EnVision Platform Sales Guide - Lightspeed Pub

Transcription

RSA enVision PlatformSales Guide

RSA enVision Platform Sales GuideLegendBusiness DriversContentsIntroduction4 anaging Security, Enhancing Compliance:Mthe RSA enVision Platform SolutionIdentifying CustomersDiscovery QuestionsPositioning StatementsPresentation of SolutionObjection HandlingHow to QuoteThe Channel AdvantageBusiness Drivers7Meeting Business Needs8RSA enVision Platform Solution Overview9Benefits of the RSA enVision Platform10Identifying Customers12Discovery Questions14Positioning Statement16Attaching and Follow-up Opportunities17Presentation of Solution18Objection Handling20FAQs21ES-1060 Demonstration Appliances22How to Quote RSA enVision23Competitive Analysis27Appendix A: Useful Resources29Presentation Materials29RSA SecurWorld Partner Locator29RSA Secured Solutions Directory and Implementation Guides29RSA Online30RSA SecurCare Online30 ContactsOther guides in this series include:Building Success with the RSA SecureWorld Partner Program, the RSA Security Value Proposition,the RSA SecurID Authentication Sales Guide, the RSA SecureID for Microsoft Windows, VPNs, Wireless andCitrix Sales Guides, the RSA SecurID Appliance Sales Guide andthe RSA SecurID Competitive Sales Strategies.25631Americas Headquarters31Corporate Headquarters31International Headquarters31Local Offices31RSA Security Distributors313

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuideIntroductionThe RSA enVision Platform Sales Guide, part of The Essential Guide series, deliverspractical, real-world sales advice about this compliance and security informationmanagement solution. This guide helps you to identify customer requirements, topresent the RSA enVision platform solution to customers effectively and to close deals.The resources in these pages provide sales personnel with current information onRSA enVision platform components and competing products in the market. The topicsprogress through a typical sales cycle, including a product overview, market drivers,product positioning, discovery questions, objection handling, price quoting andcommon questions. This guide gives salespeople the information and tools to createopportunities and generate greater revenues.Managing Security, Enhancing Compliance: the RSA enVision Platform SolutionIncreasingly complex network infrastructures and a growing body of regulatory mandates posedual challenges for enterprises striving to manage security and ensure compliance. Thousandsor tens of thousands of events occurring across an organization’s networks every second maybe logged using traditional network management tools, but unless this raw data is analyzedand converted into actionable intelligence, security risks may go undetected and regulatorycompliance requirements may not be adequately met.The RSA enVision platform provides a comprehensive information management frameworkfor compliance and security. It directly addresses the need to log network events and producemeaningful intelligence from this data. In doing so, the RSA enVision platform improves theefficiency of IT departments, strengthens the ability of security personnel to recognize andrespond to internal and external data security threats and helps ensure compliance with stateand federal regulations and industry standards that mandate accountability. The RSA enVisionplatform is the only information management platform for comprehensive and efficienttransformation of event data into actionable compliance and security intelligence. The solutionis deployed as a standard server and storage solution to collect logs from network devices,servers, applications and storage devices. Adding additional appliances in response to a risein data traffic or expansion of the network infrastructure can be accomplished simply andefficiently.Increases in data traffic—an inevitable byproduct of businesses relying more and more onthe Internet for operations—add to the difficulty of managing and contending with growingvolumes of files and ensuring that sensitive data is safeguarded. The platform approach tolog management, used by this solution, scales effectively to more demanding enterpriserequirements—even when those requirements entail managing massive volumes of data andtransactions. Adopted by many of the world’s leading enterprises, the RSA enVision platformprovides value far beyond simply capturing and logging raw data. By effectively leveragingnetwork data, extracting intelligence and useful information from data patterns and events, theRSA enVision platform addresses security, compliance and business operation challenges—thereby providing a comprehensive compliance and security information management lifecyclesolution.45

