This website uses cookies. By clicking OK, you consent to the use of cookies. Click Here to learn more about how we use cookies.
OK
  • RSA.com
  • Products
    • Archer®
      • Archer®
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Archer® Exchange
      • Training
      • Upcoming Events
      • Videos
    • RSA® Fraud & Risk Intelligence Suite
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Web Threat Detection
      • Upcoming Events
      • Videos
    • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Cloud
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Patch Content
      • Videos
    • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication Mobile SDK
      • Advisories
      • Events
      • Ideas
      • Knowledge Base
      • Request Access
      • Training
    • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 7.x
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Events
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® Adaptive Authentication for eCommerce
      • RSA® Adaptive Authentication for eCommerce
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Ideas
      • Knowledge Base
      • Training
      • Videos
    • RSA® FraudAction Services
      • RSA® FraudAction Services
      • Advisories
      • Discussions
      • Documentation
      • Ideas
      • Videos
    • RSA® Web Threat Detection
      • RSA® Web Threat Detection
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Videos
    • RSA NetWitness® Platform
      • RSA NetWitness® Platform
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA NetWitness® Detect AI
      • RSA NetWitness® Detect AI
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Investigator
      • RSA NetWitness® Investigator
      • Documentation
      • Download the Client
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA NetWitness® Orchestrator
      • RSA NetWitness® Orchestrator
      • Overview
      • Documentation
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
    • RSA SecurID® Suite
      • RSA SecurID® Suite
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Knowledge Base
      • Ideas
      • Integrations
      • Training
      • Videos
    • RSA® Identity Governance & Lifecycle
      • RSA® Identity Governance & Lifecycle
      • Advisories
      • Blog
      • Community Exchange
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • RSA SecurID® Access
      • RSA SecurID® Access
      • Advisories
      • Blog
      • Discussions
      • Documentation
      • Downloads
      • Ideas
      • Integrations
      • Knowledge Base
      • Training
      • Upcoming Events
      • Videos
    • Other RSA® Products
      • Other RSA® Products
      • RSA® Access Manager
      • RSA® Data Loss Prevention
      • RSA® Digital Certificate Solutions
      • RSA enVision®
      • RSA® Federated Identity Manager
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
      •  
  • Resources
    • Advisories
      • Product Advisories on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Hosted
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Product Advisories
    • Blogs
      • Blogs on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Blogs on RSA Link
    • Discussion Forums
      • Discussion Forums
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Discussion Forums on RSA Link
    • Documentation
      • Product Documentation
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Downloads
      • Product Downloads
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Downloads on RSA Link
    • Ideas
      • Idea Exchange
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® FraudAction Services
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Documentation on RSA Link
    • Knowledge Base
      • Knowledge Base
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication Mobile SDK
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Knowledge Base Pages on RSA Link
    • Upcoming Events on RSA Link
      • Upcoming Events
    • Videos
      • Videos on RSA Link
      • Archer®
      • RSA® Adaptive Authentication Cloud
      • RSA® Adaptive Authentication On-Premise 7.x
      • RSA® Adaptive Authentication On-Premise 14.x
      • RSA® Adaptive Authentication for eCommerce
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
      • RSA® Web Threat Detection
      • All Videos on RSA Link
  • Support
    • RSA Link Support
      • RSA Link Support
      • News & Announcements
      • Getting Started
      • Support Forum
      • Support Knowledge Base
      • Ideas & Suggestions
    • RSA Product Support
      • RSA Product Support
      • General Security Advisories and Statements
      • Product Life Cycle
      • Support Information
      •  
      •  
      •  
      •  
      •  
  • RSA Ready
  • RSA University
    • Certification Program
      • Certification Program
    • Course Catalogs
      • Course Catalogs
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • On-Demand Subscriptions
      • On-Demand Subscriptions
      • Archer®
      • RSA NetWitness® Platform
      • RSA SecurID® Suite
    • Product Training
      • Product Training
      • Archer®
      • RSA® Fraud & Risk Intelligence Suite
      • RSA® Identity Governance & Lifecycle
      • RSA NetWitness® Platform
      • RSA SecurID® Access
    • Student Resources
      • Student Resources
      • Access On-Demand Learning
      • Access Virtual Labs
      • Contact RSA University
      • Enrollments & Transcripts
      • Frequently Asked Questions
      • Getting Started
      • Learning Modalities
      • Payments & Cancellations
      • Private Training
      • Training Center Locations
      • Training Credits
      • YouTube Channel
    • Upcoming Events
      • Upcoming Events
      • Full Calendar
      • Conferences
      • Live Classroom Training
      • Live Virtual Classroom Training
      • Webinars
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
Announcements

