SlideShare a Scribd company logo
1 of 2
Download to read offline
S U C C E S S S T O R Y
Faysal Bank Protects Business-Critical
Banking Systems with NetIQ
Executive Summary
INDUSTRY DESCRIPTION
Faysal Bank Limited (Pakistan) offers
corporate, commercial, retail and Islamic
banking services in more than 260
branches in over 70 cities throughout
Pakistan. The company is a wholly
owned subsidiary of Ithmaar Bank B.S.C.,
listed on the Bahrain and Kuwait stock
exchanges.
BUSINESS SITUATION
To improve security, Faysal Bank
Ltd. wanted to improve its ability to
supervise IT administrators’activities.
The organization needed to monitor
critical systems supporting core banking,
credit card processing, and network
infrastructure.
THE NETIQ DIFFERENCE
NetIQ Sentinel Log Manager
consolidates logs from multiple systems
in real time, providing a clear, central
view of all activity, with the ability to
create detailed reports and set up event-
triggered alerts.
NETIQ PRODUCTS AND SERVICES
NetIQ® Sentinel™ Log Manager
Faysal Bank Ltd. employs approximately
4,000 people across more than 260
branches in Pakistan. The bank maintains
dozens of large databases, many of which
contain sensitive and business-critical
data. Of the 100 people on the IT team,
approximately 5 to 10 staff members
work directly on database administration.
Following internal best practices for
security, the IT management team gives
limited access rights to technical staff,
providing temporary full administrative
privileges only when necessary.
“We had introduced preventative controls
for security reasons, but it was difficult to
check that administrative privileges were
being used appropriately,”said Zahir Ali
Quettawalla, Head ITSRM, Faysal Bank Ltd.
“We needed a solution for monitoring
logs from multiple systems that would
present the information in a readable
format. The ability to review and query
the log data was vital: We did not want
to simply‘check the boxes’when it came
to complying with audit standards.”
The Solution
Following a thorough analysis of
security-monitoring solutions, Faysal
Bank Ltd. selected NetIQ® Sentinel™
Log Manager and worked with NDS, a
NetIQ partner, to deploy the solution.
“The NetIQ solution met almost all of
our log-monitoring requirements and
was considerably less costly than the
alternatives,”said Zahir Ali Quettawalla.
Faysal Bank Ltd. is now monitoring
logs for almost all of its critical
systems and user IDs, and is working
to develop reports and alerts
that will further improve visibility
and simplify compliance.
“NetIQ Sentinel Log Manager is a very
comprehensive tool, but it’s not humanly
possible to read every line of every
log,”said Zahir Ali Quettawalla.“We
are now working with NDS to create
consolidated reports and we are planning
to flag up suspicious activity using alerts
sent directly to BlackBerry devices.”
Worldwide Headquarters
1233 West Loop South, Suite 810
Houston, Texas 77027 USA
Worldwide: +1 713.548.1700
U.S. / Canada Toll Free: 888.323.6768
info@netiq.com
www.netiq.com
http://community.netiq.com
For a complete list of our offices
in North America, Europe, the
Middle East, Africa, Asia-Pacific
and Latin America, please visit
www.netiq.com/contacts.
Follow us:
Comprehensive reports enable IT
management to see at a glance
how and when users are using
administrator IDs. The reports
include the time and location of
access, and detailed information on
what commands users are running
with administrative privileges.
“With the NetIQ solution, we have a
complete record of user-generated
queries, which gives a very good idea
of what users are actually doing on
each database: which tables they
have accessed, which fields they have
changed, which values they have
updated,”said Zahir Ali Quettawalla.
With the log-monitoring solution
in place, Faysal Bank is now
embarking on a second phase.
“We have a system where users can
request access rights,”said Zahir Ali
Quettawalla.“An automated workflow
ensures approval by their line manager,
but there’s no easy way to check that
the requested access really fits that
person’s role. We are planning to deploy
Identity Manager from NetIQ to provide
full control over roles and access rights.”
The Results
A Clear View with Minimal Impact
Thanks to NetIQ Sentinel Log
Manager, Faysal Bank Ltd. now has a
clear view of administrator activity
across its most important databases.
“Administrators understand that they
are now being monitored by the NetIQ
solution, and that any out-of-the-
ordinary activities, whether accidental
or deliberate, will be permanently
visible,”said Zahir Ali Quettawalla.
Business managers previously
had concerns about setting up
logs on critical systems for fear
of impacting performance. NetIQ
Sentinel Log Manager captures
logs in real time and with zero
performance impact. Likewise, the
solution has minimal impact on
the IT team’s workload, enabling
full monitoring and sophisticated
reporting at the touch of a button.
Bringing Risk under Control
The ability to monitor and report
on comprehensive administrator-
activity logs is of great value in
demonstrating proper IT governance.
“The business risk associated with
administrative access to databases is
now under control, thanks to NetIQ
Sentinel Log Manager,”said Zahir Ali
Quettawalla.“We can set up real-time
alerts for defined security events,
and we also have a full evidence
trail for all historical activities.”
Learn more today by contacting
your NetIQ partner or a local NetIQ
sales representative, or by visiting
www.netiq.com for contact
information in your area.
“The business risk
associated with
administrative access to
databases is now under
control, thanks to NetIQ
Sentinel Log Manager.”
Zahir Ali Quettawalla,
Head IT Security Risk Management
(ITSRM),
Faysal Bank Limited (Pakistan)
NetIQ, the NetIQ logo, and Sentinel Log Manager are trademarks or registered trademarks of NetIQ Corporation in the USA.
All other company and product names may be trademarks of their respective companies.
© 2012 NetIQ Corporation and its affiliates. All Rights Reserved.	 CSS90064FBU ST 11/12