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuideThe Channel AdvantageBusiness DriversRSA Security helps ensure that, as a channel partner, you can satisfy your customers’requirements through successful planning and implementation. Customers deploying thissolution across their organization can quickly maximize their ROI and improve the productivityand efficiency of business processes.The RSA enVision platform effectively addresses a number of challenges that impact businessaround the world. The key drivers include:Partners can achieve maximum success selling RSA enVision platform components byleveraging the following factors:HH Because the solution focuses on enterprise requirements, sales typically lead to largerrevenues as organizational needs grow and networks expand.HH The complete solution often leads to complementary product sales of additional RSASecurity products.HH The solution provides abundant opportunities for strategic planning and deploymentservices.HH Growing Network Complexity: Logging events and monitoring activities on the sprawling,high-volume networks that characterize modern organizations places a large burden onIT staff members and in-house security professionals. Piecemeal solutions and end-pointapproaches fail to address the scope of the problem or provide an effective resolution fortracking, logging and extracting intelligence from a vast sea of data activity. Administrativeand IT budgets required to counter this challenge are rising and many organizationsare feeling overwhelmed as they struggle to contend with threat management whileconcurrently monitoring network activities for security policy compliance.HH Heightened Network Security Concerns: As organizations increasingly rely on the Internet,web services, and mobility applications for conducting daily business operations, therisk vectors for data theft and fraudulent activity rise in concert with the sophisticationof computer hacking techniques. Given the expanding infrastructure risks, businessesand organizations need tools to keep business operations secure. Risks can be mitigatedby monitoring potentially threatening user accesses and activities, detecting baselineanomalies and issuing appropriate alerts, and keeping track of real-time events across theuniverse of device types in use within the organization.HH Regulatory Mandates: In the current climate of privacy concerns and regulationshighlighting accountability and data protection, achieving compliance with regulatorymandates is a vital concern of businesses everywhere. Penalties for failing to protect anindividual’s personal data or failing to verify and authenticate users accessing sensitivenetwork data can result in steep fines or even the imprisonment of corporate officers. Anumber of recent regulations and industry standards adopted in the U.S. and around theworld (including HIPAA, Sarbanes-Oxley, EU Data Protection Directive and Gramm-LeachBliley) aim toward improving user authentication, protecting data access and maintainingclear audit trails. Because of these regulatory requirements, many organizations arere-assessing the end-to-end security of their infrastructure and considering enterprisecaliber solutions.This solution targets log management, security operations and regulatory compliance issues,giving businesses a strong, scalable tool for improving business operations and strengtheningtheir security. The following section highlights the ways in which this solution meets vitalbusiness needs.67

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuideMeeting Business NeedsRSA enVision Platform Solution OverviewThe RSA enVision platform addresses primary business needs in the following ways:The RSA enVision platform collects and manages All the Data across an organization’snetwork resources, delivering practical, intelligent analysis of events for enterprise logmanagement, compliance and security. As an appliance-based solution, the RSA enVisionPlatform offers an effective alternative to software, eliminating hidden costs in pricing models,simplifying deployment and providing consistent, predictable performance and results.HH Centralizes and streamlines data logging and management: The demands on ITdepartments and requisite budgets can be significantly reduced through the capabilities ofthe RSA enVision platform, providing greater visibility into business operations, compliantfriendly tracking of individual network activities and analytical tools that can be configuredto generate alerts when potential security breaches or illicit network activities are detected.Integration with other RSA products, such as RSA SecurID, helps create an intelligentframework to protect data assets and network resources.HH Strengthens data security by identifying potential threats: The security event managementfeatures of the RSA enVision platform help security staff members identify and respondto developing risks involving network access and file movements. Through the solutionfeatures that support the generation of actionable intelligence based on tracked andcorrelated security events, RSA enVision improves the efficiency and effectiveness ofsecurity practices.HH Provides reporting and analysis tools to help meet regulatory requirements: Securityinformation management features of RSA enVision are ideally suited for organizations ofall sizes, including large organizations with sizable networks. The information managementand data retention features aid in complying with reporting requirements mandated by SOX,GLBA, PCI and other current legislation. By providing extensive, system-wide recording andtracking of data events and transforming this data into a form that simplifies regulatorycompliance, organizations can avoid fines and penalties while ensuring data integrity forcustomers, vendors, and stakeholders.89

