Govern application lifecycle activities to achieve higher quality
Unify test management to drive efficiency and reuse
Integrated, component-based test framework that accelerates functional test automation
Accelerate functional test automation across web, mobile, API, and enterprise apps
Discover, design, and simulate services and APIs to remove dependencies and bottlenecks
Shift-left functional testing using the IDE, language, and testing frameworks of choice
Reliable and efficient test automation for functional and regression testing
Centralized, omnipresent lab to develop, debug, test, monitor, and optimize mobile apps
Learn more about the LoadRunner Family of solutions
Cloud-based solution to easily plan, run and scale performance tests
Project-based performance testing to identify performance issues
Easy-to-use performance testing solution for optimizing application performance
Collaborative performance testing platform for globally distributed teams
Discover, design, and simulate services and APIs to remove dependencies and bottlenecks
Identifies security vulnerabilities in software throughout development
Gain valuable insight with a centralized management repository for scan results
Manage your entire application security program from one interface
Provides comprehensive dynamic analysis of complex web applications and services
Builds packages of change artifacts to speed up mainframe application development
Enable faster, efficient parallel development at scale
A development environment that streamlines mainframe COBOL and PL/I activities
Intelligence and analysis technology that provides insight into core processes
Fuel mobile apps, cloud initiatives, process automation, and more
Future-proof core COBOL business applications
Maintain and enhance ACUCOBOL-based applications
Deliver application access—anywhere
Maintain and enhance COBOL systems
Maintain and enhance RM/COBOL applications
Connect COBOL applications to relational database management systems
Derive incremental value with real-time, relational access to COBOL data
Unlock business value with real-time, relational access to ACUCOBOL data
Connect ACUCOBOL applications to relational database management systems
Automatically understand and analyze Micro Focus COBOL applications
Build COBOL applications using Agile and DevOps practices
Deploy COBOL applications across distributed, containerized or cloud platforms
Modernize core business system infrastructure to support future innovation
Manage agile projects using a collaborative, flexible, requirements and delivery platform
Manage requirements with full end-to-end traceability of processes
Automatically understand and analyze IBM mainframe applications
Capture, analyze, and measure the value, cost and risk of application portfolios
Build packages of change artifacts to speed up mainframe application development
Build and manage packages of change artifacts to speed up mainframe application development
Provide multiple change management interfaces to maintain mainframe apps
Build and modernize IBM mainframe COBOL and PL/I applications
Enable faster, efficient parallel development at scale
Fuel mobile apps, cloud initiatives, process automation, and more
Manage mainframe files for fast problem resolution
Easily test mainframe application changes using flexible infrastructure
Compare and manage mainframe data, text, and directory files
Connect Dev and Ops by automating the deployment pipeline and reduce feedback time
Centralize planning and control for the entire software release lifecycle
Orchestrate and integrate processes for faster software development and delivery
Detect changes, synchronizes multiple environments, and restores failed systems
Execute IBM mainframe COBOL and PL/I workload on Windows, Linux and the Cloud
Execute modernized IBM mainframe workloads under Microsoft .NET and Azure
Modernize IBM, HP, and Unix application access across desktop and mobile devices
Web-enable IBM and VT application desktop access, Java free
Modernize Unisys mainframe application desktop access
Modernize IBM, HP, and Unix application desktop access
Automate IBM, HP, and Unix application desktop access
Create new applications and workflows with Web services and APIs for IBM, HP, and UNIX applications
Fuel analytics platforms and BI applications with Unisys MCP DMSII data in real time
Centralize host access management with identity-powered access control and data security
Modernize file transfer with security, encryption and automation, within and across the firewall
Learn how Advanced Authentication Connector for z/OS is a multi-factor authentication for all your IBM z/OS end points
Measure and manage terminal-based software deployment and usage
Centralize host access management with identity-powered access control and data security
Develop and deploy applications with a comprehensive suite of CORBA products
Build distributed applications at enterprise scale
Develop, deploy, and support CORBA 2.6 compliant middleware in C++ or Java
Connect applications on diverse operating environments
Email, IM, chat-based teamwork, anti-virus, anti-spam, disaster recovery, and more
Provides secure file access and sharing from any device
Provides secure email, calendaring, and task management for today's mobile world
Backup and disaster recovery solution that ensures critical email is always available
Seven essential tools to build IT infrastructures, including secure file sharing
Provides secure team collaboration with document management and workflow features
Provides single sign-on for enterprises and federation for cloud applications
Protect your sensitive information more securely with multi-factor authentication
File Reporter and Storage Manager solution suite bundle
File Reporter for OES examines OES network file systems and delivers intelligent file insights so you can make the most intelligent business decisions.
