Search free mortgage software,mortgage calculator
 
Web Security Compliance For Free with Web Application Firewall Software from Danish Armorlogic  
Published:  5/20/2008 12:27:11 AM
Company Site:  http://www.prweb.com/releases/web_security/web_application_f ..
Category:  E-Commerce
Last View 2/8/2012 2:44:38 PM
PR Hits 171




Technology PR:

May 19, 2008 -- Every company today has a presence on the Internet. The number of web applications (e-commerce, extranet, content management system, etc.) is increasing, and their growing importance to all aspects of business is obvious.

But it is estimated that 70% of current web applications are still open to attack.

While IT professionals work to secure the network perimeter, web applications continue to remain vulnerable. Web application vulnerabilities threaten not only the organization running the application, but also visitors to these websites. These visitors may lose their privacy.

Regulators are therefore increasingly requiring companies to secure their web applications and thus to purchase web application firewalls having source code reviewed and spending valuable resources fixing security problems.

Sarbanes Oxley, the Gramm-Leach-Bliley Act, HIPAA, the UK Data Protection Act, Payment Card Industry Data Security Standard (PCI-DSS), and other regulation require companies, throughout the world, to protect the web-based data which they control.

In particular the updated standard for securing websites accepting major credit cards, The Payment Card Industry Data Security Standard (PCI DSS 1.1), is very specific and prescriptive about web application security. In section 6.6 it requires that either an application layer firewall is installed or that web facing applications are tested by web security specialists.

Other standards are less prescriptive but PCI-DSS is likely to set the future standards of website security as it will serve as a guideline for auditors evaluating the strength of a company's security provisions.

Of course, from a technical standpoint, the best option would be to go for both (security testing and application firewall) but from a business perspective a lot of companies are likely to choose one of the options as only one is required, especially when they have to choose between $25K+ options, with high re-occurring cost.

Choosing the application firewall path, one option is to go for do it yourself manually configured open source application firewall solutions. For some it will work but as applications and website content tend to change over time (sometimes without the security administrator knowing it) the policy needs to be adjusted to reflect changes. Also this solution requires that the security administrator is skilled at regular expressions and that he/she has the complete picture of the web sites and applications including all input options.

There is no such thing as a free lunch and the price of the open source solution is a lot of time spent creating and adjusting the policy. The free web application firewall from Armorlogic is automated will require the policy to be manually adjusted as applications change.

Another option is to go for an automated appliance based solution which will automatically learn normal application behaviour and configure a policy allowing normal application use. These solutions will provide excellent protection but many businesses are put off by the price tag.

Clearly, the perfect solution would be an affordable automated solution allowing for fast track web security. That's Profense Professional web application firewall. "Profense fits the gap between free open source hard-to-manage-and-configure and expensive automated solutions allowing for a more balanced approach in terms of time/money spent on the solution. There may even be money left for application security testing," says Srebrenko Sehic, CTO of Armorlogic.

Some reasons for Armorlogic being able to offer their web application firewall at such attractive prices are that Profense is a "do it yourself appliance". Armorlogic provide an ISO image with a complete package including a minimalized OS (OpenBSD) which will turn a piece of server hardware into an appliance. Thus Armorlogic does not have to spend money on specialized hardware. Others have done a lot of work for Armorlogic making high quality Open Source software (OpenBSD, Apache, OpenSSL, etc.). Armorlogic rely on high numbers instead of high margins.
    
Download a free less automated version of Profense from www.armorlogic.com.

Learn more about Armorlogic and Profense, get a free license or download it to try the 30 trial at armorlogic.com.

About Armorlogic:
Armorlogic is a Danish software development company focused entirely on web application security. Armorlogic is founded on a solid foundation of expert knowledge in the areas web application development, network infrastructure, internet security and IT-security management.



Home  

 



Related Technology PR News:

PROMT Offers Free Antivirus Protection to its Customers; Leading Machine Translation Vendor Offers Translation Security for Documents and Websites - "We are delighted to offer our customers free virus protection that's recognized as high quality and effective in fighting malicious applications", said Nikolay Vasil (568 Views)

NRMA's Insurance Website Adds Great New Features to its Home Security Section - May 23, 2008 -- Home Security NRMA Insurance understands the importance ..  (546 Views)

Network Solutions Launches WatchDog™ Security Product Web Site Security Service Designed to Protect Online Business Owners and Customers - "WatchDog provides our customers with the most complete package of Web security services that are not only simple and user friendly, but also affordable," says Charlie Buc (504 Views)

Free Webinar From IT Governance To Answer the Big Questions About Information Security and ISO27001 - Allentown, PA May 24, 2008 -- A free webinar from IT governance consulta ..  (386 Views)

Xacti Delivers Free and Reliable Internet Security to Mozilla® Firefox® 3 Users with Web Security Guard 4.5.5 - Boca Raton, FL July 18, 2008 -- Xacti, a leading developer and provider ..  (236 Views)

RuleSpace Appoints Gary Thomassen as Vice President of Enterprise Products to Spearhead Continued Expansion into Web Security OEM Market - "Joining a market leader that is uniquely positioned for expansion in a new market is very exciting," said Thomassen. "RuleSpace is the clear market leader in powerin (235 Views)

Regence BlueCross and BlueShield Opts for OpenDNS as Primary Web Content-Filtering Solution for all 7 Thousand Employees, Significantly Increases Network Securi.. - San Francisco June 9, 2008 -- OpenDNS, the award-winning navigation serv ..  (130 Views)




RSS Feed of new press releases                                                             Home        Feed Map        Submit Press Release        Contact 
Privacy Policy