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuideBenefits of the RSA enVision PlatformThe RSA enVision solution offers these advantages to organizations:The RSA enVision platform solution consists of these elements:HH Exceptional scalability : the open architecture and modular hardware components of theRSA enVision platform achieve a very high level of scalability, capturing thousands of dataevents per second. The scalability of the solution allows even the largest enterprises tosuccessfully capture, monitor and analyze data in a consistent, predictable way.HH RSA enVison platform appliance: Each RSA enVision platform appliance is a controlledsecure environment, featuring a locked-down and hardened version of the MicrosoftWindows operating system and the enVision software application pre-installed. Thiscontrolled environment ensures that the usual threats to system operation—including bugs,viruses, and worms—are effectively eliminated, ensuring safe, reliable performance. Severaldifferent models of the RSA enVision platform appliance allow organizations to select thelevel of equipment corresponding with the number of devices and the volume of data eventsto be captured and processed in real-time.HH Favorable Return on Investment: By avoiding the hidden costs of software-only solutions(additional hardware investments, management expenses, storage costs and so on), theRSA enVision platform delivers strong business value and a rapid Return on Investment(ROI).HH Fast deployment: The appliance-based RSA enVision platform solution can be attachedto the network and configured in a very short period of time, typically in the range of twohours. Software-based solutions set up for a similar appliance may take anywhere from aday to a week to become fully operational.HH Industry-leading reliability: The controlled, secure environments represented by the RSAenVision platform appliances, running a hardened and locked version of Microsoft Windows,deliver a very high degree of reliability. Appliances are immune to third-party driver conflicts,bugs, worms, viruses and similar threats to data integrity and consistent operation.HH Unique IP-based database advantages: To rapidly capture and analyze IP-based data andinformation, the solution relies on an innovative database approach: Internet ProtocolDatabase (IPDB). IPDB provides unique data advantages and storage benefits that unlockmany of the capabilities of this solution for real-time operations.Many RSA Security and EMC products work together effectively so that customers candeploy complete solutions that encompass all of their security, network management,information management and compliance requirements. For example, the RSA enVisionplatform complements RSA SecurID technology to give partners the opportunity to strengthencompliance and network management with the proven benefits of two-factor authentication.This solution also complements EMC’s vision for information-centric security and is integratedwith EMC Celerra, CLARiiON, Symmetrix and Centera.10HH Internet Protocol Database: The innovative, patent-pending RSA Internet Protocol Database(IPDB) is tailored to efficiently collect and protect All the Data from any IP device on thenetwork. This database lets customers construct a robust log management platform with theability to monitor and correlate high volumes of data events and extract intelligence throughsophisticated analytics. Storage requirements for data collected are minimized throughcompression techniques and performance is enhanced through a unique approach thatworks efficiently with unstructured data formats.HH Built-in tools: The built-in tools and features of the RSA enVision platform provide theflexibility to collect, analyze and view data in numerous ways and to configure behaviorsto suit the security and compliance requirements of many different types of organizations.Among the tools and features included: advanced vulnerability and asset managementfeatures, task triage and ticketing system integration, watchlist alerting and reporting, eventexplorer and extensive features for maximizing availability.RSA is a market-proven leader in transforming enterprise-wide data into compliance andsecurity information. The RSA enVision platform is built on an architecture equal to thedemands of high-traffic network operations, collecting and protecting All the Data that driveseach customer’s business.11