Provides secure file access and sharing from any device
Protects your key business systems against downtime and disaster
Simplifies resource management on a Storage Area Network and increases availability
File, print, and storage services perfect for mixed IT environments
Cloud-based endpoint backup solution with file sync and share, and analytics
Package, test, and deploy containerized Windows apps quickly and easily
Seven integrated products to help track, manage and protect endpoint devices
Provides reports that integrate licensing, installation and usage data
Provides automated endpoint management, software distribution, support, and more
Delivers identity-based protection for devices and features total protection
Proactive laptop and desktop data protection to automatically lock out threats
Automates patch assessment and monitors patch compliance for security vulnerabilities
Streamlines and automates the way you provide IT services to your business
Cloud-based, scalable archiving for regulatory, legal, and investigative needs
Archive all business communication for case assessment, search, and eDiscovery
Automate employee data and communication monitoring to meet regulatory compliance and internal initiatives
Mitigate risk across social media channels to meet regulatory compliance obligations
Helping organizations meet data privacy regulatory guidelines through the management & disposition of data.
Address the ever-changing needs of network data management
File analysis to discover, classify and automate policy on unstructured data
Discover what is being stored and who has access
Structured data archiving to retire outdated applications and reduce data footprint
Identity-driven governance of data & access
SaaS-based file analysis on all of your unstructured data
Respond to litigation and investigations quickly, accurately, & cost-effectively
SaaS-based file analysis on all of your unstructured data
File analysis to discover, classify and automate policy on unstructured data
Discover what is being stored and who has access
Address the ever-changing needs of network data management
Structured data archiving to retire outdated applications and reduce data footprint
Helping organizations meet data privacy regulatory guidelines through the management & disposition of data.
Securely access and analyze enterprise (and public) text, audio & video data
Backup and disaster recovery for diverse, dynamic, and distributed enterprise
Automate provisioning, patching, and compliance across the data center
Discover and manage configuration items (CIs) in Hybrid IT environments.
Simplify fulfillment automation and enforce governance
Automate and manage traditional, virtual, and software-defined networks
The first containerized, autonomous monitoring solution for hybrid IT
Automate IT processes end-to-end
Build, secure, and scale automated business processes across the enterprise
Engaging end-user experience and efficient service desk based on machine learning
A comprehensive threat detection, analysis, and compliance management SIEM solution
An intelligent log management solution that eases compliance burdens and accelerates forensic investigation for security professionals
A comprehensive log management solution for easier compliance, efficient log search, and secure cost-effective storage.
Download and deploy pre-packaged content to dramatically save time and management
A future-ready data platform that transforms data chaos into security insight.
User and entity behavioral analytics that augments existing security tools and empowers security operations teams to identify and respond to the threats that matter before data is stolen
A fully-featured, adaptable solution that simplifies the day-to-day use of SIEM
A comprehensive Security Orchestration Automation Response platform with cognitive automation, investigation service desk, process orchestration and SOC analytics.
Persistent file encryption, complete control, and visibility to simplify unstructured data security
Format-preserving encryption, tokenization, data masking, and key management
Omni-channel PCI compliance and data protection for end-to-end payments security
Email, file, and Office 365 protection for PII, PHI, and Intellectual Property
Saas cloud email encryption to protect information on Office 365
The full solution for secure automated file transfer management inside and across perimeters
Identifies security vulnerabilities in source code early in software development
Provides comprehensive dynamic analysis of complex web applications and services
Gain valuable insight with a centralized management repository for scan results
Manage your entire application security program from one interface
Gain visibility into application abuse while protecting software from exploits
Provisions and governs access to unstructured data
Provides an LDAP directory with incredible scalability and an agile platform
Provides automated user access review and recertification to remain compliant
Delivers an intelligent identity management framework to service your enterprise
Provides single sign-on for enterprises and federation for cloud applications
Move beyond username and passwords and securely protect data and applications
Multi-factor Authentication for all your IBM z/OS end points
Integrate the host with your modern security framework
Adapt the authentication and access experience to the risk at hand.
Enables users to reset their passwords without the help of IT
Streamlines authentication for enterprise apps with a single login experience
Protect and manage access to your APIs.
Enables IT administrators to work on systems without exposing credentials
Limits administrative privileges and restricts directory views to specific users
Edit, test and review Group Policy Object changes before implementation
Protect critical data, reduce risk and manage change with Change Guardian
Extend the power of Active Directory to Linux resources
Unify and centrally manage policies across multiple platforms.
