Enterprise Digital Rights Management
What is the best IRM/DRM for 25-100 users on a self hosted server. Andrew Tannahill
Anonymous

Your answer depends on what you want to secure and what your budget is. There are some IRM solutions that are targeted at file servers, while some are targeted specifically at content management systems. I have to know which one you are aiming to secure to answer your question.

Also what is your budget?

Frost & Sullivan Recognizes Fasoo.com’s Outstanding Innovation in Crafting and Executing Its Competitive Strategy

The company is uniquely positioned as an independent vendor of pure Enterprise Digital Rights Management products

MOUNTAIN VIEW, Calif. - July 11, 2011 - Based on its recent analysis of the enterprise digital rights management (EDRM) market, Frost & Sullivan recognizes Fasoo.com, Inc. with the 2011 Global Frost & Sullivan Award for Competitive Strategy Innovation of the Year. Fasoo.com (Fasoo) has successfully retained its leadership in the Asia-Pacific (APAC) markets and is seeing steady improvement in its global market position based on its unique technology, ongoing R&D improvements, comprehensive product capability and effective use of competitive intelligence.

In the global EDRM market Fasoo competes with Microsoft that has the strength of its Windows Server and Office products, which are mainstay applications for enterprises worldwide. Fasoo’s technology approach is driven by security and practical considerations. By overriding an application’s memory space, it provides a strong approach to document protection that integrates smoothly with the end-user experience even for third party applications, where EDRM vendors do not have access to the program code.

“This is a difficult approach for several reasons, including risk of performance impact and the requirement of keeping pace with application and document format updates,” said Frost & Sullivan Research Analyst Avni Rambhia. “Fasoo has developed the technical strength and deployment process to execute it well.”

Another unique Fasoo’s strength is its ability to scale operations across large enterprises, which are often a patchwork of identity management and client application systems across various enterprises. Fasoo has strong experience in securing information on an enterprise-wide level for large, globally distributed companies. For example, its flagship installation for Samsung spans more than 160,000 internal users and more than one million total users worldwide. No competitor has installations on this scale.

Today, enterprises are shifting from deploying EDRM on a need-basis to employing it uniformly for all enterprise employees. Fasoo’s strategy of combining a highly interoperable product with custom services as needed has positioned it well to organically fulfill this growing demand. In contrast, competitors have tended to focus on formats or deployment environments within their core competency, and to rely on systems integrators or value added resellers to develop and deliver an overall solution for the enterprise.

Fasoo dominates the APAC markets, notably Japan and Korea, and is now expanding into major markets such as China in the East, and North America and Europe in the West, through a combination of strategic partnerships and organic growth. Fasoo is the only major player in the EDRM market who has remained a pure EDRM vendor. While acquisition by large corporations offers competitors the strength of better sales resources and a more established customer base, Fasoo is countering this in two ways. In the North American and European markets, it is joining efforts with established channel partners such as IKON Office Solutions, a wholly owned subsidiary of Ricoh Americas Corporation, and Toshiba America Business Solutions, Inc to reach customers and win market share. Second, Fasoo is being proactively sought out as a partner by leading data loss prevention (DLP) vendors who are trying to break into the APAC region.

“Fasoo effectively articulates shortcomings in competing offerings, while highlighting its own strengths in the context of customer pain points, to craft compelling sales messaging and marketing communication,” said Rambhia. “Its blue ocean strategy is to position the company as a pure EDRM vendor with the technology that is agnostic to asset management, server software and DLP systems, but which interoperates with all market leading applications and platforms and is scalable to meet the needs of large enterprises with global footprints.”

In recognition of its innovative competitive strategies, Frost & Sullivan is proud to recognize Fasoo with the Global Frost & Sullivan Award for Competitive Strategy Innovation of the Year in the EDRM market. Each year, Frost & Sullivan presents this award to the company that has demonstrated uniqueness of strategy, leveraging competitive intelligence to improve market position.

Frost & Sullivan’s Best Practices Awards recognize companies in a variety of regional and global markets for demonstrating outstanding achievement and superior performance in areas such as leadership, technological innovation, customer service and strategic product development. Industry analysts compare market participants and measure performance through in-depth interviews, analysis and extensive secondary research in order to identify best practices in the industry.

Source: Frost & Sullivan

Should Government Intervene In the Protection of Corporate IP?

Should government intervene in the protection of corporate IP? This is the thought provoking question that needs to be answered in light of the recent loss of corporate IP mainly to emerging economies like China? Is the government a stakeholder when IP is lost or stolen?

From a government perspective there are numerous issues that happen when a company looses its IP to a foreign competitor. To name a few an obvious impact on government is the loss of revenue in the form of taxes that can be directly or indirectly linked to that IP. Another impact for government is the unemployment benefits that have to be paid as a result of loss in revenue.