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuideIdentifying CustomersThe RSA enVision platform solution suits deployments in mid-size to large organizations, aswell as global enterprises where extremely high data traffic on the network is typical. Primaryindustries include:HH Financial servicesHH Outsourcers and managed service providersHH Retail and hospitality servicesHH Healthcare industryKey indicators that an organization can effectively take advantage of the RSA enVision platformare:HH No unified system in place for monitoring and analyzing network events: Organizationsthat lack a centralized, unified means for collecting and analyzing network data events riskpotential security breaches—internal as well as external—and often devote excessive timeto trying to interpret and make decisions on uncorrelated data collected by non-intelligentlogging tools. Streamlining data collection and extracting key intelligence from it can greatlysimply business operations, strengthen security and reduce IT costs.Organizations that are concerned with security and information management—for improvedprotection of data resources, regulatory compliance, and enhanced business operations—generally respond favorably to the features and capabilities of the RSA enVision platform.HH Existing network logging tools do not adequately meet regulatory mandates: Morestringent regulations involving accountability, authentication and auditing of networkactivities have emerged in recent months, creating a need for companies to reassess theeffectiveness of their existing piecemeal or less comprehensive solutions to logging andmonitoring. Raw information may be collected, but often the intelligence component islacking, making it difficult to view or evaluate the data, or to present it in a way that meetsmandatory requirements.Strongly regulated industries—such as finance, government, pharmaceutical, andhealthcare—face substantial regulatory mandates and compliance requirements, which can bemet with a properly deployed RSA enVision platform solution.HH Costs of IT administration: Inefficient, non-centralized approaches to security informationand event management (SIEM) can drive up the costs of IT administration, requiring manualintervention for many processes that should be automated.HH Energy and utility industryHH Public sector and non-governmental organizationsTypical prospects for the RSA enVision platform have these characteristics:HH A wide range of computing device types accessing network resourcesHH Large volumes of critical applications and sensitive data in useHH Complex network infrastructures requiring substantial IT managementHH Stringent compliance requirements at state, federal and international levelsIncreasingly, organizations are recognizing the importance of managing compliance andsecurity event log data more effectively—from the time the event data are generated to thetime it no longer needs to be retained (according to regulatory guidelines).1213

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuideDiscovery QuestionsThe RSA enVision platform is well suited to organizations of all sizes, but it is ideal for amedium to large enterprise sale. You can effectively focus a sales engagement by addressingthe security and compliance functions and asking basic qualifying questions. Inquiring abouta customer’s current environment and existing security and compliance strategies is oftena good place to start the discussion. Ideally, you can lead the discussion toward the goal ofselling a combined solution that addresses the security and compliance needs of multiplestakeholders in the organization and that includes development and implementation services,the core product and an appropriate EMC storage platform.The following questions focus on concerns of the typical manager:Given your current capacity and existing configuration for storing security information,for how long a period can you retain the data?What do you estimate it costs your IT group each year to log and manage data events?What systems are in place to monitor access control, privileged users and configurationcontrols?Potential decision makers for the RSA enVision solution typically fit into three categories:HH Executives: Have considerable influence; concerned with shareholder values, revenueissues and regulatory compliance.HH Managers: Have influence over budget and project implementations; concerned withcustomer relationships, cost controls and business objectives.HH Operations personnel: Focused primarily on implementation strategies, resources andtechnology issues.Do you feel that your company’s critical applications and data are sufficiently protectedagainst external threats?Can you analyze all of the data logged in real-time and apply it to forensic situations?For operations personnel, these questions may help determine a fit:How will your organization create a compliance program in a cost-effective manner?Selling effectively to these three categories of buyers requires asking questions to highlightthe individual’s concerns and offering solutions in terms that address the challenges faced bythe organization. Focus the discussion on the key motivations identified for each buyer.Are their multiple departments or groups collecting security audit information? Doadditional groups have a need to collect this information?Effective questioning strategies target each individual’s most important concerns. For example,when talking with an executive, the following questions can help lead the sales discussion:When a security threat is identified, are you able to cross-reference it with the rest ofthe network?Have you found a satisfactory way to monitor and track network data events acrossyour infrastructure for compliance and security?How do you keep up with real-time monitoring, threat detection and malicious codedetection without being overwhelmed by false positives?Are your network data resources protected against emerging security threatsAre you able to add proprietary applications to extend the collection of source devicesin use on the network?Are your security investments working? Can you easily prove it?Do you need to make your compliance reporting more effective while consuming fewerresources?Do you have a compliance initiative in effect that mandates improved accountabilityand data retention?14Do you need to produce frequent compliance reports or reports for many differentaudiences?Using these sample questions to stimulate discussions with potential buyers—based on theirdemonstrated concerns—helps discover the underlying business needs and buyer motivations.This, in turn, can suggest the most compelling points to focus the sales presentation.15