Protect critical data, reduce risk and manage change with Change Guardian
Finds and repairs configuration errors that lead to security breaches or downtime
Provides easy compliance auditing and real-time protection for IBM iSeries systems
Protect your network and messaging system from malware, viruses, and harmful content
Scalable, end-to-end encrypted email solution for desktop, cloud, and mobile
Cloud-based endpoint backup solution with file sync and share, and analytics
Package, test, and deploy containerized Windows apps quickly and easily
Provides reports that integrate licensing, installation and usage data
Provides automated endpoint management, software distribution, support, and more
Delivers identity-based protection for devices and features total protection
Proactive laptop and desktop data protection to automatically lock out threats
Automates patch assessment and monitors patch compliance for security vulnerabilities
Streamlines and automates the way you provide IT services to your business
Seven integrated products to help track, manage and protect endpoint devices
Help you embed security throughout the IT value chain and drive collaboration between IT operations, applications, and security teams.
Help you to react faster and gain a competitive advantage with enterprise agility.
Accelerate your hybrid cloud outcomes with advisory, transformation and implementation services.
Application management services that let you out-task solution management to experts who understand your environment.
Strategic consulting services to guide your digital transformation agenda.
Fully functional use-case modeling, with pre-built integrations across the Micro Focus Software portfolio, showcasing real-life use-case
Expert security intelligence services to help you quickly architect, deploy, and validate your Micro Focus security technology implementation.
A service integration and management service that optimizes delivery, assurance, and governance in multi-supplier settings.
Get insights from big data with real-time analytics, and search unstructured data.
Get insights from big data with real-time analytics, and search unstructured data.
Get insights from big data with real-time analytics, and search unstructured data.
Mobile services that ensure performance and expedite time-to-market without compromising quality.
Get insights from big data with real-time analytics, and search unstructured data.
Comprehensive Big Data services to propel your enterprise forward.
All Micro Focus learning in one place
Belarusian Telecommunications Network (“BeST”, trademark “life:)”) is the mobile carrier with the third highest number of service users in the Republic of Belarus. In addition to the services that relate to the brand life:), the company offers digital services, including TV+ television service, fizy music service, Apps Club (a gaming application), BiP messenger, Lifebox cloud storage and others.
Industry
Location
Product
In 2008, the high-profile Turkish telecom operator Turkcell became the principal shareholder in BeST. Since its capital is listed on the New York Stock Exchange (NYSE), Turkcell conducts an annual audit in accordance with the American Sarbanes-Oxley Act (SOX). This audit is mandatory for subsidiary companies such as ZAO BeST.
To ensure the required level of information security (IS) at the company, IS events from a wide range of critical systems and telecom equipment from a variety of vendors need to be captured and processed. It is also important to identify, investigate, and react to IS incidents as quickly as possible. The company used a SIEM to this end, but the discontinuation of manufacturer support in 2015 prompted a replacement.
To select and implement a new SIEM system, ZAO BeST turned to OOO Lifetech, which is a subsidiary organization that provides IT and IS services. The key requirements for choosing a new system were: performance and scalability; guaranteed event source capture, including critical applications, systems and telecommunications equipment; ease of implementation and maintenance; the ability to search for event correlations to identify IS incidents; provision of reporting and dashboards with all the necessary information for monitoring and SOX audits. It was implemented in a short time – less than 6 months.
The products Micro Focus ArcSight Enterprise Security Manager (ArcSight ESM), IBM QRadar, and the open source software Elasticsearch in conjunction with Kibana were considered during the selection process. ArcSight ESM was chosen following comparison of these solutions and evaluation of how they comply with the key requirements for the new SIEM system.
“One of its main advantages was the ability to capture events from a large number of systems, more than 400 standard connectors (Smart connectors) and a dedicated connector (Flex connector), the configuration design which ensures that events are captured from most systems. Using ArcSight ESM we were able to process events from all the large-scale critical systems and telecommunications equipment at our company,” says Aleksandr Turlo, Head of IT and IS at OOO Lifetech. “Another important aspect is that the rival products could not provide sufficient performance at a significant load (2,500 events per second). This could result in the loss of individual events, which is absolutely unacceptable. To effectively secure IS and breeze through SOX audits we need to monitor even minor changes in the systems responsible for financial reporting. Turkcell and its subsidiary companies must be transparent for shareholders and auditors.”