RSA SecurID® Access Blog

Subscribe to the official SecurID Access blog for information about new product features, industry insights, best practices, and more.
  • RSA Link
  • :
  • Products
  • :
  • RSA SecurID Suite
  • :
  • RSA SecurID Access
  • :
  • Blogs
  • :
  • Defense-in-Depth: RSA SecurID® Access in November ...

Defense-in-Depth: RSA SecurID® Access in November 2020

NandiniV
Contributor NandiniV Contributor
Contributor
0 0 870
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
‎2020-12-08 02:04 AM

We understand the challenges of our customers in the federal and public sector space who are making strategic investments to securely manage their IT infrastructure and planning to migrate to the cloud. While the scope of various regulatory frameworks (FedRAMP, FISMA, DISA STIGs) may or may not  be relevant to your organization, the benefit of “Do once, apply many times” goes beyond any specific compliance. Commercial customers gain a lot from the IT vendors who comply with the security standards and best practices, as this also increases the trust of your customers. With the additional insights and transparency, enterprises can improve the information security strategy of their overall IT programs.

RSA continues to reduce your compliance burden by always staying on top of the security best practices. Our continuous platform upgrades and improvements ensure customers are kept safe from security holes and vulnerabilities. With the latest release of Cloud, Mobile and Identity Router, we are excited to bring these updates that are layered across RSA SecurID Access to provide outstanding protection for your data and information.

 

FIPS 140-2 Update - Why Is It Important?

We are living in the era of zettabytes, where the data is growing at a mind-boggling rate. Given the proliferation of digital data, protecting data from being exposed to potential attacks is crucial. This requires the continuous update of cryptographic modules. Federal Information Processing Standard (FIPS) 140-2 standardizes the cryptographic requirements to manage data at rest (storage), as well as data in motion (transmission).

FIPS 140-2 plays an important role outside government as well. For example, healthcare organizations have a mandatory requirement of using FIPS-validated MFA for EPCS (Electronic Prescription of Controlled Substances) systems. The military uses it to be compliant with DFARS (Defense Federal Acquisition Regulation Supplement) to protect data at rest. It is also critical for fintech organizations to leverage reliable and standard cryptographic-based tools and systems.

RSA SecurID Access continues to leverage FIPS 140-2 validated cryptography modules to constantly align our various components - Cloud Authentication Service, Identity Router and RSA SecurID Authenticate app (Android, iOS and Windows) to achieve compliance on any given day. So you can march confidently towards meeting your compliance needs where FIPS 140-2 compliance is a non-negotiable item.

 

Identity Router Release - What’s Special About It?

We continue to make investments in building the most secure identity infrastructure so that we have your complete trust in enabling your business. Be it getting rid of outdated operating systems, upgrading the crypto libraries (as part our comprehensive security regimes) or making configuration changes to be compliant with the latest guidelines that created buzz yesterday, we want to have it all covered. To achieve this goal, regular upgrade cycles are necessary. With the release of Identity Router, we are excited that our customers will benefit from these additional security enhancements including those with the compliance mandates.

