McAfee Secure 網站能協助您遠離身份竊取、信用卡詐欺、間諜軟體、垃圾郵件、病毒和線上詐騙

北美法規

遵循政府及產業特定的要求

後續步驟:

概觀

McAfee 解決方案有助於遵循不斷增加的產業及政府法規,並證明法規遵循狀態。透過 McAfee,您可以針對保護私人、金融和其他敏感資料的北美法規,建立持續且一致的作法來達成遵循作業所需的控制,例如:

  • 21 CFR 第 11 章 (FDA)
  • 加州 AB 1950
  • 加州 SB 1386
  • 公平正確信用交易法 (FACTA)
  • 公平信用報告法案 (FCRA)
  • 聯邦能源管制委員會 (FERC)
  • 金融服務現代化法案 (GLBA)
  • 健康保險流通與責任法案 (HIPAA)
  • 支付卡產業資料安全標準 (PCI DSS)
  • 個人資訊保護與電子文件法案 (PIPEDA)
  • 沙賓法案 (SOX)

有鑑於法規通常都有解釋的餘地,而且許多組織受到五種以上立意近似的法規所規範,McAfee 能夠因應並提供常用且一致的控制功能,來協助統整用以保護貴公司並展現法規遵循狀態的控制作業。這種統一的作法能夠節省您的作業和時間,讓您的安全架構達到最佳化的效果。

McAfee 的端點到網路產品組合能夠讓您充分處理資料外洩、內部威脅、存取缺口及惡意攻擊。我們能夠協助您瞭解受規範的資料所在位置,以及如何實作保護這些資料的原則及控制。報告範本可協助產生所需的證明文件。透過自動化及整合能夠節省時間,將節省的時間用來處理核心業務的方案。

主要優點

  • 針對多種法規及業務要求加以統一的控制
    將您的需求與業界最佳作法相對應,並簡化控制,以達到共通的要求,並制定一致的行動計劃。
  • 管理的廠商更少,進而更輕鬆達到遵循法規的需求
    存取業界涵蓋範圍最廣的技術與原則需求,合併端點、網路與雲端控制項,並更容易遵循產業、聯邦及各州的法規。點選 McAfee Security Innovation Alliance 共存系統以擴大範圍。
  • 以自動化的工作節省時間並增加正確性
    避免耗時的特殊處理程序,並消除使用 McAfee 自動掃描、稽核、修補、執行與報表作業發生的錯誤。
  • 評估風險與安排修補的優先順序 - 自動
    找尋端點及網路系統的問題,並排定優先順序,然後與弱點、違規、資產及對策資料相互關聯,以運用有限資源達到最大程度的法規遵循效果。
  • 享受簡化的集中法規遵循報表
    提供標準化範本編譯所有有代理程式與無代理程式系統的資料,以瞭解全貌,並以這些範本改善法規遵循的資料收集與報表工作。自訂符合執行長與稽核人員需求的報表。
  • 將 IT 控制項間的檢視合併
    使用單一的 McAfee ePolicy Orchestrator (ePO) 管理平台即可看到整個 IT 控制單位與 PCI 需求 — 減少與個別產品整合所帶來的工作難度、費用與延遲。
  • 使用自動化的原則定義節省時間並減少麻煩
    運用領先業界的自動化原則範本,存取並對應法規準則的 IT 控制。
  • 以出埠電子郵件控制避免資料外洩
    使用預先定義的字典 (僅英文版) 及啟發式分析,自動掃描電子郵件是否有財務和私人資訊。依據原則將訊息予以封鎖、監控或加密,以確保遵循法規。

客戶案例

Abtran (English)

McAfee security risk management solutions help Abtran meet clients’ increasing security requirements.

重點功能
  • Provided multiple layers of security risk management protection for Abtran’s clients
  • Reduced IT hours spent supporting, administering, and monitoring endpoint security
  • Cut time to produce weekly security reports from three or four hours to less than two minutes
  • Migrated easily and seamlessly from existing anti-virus solutions

California State University, Chico (English)

California State University, Chico, remediates system vulnerabilities and mitigates risk with McAfee Vulnerability Manager.

重點功能
  • Increased risk visibility at department and campus levels, enabling snapshot of security status at any time
  • Accelerated time to remediation by providing clear remediation steps for systems administrators
  • Reduced time spent scheduling vulnerability scans, and preparing and analyzing reports
  • Improved and accelerated decision making by providing user-friendly metrics, graphical reports, and trend analysis
  • Improved overall security risk posture

DSM (English)

DSM enlists McAfee to strengthen enterprise network security control and compliance.