In the UK small businesses form almost 80% of the economy and a considerable number gain their competitive edge through intellectual property rights and trade secrets. Considering the impact these businesses have on the economy as a whole, tax breaks should be given to these businesses to enable them invest in protecting their IP and trade secrets, as well as setting aside funds for any legal challenges.

Such tax breaks are bound to yield a return for the government in terms of safeguarding jobs and increased tax revenues, overall it is a win win for all involved. The competition coming from the far east is a reality that is quickly catching up with the western economies, and the protection of IP and trade secrets is of great concern to governments in the west.

In the recent visit of the Chinese premier to the United States, the protection of IP was one of the key agenda items that was discussed. Nevertheless, the governments in North America and Western Europe need to be seen to play an active role and continue dialogue with various industries on the best way forward to achieve IP and trade secrets protection.

When network security is not enough

You may be in control of all within the perimeter of corporate security, but when data leaves that safe haven, information rights management is essential, argues security partner of Deloitte, Paul Boichat.

Controlling access to the most sensitive information and data in an organisation is an age-old problem with a trusted technical solution, but is it fit for purpose in today’s environment.

Click here to access the remaining article……..

Controlling Confidentiality

Cara Garretson has written an interesting article in the State Tech Magazine on using Enterprise Rights Management tools to help government agencies protect their most sensitive documents.

Cara puts forward a solid case why agencies should adopt Enterprise Rights Management. I believe that 2011 would see the highest rate of adoption for Enterprise Rights Management, as WikiLeaks remains centre stage and many emerging nations turn a blind eye to intellectual-property theft.

To read Cara’s article in the State Tech Magazine click here.

China: The Intellectual-Property Battleground

If the survival of your organization revolves around patents and the protection of intellectual property then read what James Dyson, the founder of Dyson vacuum cleaners has to say about why businesses need to keep their eyes on the ball, when it comes to protecting their IP as well making sure the patents are watertight and properly registered.

Access the full article by clicking here

UK Government Bodies Are More Vulnerable To Data Breaches

UK government bodies are more vulnerable to data breaches now than ever before. Last week saw the London borough of Ealing and Hounslow council fined £80,000 and £70,000 respectively by the Information Commissioner’s Office (“ICO”) following the loss of two laptops containing sensitive personal information.

I have been consulting with one of these councils for over a year now to consider the deployment of Enterprise Rights Management across the entire organisation but this has not yielded a positive result. The last time I spoke to one of the managers responsible for data security I was told that the council was deep in the middle of their ICT strategy and would not be in a position to review anything outside of that until at least late 2012.

With many jobs on the line in local government, there is a great risk that staff could leave with confidential information with the aim of starting their own businesses or selling the information to third parties. However, it is a shame to say that out of 36 local government authorities I have made contact with, not one seems to have a solid strategy to prevent this from happening.

Even those who eventually keep their jobs will be less motivated to put data protection at the top of their agenda, and as such leave the council vulnerable to all kinds of data breaches. This picture is reflective of all government establishments up and down the country, and if there is the potential for financial gain the more vulnerable the organisation becomes.

The very low uptake of tools like enterprise rights management and data loss prevention is a true reflection of where the government at both the national and local levels. It is unlikely that anyone would loose their jobs when a data breach happens, and as such unless the ICO enforces the adoption of data security tools, it will be hard to stem the data breaches.

When Unauthorized Access To Confidential Information Could Cost You

The UK government cancelled a highly lucrative contract last week because the company that won the contract illegally gained access to confidential information that allegedly gave it competitive advantage over other businesses bidding for the same contract.

According to the BBC the cancellation of a deal which would have privatised the UK’s search and rescue helicopters raised “serious questions” because the private consortium Soteria that had been named as preferred bidder for the £6bn contract, which was due to run by 2012 had gained access to commercially sensitive information according to the Ministry of Defence.

There have been many occasions access to such sensitive information could lead to a competitive advantage, however, on this occasion it has resulted in a £6bn loss in revenue. This is an situation where going through a due and fair process is the best route to follow even if you loose the contract.

The military police are currently investigating how a former RAF officer now working with Soteria was able to gain access to commercially sensitive information and pass it on to his current employers.

It will be interesting to see how the whole story unfolds, but for now it is unlikely that the contract will be awarded to the private sector and will remain under the Royal Air Force operations.

This story reveals that information security is still not watertight at some of the UK’s most important and strategic organizations and a lot of work still needs to be done to make it highly secured when it comes to managing confidential information.