ZAO BeST has a suite of applications, systems and equipment at its disposal: billing system, CRM, ERP, DBMS, virtualization platform, various network and telecommunications equipment.
Aleksandr Turlo explains the basic requirements of the IT process. One of the key requirements is the need to monitor not only IS incidents, but also implement changes in the configuration. For example, it is necessary to check that a particular change has been approved and to check compliance with procedures in accordance with the company’s operating processes.
IT processes at ZAO BeST are based on ITIL recommendations, which fully comply with SOX audit requirements.
Lifetech implemented all the ArcSight modules. It took less than four months to build the system in the existing IT landscape and configure all the necessary settings. The licenses were obtained in August 2016 and project implementation started at the end of September and completed in January 2017.
Prior to starting the ArcSight ESM expansion, Lifetech specialists developed an architecture for the new SIEM system: they determined which of the systems, applications, and telecom equipment would be monitored and in what sequence they should be connected. Recommendations from Micro Focus experts were considered when making decisions.
ArcSight was rolled out in the virtual environment and no additional equipment or software were required. First, integration with the Active Directory catalog, the email server, and SMS centers of the company was provided to send regular reports and receive notifications about incidents. Then, work began to set up the monitoring systems, applications, and telecom equipment at ZAO BeST. More than 26 types of Flex connector were developed for unique event sources during the main integration work, which enabled IP addresses to be added automatically to the quarantine list and network attacks to be blocked. The specialists then began to ‘fine-tune’ the connectors and exclude events from the stream that are not significant in terms of IS or SOX audit controls, but that create an additional load on the SIEM system. The following steps were to configure the report settings and dashboards, and integration of ArcSight with the Service Desk corporate system.
In the final stages of the project, integration with a third-party SOC was achieved by rolling out additional ArcSight modules. “To optimize its processes, Lifetech has carried out integration with the monitoring and incident response center (SOC). The stream of events that enters our SIEM system is duplicated in the SOC center. Its analytics perform the primary processing of IS incidents and report on critical incidents, providing the information discovered during the investigation. This allows us to decide on effective solutions and actions to eliminate identified incidents,” according to Alexandr Turlo.
Before the new SIEM system based on ArcSight ESM was launched into production, the old and new systems worked in parallel. Once Lifetech specialists were confident the new system was functioning accurately and reliably, the previous system was retired.
The new SIEM system based on ArcSight provides the required performance and data throughput. Lifetech specialists were able to ensure the guaranteed real-time collection of all events and their aggregation and normalization, despite the variety and distribution of systems by data centers and the industry specific system protocols (logs) of telecom equipment. Events are stored in the SIEM system for 90 days with instant access. Later events are backed up daily for 13 months without modification.
ArcSight ESM is also integrated with the company’s existing IT systems (IPS, FW, antivirus, IAM) and automated response has been implemented for certain incidents, which has greatly increased the level of security for the information systems. In addition, events are entered into more than 40 reports that have been created and are scheduled to be generated regularly (daily, weekly, monthly) to ensure the implementation of SOX audit controls.
Today, ArcSight ESM collects and analyzes events in critical systems, applications, and telecommunications equipment involved in supporting ZAO BeST’s business processes.
As Aleksandr Turlo has noted, an important achievement thanks to implementing the SIEM system based on ArcSight ESM is that the number of successfully passed SOX audit controls has nearly doubled, from 46 to 86%.
“We were particularly impressed by ArcSight ESM’s extensive integration capability, flexible settings, high level of performance, and potential to scale in the event of an increased event flow and system load,” Alexandr continues. Integration of ArcSight ESM with Service Desk systems: incidents that are contained in the scheduled downloads from SIEM reports are automatically registered by the Service Desk. This helps to substantially increase the effectiveness of internal control processes.
Lifetech specialists are continuing to develop the ZAO BeST SIEM system. All new event sources are integrated in ArcSight ESM. Looking ahead, there are plans to use the Interset User and Entity Behavioral Analytics functionality from Micro Focus for behavioral analysis of users to identify abnormal activities.
The Lifetech team is also reviewing the possibility of acquiring other Micro Focus products. In particular, ArcSight Transformation Hub enables data to be quickly distributed from sources and transfers it not only to the SIEM system, but also to other centers to be processed and analyzed.
We were particularly impressed by ArcSight ESM’s extensive integration capability, flexible settings, high level of performance and possible scalability in the event of an increased event flow and system load.
Thanks to the implementation of the SIEM system based on ArcSight ESM, the number of successfully passed SOX audit controls has almost doubled from 46 to 86%.