重點功能
  • Provided full visibility into network traffic and connected systems
  • Simplified patch management
  • Improved compliance with regulations and policies
  • Increased efficiencies for significant cost savings

Idaho State Tax Commission (English)

Idaho State Tax Commission chooses McAfee to embed security in a new network infrastructure.

重點功能
  • Identified vulnerabilities and blocked threats
  • Delivered reliable endpoint protection
  • Enabled compliance with National Institute of Standards and Technology (NIST) security guidelines
  • Provided support for the commission’s defense-in-depth security strategy
  • Helped increase security awareness among network users

PAETEC (English)

Telecommunications provider PAETEC watches sales skyrocket with managed service based on McAfee Network Security Platform.

重點功能
  • Protected against emerging threats even before installation of new signatures
  • Delivered excellent performance and reliability to PAETEC customers, who enjoy thorough and timely protection against threats without IT infrastructure burdens
  • Differentiated against offerings from competitors
  • Contributed to an already strong revenue stream and grew to emerge as the fastest growing area of PAETEC’s business

產品

資料保護

McAfee Total Protection for Data Loss Prevention
McAfee Total Protection for Data Loss Prevention

McAfee Total Protection for Data Loss Prevention (DLP) 能保護任何地方 (網路、儲存系統或端點) 的敏感資料,以保護智慧財產並確保法規遵循;同時提供集中式部署、管理和報告功能,可以節省時間和金錢。

McAfee Total Protection for Data
McAfee Total Protection for Data

McAfee Total Protection for Data 提供強式的加密、驗證、資料遺失防止和政策導向安全控制功能,可以隨時隨地防止未經授權存取機密資訊的行為。

McAfee E-Business Server
McAfee E-Business Server

McAfee E-Business Server 產品能保護資料在儲存與交換時的安全,無論是在公司內部或外部。

Email & Web Security

McAfee Content Security Blade Server
McAfee Content Security Blade Server

McAfee Content Security Blade Server 能保護網路,利用單一部高效能的解決方案阻擋垃圾郵件、惡意軟體和其他入侵行為。Content Security Blade Server 採用新一代的刀鋒伺服器架構,能降低 IT 成本、精簡複雜性,並且能插入額外的掃描刀鋒來符合未來的容量需求,容易地加以延展。

端點保護

McAfee Host Intrusion Prevention for Desktop
McAfee Host Intrusion Prevention for Desktop

McAfee Host Intrusion Prevention for desktop 能用全方位的三重防禦 (攻擊特徵分析、行為式分析和系統防火牆),監控並阻擋不需要的活動,協助您保護商業的安全和產能,而這些操作都可以容易地從 McAfee ePolicy Orchestrator (ePO) 平台的單一主控台來進行管理。

McAfee Host Intrusion Prevention for Server
McAfee Host Intrusion Prevention for Server

McAfee Host Intrusion Prevention for Server 能防範網路竊賊所發動的複雜威脅。它能保護關鍵公司資產,包括伺服器、應用程式、客戶資訊和資料庫,協助您維持企業正常營運。

網路安全

McAfee Firewall Enterprise
McAfee Firewall Enterprise

McAfee Firewall Enterprise 是新一代的防火牆,可以取回控制能力並保護您的網路。

McAfee Network Security Platform
McAfee Network Security Platform

McAfee Network Security Platform 是業界最安全的網路入侵防禦系統 (IPS)。其由 McAfee Labs 所支援,能妥善保護客戶,平均可以領先威脅 80 天。它能即時阻擋攻擊,避免它們造成傷害,而且可以保護所有連接到網路的裝置。有了 Network Security Platform,您可以自動管理風險並落實法規遵循作業,同時能強化運作效率與降低 IT 人力。

McAfee Network User Behavior Analysis
McAfee Network User Behavior Analysis

McAfee Network User Behavior Analysis 提供即時可見度,可以掌握網路上使用者的行為,以及他們如何使用關鍵的商業應用程式。這個直覺的檢視可以提供降低風險並符合法規遵循需求所要的決策支援資訊。根據封包擷取結果來進行自動監控與分析,並且能即時修正安全原則,大幅提升準確性並降低偵測行為異常所需的時間與人力。

風險與法規遵循

McAfee Total Protection for Compliance
McAfee Total Protection for Compliance

McAfee Total Protection for Compliance 是業界第一個弱點管理、法規遵循評估和回報,以及全方位風險管理的整合式解決方案,能容易地達成法規遵循目的。

McAfee Application Control
McAfee Application Control

McAfee Application Control 確保只有被信任的應用程式可以在伺服器與端點上執行。它能減少來自未經授權軟體的風險、大幅提升端點控制能力、擴充原有功能系統的可行性而無須影響效能,並且還能減少營運支出。

