IBM Boosts Mainframe Security

IBM last week unveiled a new release of its mainframe operating system -- the z/OS -- adding features that increase the software's already fortress-like security for online commerce as well as the next generation of highly secure business transactions. IBM also announced new mainframe software that automates security administration and audit processes.

"Originally designed to be shared by thousands of users, the IBM mainframe has security built into nearly every level of the computer -- from the processor level, to the operating system to the application level," said Jim Porell, Distinguished Engineer and System z Chief Architect. "Our security leadership is one of the many reasons why the world's top banks rely on the IBM mainframe for their financial transactions."

For companies running "thousands" of transactions that require identity validation and lightning fast communications from countless customers and unknown parties, the new IBM z/OS is designed to deliver the following:

• Improved network security policy management -- making it easier to set network security policy across multiple instances of z/OS mainframe operating systems. Administrators only need to define one centralized policy to enforce network encryption rules and intrusion detection for all z/OS systems within an enterprise -- including distributed systems attempting communication with z/OS systems.

• Enhanced Public Key Infrastructure (PKI) services to help improve the creation, authentication, renewal, and management of digital certificates for user and device authentication. By managing digital certificates directly through their z/OS mainframe, customers can potentially see substantial savings compared to the cost of third party hosting. This capability is essential in creating the digital certificates for buyers and sellers to conduct secure business transactions online. z/OS's PKI can be used for many important tasks, such as securing a wireless network infrastructure using WPA security, exploiting smartcard technology on credit and cash cards and securing the end nodes of a Virtual Private Network that might be hosting Point of Sale or ATM communications traffic.

• Adoption of the popular security standard, PKCS #11, which specifies an application programming interface for devices that hold cryptographic information and perform cryptographic functions. These functions are now provided on z/OS to help host applications that utilize this standard onto z/OS to take advantage of the centralized key storage provided by z/OS. Additional enhancements include more robust scalability and availability for clustered environments, improved economics via expanded use of specialty engines, simplified management for network diagnosis, among others. For details, log on to http://www-03.ibm.com/servers/eserver/zseries/zos/.

Featured

  • It's Show Time

    I am one of those people that likes to see things get bigger and better. As advertised, ISC West is going to be bigger (more exhibitors) and better (more attendees). It’s show time in Las Vegas. Read Now

    • Industry Events
    • ISC West
  • SIA Releases New Report on Operational Security Technology

    The Security Industry Association (SIA) has released an impactful new resource – Operational Security Technology: Principles, Challenges and Achieving Mission-Critical Outcomes Leveraging OST. Read Now

  • Cyber Overconfidence Is Leaving Your Organization Vulnerable

    The increased sophistication of cyber threats pumped by the relentless use of AI and machine learning brings forth record-breaking statistics. Cyberattacks grew 44% YoY in 2024, with a weekly average of 1,673 cyberattacks per organization. While organizations up their security game to help thwart these attacks, a critical question remains: Can employees identify a threat when they come across one? A Confidence Gap survey reveals that 86% of employees feel confident in their ability to identify phishing attempts. But things are not as rosy as they appear; the more significant part of the report finds this confidence misplaced. Read Now

  • Mission 500 Debuts Refreshed Identity Ahead of Security 5K/2K at ISC West

    Mission 500, the security industry’s nonprofit charity dedicated to supporting children in need across the US, Canada, and Puerto Rico, has unveiled a refreshed brand identity ahead of ISC West. The charity’s new look includes a modernized logo with refined messaging to reinforce Mission 500’s nearly decade-long commitment to serving the needs of children and families in crisis. Read Now

    • Industry Events

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.