Information Rights Management Could Be The Correct Term

Over the last 10 years or so there has been a great debate over whether Information Rights Management is a better term over Enterprise Rights Management. However, the more I speak with customers that use Information Rights Management or Enterprise Rights Management, the more I am convinced that Information Rights Management is a better term for the following reasons below:-

  1. The word “Enterprise” has connotation that it is very expensive and resource intensive to deploy like other enterprise software e.g. Enterprise Resource Planning (ERP). This is actually not the case as it can be deplored in a small department with only 5 people.
  2. The acronyms used to describe enterprise rights management (erm) or enterprise digital rights management (edrm) are already used to describe Enterprise Risk Management and Electronic Data and Records Management, and can therefore be sometimes confusing.
  3. Information Rights Management best describes how rights management is applied, and that is on the information. The acronym IRM is also easy to associate with Information Rights Management.
  4. Finally adopting a single term preferably Information Rights Management will reduce the confusion about what it actually is.

Maybe you could have reasons why Information Rights Management is a better term and Enterprise Rights Management or vice versa, it will be great to hear from you. It could well be that keeping both terms is a good thing.

Fasoo.com to Launch New Mobile DRM Solution at the RSA Conference 2011

Fasoo.com, Inc., a leading enterprise rights management solution provider, will be  launching its latest mobile enterprise rights management solution, Fasoo Mobile Gateway at the RSA Conference in San Francisco from February 15 - 17, 2011.

Fasoo Mobile Gateway extends enterprise digital rights management to mobile computing and enables organizations to apply rights management policies to documents downloaded onto smartphones and tablets. The documents protected by enterprise rights management can be accessed from iPhone, iPad, Android devices, etc. via the Fasoo Mobile Rights Management App. With consumer technologies continuing to infiltrate the workplace, the new mobile solution will enable businesses to better manage and protect sensitive information, much of which is accessed from these unprotected devices. In fact, more than 76 percent of consumers surveyed use their smartphones or tablets to access sensitive or business information, according to a recent global study by Juniper Networks.

Fasoo Mobile Gateway supports various native file formats — such as Microsoft Office, PDFs, etc — on mobile devices. These documents can be accessed from the Fasoo Mobile Rights Management App, without changing file formats. The solution also enables organizations to constantly protect files; control file access privileges of users, groups and/or environments; and track activities of users and files, in addition to changes in configuration.

“Businesses have traditionally struggled to extend protection of their documents outside of the organization. But with mobile devices becoming so ubiquitous, it’s critical for businesses to protect sensitive content — even beyond the walls of their organization,” said Dr. Kyugon Cho, Fasoo founder and CEO. “Fasoo’s new Mobile Rights Management solution effectively fulfills diversified security requirements for mobile devices without compromising mobility and flexibility.”

To learn more about Fasoo, visit www.fasoo.com. The Fasoo stand will be at booth #533 at this year’s RSA conference.

Source: March Communications

Do You Know What Enterprise Rights Management Really Is?

Over the weekend I read an article posted on Infosec Island titled “Putting an End to Data Breaches as We Know Them” by Robert Siciliano. Having read the article and the comments I came to the conclusion that even information or data security experts do not fully understand what enterprise rights management is.

So here is the underlying problem; if IT security experts do not understand the full capabilities of enterprise rights management, how can they effectively communicate the benefits or shortcomings to their employers or clients? For me the article on Infosec Island revolves around whether ZafeSoft is enterprise rights management or not.

Even though throughout the website the phrase ‘enterprise rights management’ or ‘information rights management’ is not used, the writer deemed it to be superior to “other” enterprise rights management solutions out there. On the other hand having read through the ZafeSoft website and the features of their products I came to the conclusion that ZafeSoft is enterprise rights management.

Read More

Seminar: Protecting Engineering Data with Enterprise Rights Management

ProSTEP iViP is hosting a seminar targeted at engineering companies titled “Protecting Engineering Data with Enterprise Rights Management” in Stuttgart, Germany from February 9-10, 2011. With a rise in the theft of intellectual property in 2010, engineering companies need to invest in their future and the future of their employees by deploying Enterprise Rights Management. Companies like Intel have adopted Enterprise Rights Management, come and see the reason your company should.

Attend this seminar to have all your questions answered on protecting your IP and confidential data with Enterprise Rights Management. Call Yvonne van der Steeg on +49 (0) 6151-9287-446 or email her at yvonne.vandersteeg@prostep.com for a late registration as there may be a few places left.

For further information please visit the ProSTEP iViP website.

Intel Adopts Enterprise Rights Management

Intel recognises enterprise rights management as core to its future and the future of its employees according to its IT performance report for 2010 - 2011 titled “Delivering Competitive Advantage through IT” in which it said,

“We are implementing a secure integrated collaboration solution for our design engineers, with the goal of protecting Intel’s intellectual property while helping to accelerate silicon design. The new solution protects information at all times during creation, storage and transmission, using encrypted files and content repositories with enterprise rights management. This helps engineers be more productive by eliminating the need to secure data using manual methods. We began piloting the solution in 2010 in preparation for widespread deployment in 2011”.