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuidePositioning StatementAttaching and Follow-up OpportunitiesFaced with increasingly complex network environments, emerging data security threatsand stringent compliance requirements, many organizations are turning to comprehensiveinformation lifecycle management solutions, looking for tools that support best practicesfor security information and event management. Given the complexities of planning andimplementing solutions in this area, appliance-based solutions designed around an openarchitecture model have significant advantages in terms of cost, reliability, scalability andinstallation.Properly trained partners and RSA can offer customers additional services to accompany theproduct sale of RSA enVision platform components, including:HH The RSA enVision platform offers clear advantages in a number of areas, providing SIEMcapabilities that directly address key customer requirements. Presented as part of a solutionsales approach, this platform:HH Provides a scalable log management platform that enables compliance and security, anddelivers business intelligence to enhance operationsHH Offers a comprehensive, open-architecture approach to SIEM that integrates effectively withexisting network equipment and supports high-volume data environmentsHH Expands the value of data on the network, analyzing All the Data to support a rich,information-centric security strategyIn this context, the RSA enVision platform helps customers eliminate redundant silos ofinformation and create a unified framework that spans the enterprise, turning raw data intoactionable intelligence.HH Universal Device DevelopmentHH Sure StartHH Report and Alert DeveloperHH Compliance Assessment and EnablementHH Security Assessment and EnablementAs part of an overall network security strategy, and to strengthen the compliance and securityaspects of network access and use, other complementary products offering some opportunityfor the additional sales include:HH Addition of RSA SecurID: Authentication is a prime aspect of compliance regulations, aswell as a best-practice approach to network security. RSA SecurID provides industry-leadingtwo-factor authentication for compliance and improved security.HH Addition of Use of a Certificate Authority: Customers using certificate authorities, such asRSA Digital Certificate Solutions, have an ongoing need for the protection of certificates andkeys. RSA Smart Cards and RSA USB Authenticators ensure protection of each user’s privatekeys.HH RSA SecurID Tokens: Customers looking for tighter security than passwords can provide willbe interested in using multi-factor authentication. For new customers this will lead to salesof RSA SecurID tokens and software licenses. For existing RSA customers, it may mean anexpansion of the number of tokens in use.This RSA enVision solution provides a proven framework for strengthening enterprise securityand ensuring compliance. Your customers can also leverage existing RSA Security investments,such as RSA SecurID tokens or RSA Keon digital certificates, combining a comprehensiverange of security tools within an framework.1617