More Related Content

More from NetIQ

BrainShare 2014
BrainShare 2014 BrainShare 2014
BrainShare 2014 NetIQ
 
Paraca Inc.
Paraca Inc.Paraca Inc.
Paraca Inc.NetIQ
 
The University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity ManagerThe University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity ManagerNetIQ
 
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...NetIQ
 
Swisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User AccessSwisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User AccessNetIQ
 
Vodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQVodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQNetIQ
 
University of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log ManagerUniversity of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log ManagerNetIQ
 
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQNippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQNetIQ
 
Nexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations CenterNexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations CenterNetIQ
 
Netiq css huntington_bank
Netiq css huntington_bankNetiq css huntington_bank
Netiq css huntington_bankNetIQ
 
Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...NetIQ
 
NetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal UniversityNetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal UniversityNetIQ
 
Handelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQHandelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQNetIQ
 
Millions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQMillions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQNetIQ
 
bluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed Servicebluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed ServiceNetIQ
 
Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...NetIQ
 
Cloud Identity
Cloud IdentityCloud Identity
Cloud IdentityNetIQ
 
2014 Cyberthreat Defense Report
2014 Cyberthreat Defense Report2014 Cyberthreat Defense Report
2014 Cyberthreat Defense ReportNetIQ
 
Identity-Powered Security
Identity-Powered SecurityIdentity-Powered Security
Identity-Powered SecurityNetIQ
 
IT Disaster Recovery
IT Disaster RecoveryIT Disaster Recovery
IT Disaster RecoveryNetIQ
 

More from NetIQ (20)

BrainShare 2014
BrainShare 2014 BrainShare 2014
BrainShare 2014
 
Paraca Inc.
Paraca Inc.Paraca Inc.
Paraca Inc.
 
The University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity ManagerThe University of Westminster Saves Time and Money with Identity Manager
The University of Westminster Saves Time and Money with Identity Manager
 
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
The London School of Hygiene & Tropical Medicine Accelerates and Streamlines ...
 
Swisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User AccessSwisscard Saves Time and Effort in Managing User Access
Swisscard Saves Time and Effort in Managing User Access
 
Vodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQVodacom Tightens Security with Identity Manager from NetIQ
Vodacom Tightens Security with Identity Manager from NetIQ
 
University of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log ManagerUniversity of Dayton Ensures Compliance with Sentinel Log Manager
University of Dayton Ensures Compliance with Sentinel Log Manager
 
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQNippon Light Metal Forges a Disaster Recovery Solution with NetIQ
Nippon Light Metal Forges a Disaster Recovery Solution with NetIQ
 
Nexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations CenterNexus Differentiates Itself and Grows Its Capabilities with Operations Center
Nexus Differentiates Itself and Grows Its Capabilities with Operations Center
 
Netiq css huntington_bank
Netiq css huntington_bankNetiq css huntington_bank
Netiq css huntington_bank
 
Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...Professional Services Company Boosts Security, Facilitates Compliance, Automa...
Professional Services Company Boosts Security, Facilitates Compliance, Automa...
 
NetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal UniversityNetIQ Identity Manager Unites Hanshan Normal University
NetIQ Identity Manager Unites Hanshan Normal University
 
Handelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQHandelsbanken Takes Control of Identity Management with NetIQ
Handelsbanken Takes Control of Identity Management with NetIQ
 
Millions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQMillions of People Depend on Datang Xianyi Technology and NetIQ
Millions of People Depend on Datang Xianyi Technology and NetIQ
 
bluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed Servicebluesource Uses NetIQ AppManager to Offer Standout Managed Service
bluesource Uses NetIQ AppManager to Offer Standout Managed Service
 
Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...Central Denmark Region Strengthens Administrative Security with Identity Mana...
Central Denmark Region Strengthens Administrative Security with Identity Mana...
 
Cloud Identity
Cloud IdentityCloud Identity
Cloud Identity
 
2014 Cyberthreat Defense Report
2014 Cyberthreat Defense Report2014 Cyberthreat Defense Report
2014 Cyberthreat Defense Report
 
Identity-Powered Security
Identity-Powered SecurityIdentity-Powered Security
Identity-Powered Security
 
IT Disaster Recovery
IT Disaster RecoveryIT Disaster Recovery
IT Disaster Recovery
 

Recently uploaded

Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfOverkill Security
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodJuan lago vázquez
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 

Recently uploaded (20)

Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 

Faysal Bank Protects Business-Critical Banking Systems with NetIQ

  • 1. S U C C E S S S T O R Y Faysal Bank Protects Business-Critical Banking Systems with NetIQ Executive Summary INDUSTRY DESCRIPTION Faysal Bank Limited (Pakistan) offers corporate, commercial, retail and Islamic banking services in more than 260 branches in over 70 cities throughout Pakistan. The company is a wholly owned subsidiary of Ithmaar Bank B.S.C., listed on the Bahrain and Kuwait stock exchanges. BUSINESS SITUATION To improve security, Faysal Bank Ltd. wanted to improve its ability to supervise IT administrators’activities. The organization needed to monitor critical systems supporting core banking, credit card processing, and network infrastructure. THE NETIQ DIFFERENCE NetIQ Sentinel Log Manager consolidates logs from multiple systems in real time, providing a clear, central view of all activity, with the ability to create detailed reports and set up event- triggered alerts. NETIQ PRODUCTS AND SERVICES NetIQ® Sentinel™ Log Manager Faysal Bank Ltd. employs approximately 4,000 people across more than 260 branches in Pakistan. The bank maintains dozens of large databases, many of which contain sensitive and business-critical data. Of the 100 people on the IT team, approximately 5 to 10 staff members work directly on database administration. Following internal best practices for security, the IT management team gives limited access rights to technical staff, providing temporary full administrative privileges only when necessary. “We had introduced preventative controls for security reasons, but it was difficult to check that administrative privileges were being used appropriately,”said Zahir Ali Quettawalla, Head ITSRM, Faysal Bank Ltd. “We needed a solution for monitoring logs from multiple systems that would present the information in a readable format. The ability to review and query the log data was vital: We did not want to simply‘check the boxes’when it came to complying with audit standards.” The Solution Following a thorough analysis of security-monitoring solutions, Faysal Bank Ltd. selected NetIQ® Sentinel™ Log Manager and worked with NDS, a NetIQ partner, to deploy the solution. “The NetIQ solution met almost all of our log-monitoring requirements and was considerably less costly than the alternatives,”said Zahir Ali Quettawalla. Faysal Bank Ltd. is now monitoring logs for almost all of its critical systems and user IDs, and is working to develop reports and alerts that will further improve visibility and simplify compliance. “NetIQ Sentinel Log Manager is a very comprehensive tool, but it’s not humanly possible to read every line of every log,”said Zahir Ali Quettawalla.“We are now working with NDS to create consolidated reports and we are planning to flag up suspicious activity using alerts sent directly to BlackBerry devices.”
  • 2. Worldwide Headquarters 1233 West Loop South, Suite 810 Houston, Texas 77027 USA Worldwide: +1 713.548.1700 U.S. / Canada Toll Free: 888.323.6768 info@netiq.com www.netiq.com http://community.netiq.com For a complete list of our offices in North America, Europe, the Middle East, Africa, Asia-Pacific and Latin America, please visit www.netiq.com/contacts. Follow us: Comprehensive reports enable IT management to see at a glance how and when users are using administrator IDs. The reports include the time and location of access, and detailed information on what commands users are running with administrative privileges. “With the NetIQ solution, we have a complete record of user-generated queries, which gives a very good idea of what users are actually doing on each database: which tables they have accessed, which fields they have changed, which values they have updated,”said Zahir Ali Quettawalla. With the log-monitoring solution in place, Faysal Bank is now embarking on a second phase. “We have a system where users can request access rights,”said Zahir Ali Quettawalla.“An automated workflow ensures approval by their line manager, but there’s no easy way to check that the requested access really fits that person’s role. We are planning to deploy Identity Manager from NetIQ to provide full control over roles and access rights.” The Results A Clear View with Minimal Impact Thanks to NetIQ Sentinel Log Manager, Faysal Bank Ltd. now has a clear view of administrator activity across its most important databases. “Administrators understand that they are now being monitored by the NetIQ solution, and that any out-of-the- ordinary activities, whether accidental or deliberate, will be permanently visible,”said Zahir Ali Quettawalla. Business managers previously had concerns about setting up logs on critical systems for fear of impacting performance. NetIQ Sentinel Log Manager captures logs in real time and with zero performance impact. Likewise, the solution has minimal impact on the IT team’s workload, enabling full monitoring and sophisticated reporting at the touch of a button. Bringing Risk under Control The ability to monitor and report on comprehensive administrator- activity logs is of great value in demonstrating proper IT governance. “The business risk associated with administrative access to databases is now under control, thanks to NetIQ Sentinel Log Manager,”said Zahir Ali Quettawalla.“We can set up real-time alerts for defined security events, and we also have a full evidence trail for all historical activities.” Learn more today by contacting your NetIQ partner or a local NetIQ sales representative, or by visiting www.netiq.com for contact information in your area. “The business risk associated with administrative access to databases is now under control, thanks to NetIQ Sentinel Log Manager.” Zahir Ali Quettawalla, Head IT Security Risk Management (ITSRM), Faysal Bank Limited (Pakistan) NetIQ, the NetIQ logo, and Sentinel Log Manager are trademarks or registered trademarks of NetIQ Corporation in the USA. All other company and product names may be trademarks of their respective companies. © 2012 NetIQ Corporation and its affiliates. All Rights Reserved. CSS90064FBU ST 11/12