Intel is surely leading the way for companies that depend highly on their intellectual property to survive, and if it is important for Intel to invest heavily in data security, it should serve as a wake up call for businesses especially technology businesses that have a liberal attitude towards the protection of its intellectual property.

Is WatchDox Enterprise Rights Management?

Two weeks ago I read a press release about WatchDox about the latest round of funding for this online document security business. In his comments Moti Rafalin, the WatchDox CEO said “Legacy enterprise digital rights management and data loss prevention products are failing to address the problem, and enterprises are realizing documents need to be seamlessly protected and controlled wherever they go.

So what does Rafalin mean by Legacy enterprise digital rights management and data loss prevention products? Considering that both document security tools are less than 10 years old, what makes them legacy? To understand what he meant by legacy I revisited the WatchDox website to try and understand what WatchDox does that other enterprise rights management solutions don’t do.

First of all I watched the video and everything demonstrated in this video is what most other vendors like Oracle, Fasoo, NextLabs, Covertix and CheckPoint to name a few also have the capability of doing also. So what does Rafalin actually mean by his criticism of WatchDox’s competitors?

On the web page titled “WatchDox vs. DRM, IRM or eDRM”, 4 key differentiators are mentioned between WatchDox and enterprise rights management, namely:-

  • Ease of use
  • Facilitating sharing and collaboration
  • Extended control
  • Cost

Under ease of use the main claim is WatchDox’s no client installation; no passwords; no enterprise deployment; no IT; and no hassle. Like WatchDox other vendors like NextLabs and Covertix offer the same no client installation, while a majority of the other vendors offer the remaining features like no passwords and it does not have to be an enterprise deployment, and apart from the server software installation, no further IT involvement is required.

Under facilitating sharing and collaboration WatchDox mentions that traditional DRM solutions typically deal with the insider threat. I definitely know that this is not the case as Fasoo, NextLabs and Oracle have always had a view to providing security both inside and outside the corporate firewall.

Under extended control WatchDox claims that it allows tracking, updating, revoking and changing document permissions even after they had been sent. Again, these are standard features that other enterprise rights management vendors offer in their software.

Regarding cost, other vendors are providing cheaper solutions. Fasoo has a file server solution that costs $5,000 and is implementing a number of SaaS solutions through its partners to lower the entry barrier. Costs from other vendors are also falling in line with the current economic situation in order to remain competitive.

So is WatchDox an enterprise digital rights management solution? I am certain it is, but is it any different from other vendors out there? Yes it is on the basis that it only offers a web based solution. However, there are opportunities for non web based solutions which its competitors offer.

WatchDox is an innovator in the enterprise rights management space because as a business has found a way to lower the barriers to entry from a cost perspective and will continue to challenge the status quo, but is not any significantly different from any other enterprise rights management solution in the marketplace.

Copy Protect eBooks, Documents and Your Livelihood with DRM

Brisbane, AU January 24, 2011 – Protecting documents and eBooks from copy and redistribution can be a daunting task when having to choose from a myriad of protective solutions that cannot thwart the simplest of bandits. But now authors can rest assured that their livelihood can be secured, by using an ArtistScope document solutions to control exactly who and how those documents can be accessed.

Copy protection and DRM have been around for years and most of it is superficial and easily circumvented, but not so with CopySafe technology which provides the most secure copy protection and the only solution that is safe from all copy including Printscreen and screen capture. Combined with ArtistScope’s DRM technology you can now have the most secure document protection imaginable, where even if your document falls into the hands of an unauthorized user, one who has not paid for the privilege, then they will not be able to open it.

But the big plus with the ArtistScope PDF solution and DRM is that as the author of the document, you can change a document’s properties at any time with immediate affect over all documents, even those that have already been downloaded. For example if you want to revoke a user’s privileges or change it so that the document can no longer be printed, then you can simply update that document’s settings at your Control Panel for immediate effect.

With ArtistScope DRM you can control who can open a document, who can print a document and even how many times a document can be opened or printed. And when an expiry date is set, it cannot be foiled in the usual manner by turning back a computer’s clock, because it can use an online timeserver. However you also have the choice of only using the computer’s clock to cater for documents that need to be accessed in the field without Internet access.

Almost any type of file can be converted to PDF and CopySafe PDF Protector can then encrypt it for the most secure copy protection with/without DRM applied. ArtistScope also provide a ready to use online service for DRM validation where you can simply upload your DRM documents and manage subscriptions straight away.

For the PDF Protection software and DRM Portal visit ArtistScope Copy Protection Software.