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuidePresentation of SolutionThe RSA enVision platform is built around a solid framework of information managementcapabilities—recognizing that transforming event data into actionable compliance and securityintelligence is a fundamental necessity for modern businesses and large-scale organizations.With proven performance, exceptional scalability, an innovative database tuned for handlingIP-generated data and best-in-class analytical tools, the RSA enVision platform equipscompanies for success in compliance and security operations. The RSA enVision platformresponds to the need for security and compliance intelligence at a system level and providesgreater overall return on investment. For these reasons, RSA enVision platform technologyleads the industry in effective, proven SIEM solutions and has been successfully deployedin hundreds of organizations worldwide. Figure 1 illustrates the platform capabilities for thissolution.Solution: RSA enVisionAn Information Management Platform for Compliance & Security Operations4FSWFS&OHJOFFSJOH#VTJOFTT 0QT-PH .BOBHFNFOU PNQMJBODF "VEJU"TTFU *EFOUJGJDBUJPO3JTL .BOBHFNFOU#BTFMJOF3FQPSU PNQMJBODF 0QFSBUJPOT4FDVSJUZ 0QT"MFSU PSSFMBUJPO%FTLUPQ 0QT/FUXPSL 0QT'PSFOTJDTAs a full-featured, scalable, enterprise-class solution, the business value of RSA enVision isrealized in large-scale deployments—where data event logging typically reaches thousands totens of thousand of events per second. However, with the selection of the appropriate enVisionappliance, this solution can be cost effective in much smaller deployments where eventoccurrences range from the tens to the hundreds of instances per second.Industries that have particularly strict regulatory compliance concerns—such as the insurance,financial, and government sectors—can rely on integration with RSA SecurID to ensure aneven more comprehensive security solution. Complete solutions in the security realm shouldencompass access and transaction control throughout the organization’s infrastructure, as wellas ensuring a clear audit trail and definitive logging of all event activity.The RSA enVision platform fits well in environments where customers have a strong need tocentralize and unify logging and information management activities in response to a desirefor improved security, more efficient operations through greater data visibility, and enhancedregulatory compliance."QQMJDBUJPO %BUBCBTF*ODJEFOU .BOBHFNFOU4FDVSJUZ 0QFSBUJPOT"DDFTT POUSPM POGJHVSBUJPO POUSPM.BMJDJPVT 4PGUXBSF1PMJDZ &OGPSDFNFOUT6TFS .POJUPSJOH .BOBHFNFOU&OWJSPONFOUBM 5SBOTNJTTJPO 4FDVSJUZ"DDFTT POUSPM &OGPSDFNFOU4-" PNQMJBODF .POJUPSJOH'BMTF 1PTJUJWF 3FEVDUJPO3FBM UJNF .POJUPSJOH6OBVUIPSJ[FE /FUXPSL 4FSWJDF %FUFDUJPO.PSF "-- 5)& %"5"-PH .BOBHFNFOU"OZ FOUFSQSJTF *1 EFWJDF 6OJWFSTBM %FWJDF 4VQQPSU 6%4/P GJMUFSJOH OPSNBMJ[JOH PS EBUB SFEVDUJPO4FDVSJUZ FWFOUT PQFSBUJPOBM JOGPSNBUJPO/P BHFOUT SFRVJSFE1819

RSA enVision Platform Sales GuideRSA enVision Platform Sales GuideObjection HandlingFAQsThe following are typical objections you might encounter while attempting to sell the RSAenVision platform. Responses to these objections are included to help you keep the prospectin your sales pipeline and close the deal.Does the RSA enVision platform integrate easily with storage systems from other vendors?We have dedicated teams in place that perform monitoring, reporting, and similaranalytical activities.The RSA enVision platform is a robust enterprise system that can make these activities moreefficient, more responsive, and less resource-intensive. Better configuration management canalso enhance your ability to meet regulatory compliance mandates.We don’t need a system like this.Changing regulatory frameworks and increased incidents of data security breaches andnetwork intrusions make it essential for every enterprise to have a security strategy thatincludes comprehensive real-time monitoring, intelligent logging and verifiable compliancemanagement.We already have a system that collects and correlates events from our network devices.Event management and real-time alerting are basic features of many similar solutions, but theRSA enVision platform puts greater emphasis on compliance reporting capabilities, as well asproviding sophisticated real-time and forensic tools for analyzing and responding to loggedevent data.A platform like this will be too expensive for our organization.20The solution provides integration with NAS systems from Network Appliance (NetApp), as wellas full integration with DAS- and NAS-based EMC storage systems, such as CLARiiON, Celerra,Symmetrix (with the Celerra Gateway) and Centera. EMC offers the Design and Implementationfor Security Information Management service to help organizations configure the RSA enVisionplatform with EMC storage systems.Do agents have to be installed for use with enVision?The unique architecture and data collection techniques e

The RSA enVision platform addresses primary business needs in the following ways: H Centralizes and streamlines data logging and management: The demands on IT departments and requisite budgets can be significantly reduced through the capabilities of the RSA enVision platform, providing greater visibility into business operations, compliant-