McAfee Change Control
McAfee Change Control

McAfee Change Control 能落實原則並對檔案完整性問題發出警示,同時能選擇是否阻擋對關鍵系統檔案和目錄所發生的未經授權變更。

McAfee Integrity Monitor
McAfee Integrity Monitor

McAfee Integrity Monitor 能持續監控檔案完整性,這是測試和驗證環境安全性的必備要件。

McAfee Policy Auditor
McAfee Policy Auditor

McAfee Policy Auditor 會自動化內部和外部系統層級之 IT 稽核所需的資料收集和評估程序。

McAfee Risk Advisor
McAfee Risk Advisor

McAfee Risk Advisor 可主動綜合威脅、弱點和因應對策資訊,以找出真正有風險的資產,節省您的時間和金錢。

McAfee Vulnerability Manager 
McAfee Vulnerability Manager 

McAfee Vulnerability Manager 會尋找網路上的弱點和違反原則的行為,並且排定處理的優先性。它會在資產重要性和弱點緊急性中間取得平衡,讓您可以將防護放在最重要的資產上。

服務

Data Loss Prevention Assessment

偵測與防止未經授權傳輸或公開機密資訊。McAfee Foundstone 會辨識出遭複製的機密資料,或目前正從其原始應有容器中向外傳輸的機密資料。

Incident Management Check

建立更好、更有效的事件回應與管理程式。McAfee Foundstone 會分析您事件管理程式中的漏洞,並提出改善您緊急回應通訊協定的建議。

Regulatory & Compliance Check

符合資訊安全法規遵循需求。McAfee Foundstone 會評估組織的法規與遵循狀態的漏洞,並提出後續步驟的建議。

Vulnerability Management Check

評估弱點管理程式。McAfee Foundstone 會分析程式的漏洞,確保人員、程序與技術會達到正確的平衡。

資源

報告

Risk & Compliance Outlook 2012 (English)

In this global study, independent research firm Evalueserve examines the dynamic risk and compliance market, including the state of the industry, the challenges faced by enterprises, and emerging trends that will impact both consumers and vendors.

Risk & Compliance Outlook 2011 (English)

In this global study, independent research firm Evalueserve examines the dynamic risk and compliance market, including the state of the industry, the challenges faced by enterprises, and emerging trends that will impact both consumers and vendors.

白皮書

社群

論壇

沒有找到結果

部落格

  • RDP+RCE=Bad News (MS12-020)
    Jim Walter - 三月 14, 2012
    See March 15 and 16 updates at the end of this blog. —————————————————-   The March Security Bulletin release from Microsoft was relatively light in volume. Out of the six bulletins released, only one was rated as Critical. And for good reason. MS12-020 includes CVE-2012-0002. This flaw is specific to the Remote Desktop Protocol (RDP) present on Read more...
  • An Update on DNSChanger and Rogue DNS Servers
    Jim Walter - 三月 06, 2012
    In late 2011, the FBI released documents and data focusing on “Operation Ghost Click.” This malicious operation, leveraging a variety of DNSChanger-type malware, was defined by the FBI as an “international cyber ring that infected millions of computers.” Associated malware samples and events can be traced back several years, and multiple platforms were targeted. To this day many remain Read more...
  • McAfee Q4 Threats Report Shows Malware Surpassed 75 Million Samples in 2011
    David Marcus - 二月 21, 2012
    Today we released our Fourth Quarter 2011 Threat Report, revealing that malware surpassed the our estimate of 75 million unique malware samples last year. Although the release of new malware slowed a bit in Q4, mobile malware continued to increase and recorded its busiest year to date. Malware The overall growth of PC-based malware actually Read more...
  • Cultural Security: Promoting Security Policies Using Organizational Culture
    Steven Fox - 九月 06, 2011
    Most of us refer to security policies in much the same way as we refer to our car manuals – when something unexpected happens.  We know these documents have useful information.  However, their utility is tied to situations where answers do not present themselves readily. According to Chris Noel, SVP of Product Management at ANXeBusiness, Read more...
  • Building an Arsenal of Best-in-Breed Database Security Solutions
    Eric Schou - 八月 19, 2011
    Visit any news site on the Web, and undoubtedly you’ll come across a barrage of articles publicizing the details of yet another data breach. With the prominence of SQL injection attacks, and malicious insiders and hackers exploiting sensitive data stored on unpatched and vulnerable databases, enterprise organizations have found themselves reevaluating their security strategies. Following Read more...