  •  A layer of defense: By adhering to Security Technical Implementation Guide (STIG), November release of Identity Router image adds yet another layer to meet the compliance requirements elicited by DISA, the Defense Information System Agency, part of the US Department of Defense (DoD). This ensures the operating system, network infrastructure and other computing systems are hardened to operate in the federal infrastructure.
  • Beyond Compliance: Following security benchmarks, whether you are in federal government or not, helps in maintaining the overall security posture of your IT infrastructure. STIGs play a critical role in ensuring the systems are configured as securely as possible (rather than going by the “default settings”) to prevent them from being an easy target for cyber attacks. Security vulnerabilities can be costly and frustrating for commercial organizations as well.
  • Keeping Current: Running an outdated operating system or application software in production is like a ticking time bomb. These could put your network infrastructure and business at risk even before the auditors raise them as red flags. With the SLES 12 SP5 upgrade, we want to ensure our customers are always on the latest and greatest of the software and keep your IT teams and auditors happy.

Other Updates

Admin Console - Security Beyond MFA

To further tighten the security, the administrator console of RSA SecurID Access Cloud Authentication Service now has additional access control measures baked in as part of the account and access management. These additional controls enforce stricter policies such as - session lockout interval, unsuccessful login attempts and password complexity as part of authentication. With the risk of cyber attacks, any such additional measures to prevent hackers gaining access to critical resources and accounts goes a long way.

Usage Reporting - The More Data The Merrier

Usage reporting of Cloud Authentication Service is enhanced to include additional usage metric data Active Users. If you are an administrator, you probably know the existing usage metrics that are made available through our Cloud Administration Retrieve License Usage API.  The existing usage reports already show MFA licenses count, users with FIDO authenticator and SMS/Voice data; the new report metric shows the number of unique users successfully authenticated by Cloud Authentication Service for MFA. Besides addressing compliance needs, this report will also come in handy for planning for the future.  You can use this data for effective budgeting and capacity planning as part of your MFA deployment strategy.  

 

To learn about additional November 2020 updates, see November Release Notes. 

 

Flexible Access Policy Assignment to Reduce Administrative Overhead

Some applications, such as SSO applications, may need to invoke a specific authentication policy in RSA SecurID Access based on a condition (for example, the user group and/or resource being accessed). SAML-based applications can use the AuthnContext SAML attribute to do just this. But some SSO platforms do not have this support and pose a challenge in complex customer environments. To overcome this limitation, we provide the flexibility to invoke a specific authentication policy based on specific conditions. As part of the SAML connector configuration, administrators can customize the Entity ID of an identity provider by adding a discriminator unique to a SAML-based service provider (SP). This enables you to use different access policies for different SAML-based applications to improve security and flexibility. To learn about additional features in September 2020, see September Release Notes. 

Authenticate to the Cloud Administration Console through a Third-Party Identity Provider

You can now securely sign into the Cloud Administration Console through federation by extending  your identity provider (IdP). This is useful in general but specifically becomes very handy for federal administrators who use  a common access card (CAC) and personal identity verification (PIV) and can continue to use their third-party IdP infrastructure to perform a federated sign-in to the Cloud Administration Console. We encourage you to test this feature in a development environment to make sure everything works before moving into production. To learn about additional features in September 2020, see September Release Notes. 

Tags (9)
  • Tags:
  • Cloud Authentication Service
  • fedramp
  • fips 140
  • fips compliance
  • IDR
  • license reporting
  • RSA SecurID
  • RSA SecurID Access
  • SecurID
0 Likes
Share

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • Defense-in-Depth: RSA SecurID® Access in November ...
  • Protect Stormshield VPN with RSA MFA
  • Optimize your Dynamic Workforce with RSA SecurID A...
  • Securing access to corporate endpoints is made eas...
  • New RSA SecurID Access & Authentication Manager Tr...
  • What's New for RSA SecurID® Access in June 2020
  • Cake for All! Secure & Convenient Login for The Ne...
  • macOS® authentication with RSA SecurID Access
  • Where is my authentication framework? Does a free...
  • Reduce people & process overhead costs through a s...
Labels
  • Announcements 1
  • Resources 1
  • Tutorials 27
  • Use Cases 3
  • Videos 93
Powered by Khoros
  • Products
  • Resources
  • Solutions
  • RSA University
  • Support
  • RSA Labs
  • RSA Ready
  • About RSA Link
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
© 2021 RSA Security LLC or its affiliates.
All rights reserved.