company and product overview fasoo 2014-1 q v2.2 (fsd for sharepoint)
DESCRIPTION
Fasoo Secure Document for SharePointTRANSCRIPT
1
Company and Product Overview1Q/2014
FSD for SharePoint
2External Communication
Company Overview
Founded in June, 2000
Specializes in Enterprise DRM (EDRM) solutions and services
Holds 270 employees, and more than 60% of employees has security consulting or DRM engineering backgrounds
Deployed over 1,200 organizations for more than 2 million users
Most of customers have deployed the solutions in enterprise-wide scale, and 20+ customers have the deployment of over 100,000 users worldwide
Launched DigitalQuick (secure cloud collaboration) in 2013
3External Communication
Value Proposition
Protects valuable information such as trade secrets & classified information beyond controlled boundaries (data-centric)
Ensures valuable digital assets are only viewed by the intended audience and unauthorized copies of documents are not produced and circulated
Reduces the risk of intellectual property loss while collaborating with 3rd parties
Secure Inter-Organizational Communication
s Effective Knowledge
Management
RegulatoryCompliance
4External Communication
New Challenges
Tightened regulation and compliance around PII and data integrity
Growing concerns of losing intellectual properties and trade secrets
Increasing threats by insiders/authorized users
New data security demands in cloud, mobile and social computing
5External Communication
Problems in Conventional Security
Conventional security solutions (Firewall, IPS, VPN, DLP) basically establish a physical boundary whose inside is assumed safe
Difficult to set up an effective policy against unfaithful insiders and smart hackers
In cloud and mobile computing environment, it is impossible to define the physical boundary of safe inside
These limitations have been seen repeatedly through a series of PII leak incidents
6External Communication
Fasoo Enterprise DRM
Fasoo Enterprise DRM safeguards and prevents unauthorized use of digital files and provides consistent and reliable protection of the documents with effective file encryption, permission control and audit trail technologies.
The solution offers customers persistent document security through encryption technologies that limit document access and rights.
It allows enterprises to prevent unintended information disclosure or exposure, ensure a secure information sharing environment, better manage workflows and simplify secure collaboration.
7External Communication
As-IsSteve in Sales
Sam in Sales
Sam creates and shares price list with Steve.
Steve reviews & shares the final version to Fred in Finance.
Fred in Finance
Fred receives the list from Seth via email, and makes updates (incl. PII) on his ledger.
Cameron can print any document.
Cam, Contractor
Ex-Employee
Ex-employees can access any document (copied while he was with previous organization).
Business Traveler
Partner Employee
External users could access documents with full access
Business travelers could access documents with full permission.
Security Vulnerability
8External Communication
To-BeSteve in Sales
Sam in Sales
Sam creates and shares price list with Steve.
Steve reviews & shares the final version to Fred in Finance.
Fred in Finance
Fred receives the list from Seth via email, and makes updates (incl. PII) on his ledger.
Cameron prints protected documents, and visible watermark is placed on non-PII documents. However, Cameron cannot print documents w/ PII.
Cam, Contractor
Ex-Employee
Ex-employees attempt to access protected document, but have no access to protected documents.
Business Traveler
Partner Employee
External users with appropriate credentials could access FSE-enabled documents using automated email authentication.
Business travelers could access protected documents via offline license, but have limited permission.
ProtectedGained abilities to secure, control and track sensitive documents no matter where they are.
Security Admin
9External Communication
General Flow of Data and SW Components
DRM Packager
DRM Client/Agent
DRM Server
Mobile Gateway
Mobile App
10External Communication
Characteristic Fasoo secures information persistently regardless of
location or whether it is at rest, in transit or in use.
Products manage documents created locally at a PC, created and stored inside a document repository, such as Microsoft SharePoint, or created and distributed to ad-hoc external users, using email, FTP, file sharing services, USB drives or other distribution methods.
Documents are encrypted and access is controlled through a policy (License) defined by administrators or document creators.
Since a DRM Client controls access to the rendering application, access is only granted through a License.
Each time a user accesses a document, the DRM Client contacts the DRM Server for a License.
This enables an administrator or document creator to change access permissions dynamically and even revoke access to a document once the document is created and distributed.
11External Communication
FSD---------------------Protects/controls/tracks documents have left the protective confines of the repository
--------------------- FSD Server FSD Server-Packager DRM Client
Item Description
Encryption • FSD Server-Packager (encryption module) integrates with web server of repository to encrypt target documents automatically.
• While encrypting documents, the module is also injecting metadata (e.g., document’s library path, repository’s ID, FSD Server ID, etc. as DRM/IRM policy identifiers).
• Even if the encrypted documents are being edited at desktops, its derivatives also maintain the consistent DRM policy by the client.
Authentication • FSD Server communicates either repository, user directory (e.g., AD) or 3rd party authentication tool to validate user credentials.
Policy • FSD Server communicates with repository by sending document ID (e.g., document’s library path, file ID, etc.) and user ID, then is mapping the user’s repository permission (e.g., Read, Contribute, Full Control, etc.) with DRM permission (e.g., View, Edit, Capture, Watermark, etc.)
• After permission mapping, FSD Server generates permission License file, then sends back to the user (DRM Client) for document access.
Audit trail • DRM Client sends document usage logs (e.g., user ID, file ID, device, network information) back to FSD Server periodically.
12External Communication
FSD---------------------General Flow of Data and SW Components
FSD Server
RepositoryUser 1 User Directory (AD)
User 2 (w/ credentials)
User 3 (w/o credentials)
Has View/Edit, but no
Print/Capture permissions
13Confidential
FSD for SharePoint---------------------Enabling IRM for Document Library – Encrypting on the fly (1)
14Confidential
FSD for SharePoint---------------------Enabling IRM for Document Library – Encrypting on the fly (2)
15Confidential
FSD for SharePoint--------------------Setting IRM Permission for Document Library (1)
16Confidential
FSD for SharePoint--------------------Setting IRM Permission for Document Library (2)
17Confidential
FSD for SharePoint--------------------Setting IRM Permission for Document Library (3)
18Confidential
FSD for SharePoint--------------------Allowing administrators to grant Print/Screen Capture/Office Access to users/groups
19Confidential
Customizable Permission Mapping--------------------Allowing administrators to map existing SharePoint list permissions SP Permission DRM Permission Level (Detail DRM
Permission)
ViewListItem View (VIEW)
EditListItems, ManageList or AddandCustomizePages
Edit (VIEW, EDIT, SECURE_SAVE, SECURE_EXTRACT)
ManagePermissions, ManageWeb or FullMask Full (VIEW, EDIT, SECURE_SAVE, SAVE, SECURE_EXTRACT, EXTRACT)
n/a Print (PRINT, SECURE_PRINT)
n/a Screen Capture (PRINT_SCREEN)
SP Permission Level DRM Permission Level (Detail DRM Permission)
Read, Restricted Read or View Only View (VIEW)
Design, Approve or Contribute Edit (VIEW, EDIT, SECURE_SAVE, SECURE_EXTRACT)
Full Control or Manage Hierarchy Full (VIEW, EDIT, SECURE_SAVE, SAVE, SECURE_EXTRACT, EXTRACT)
n/a Print (PRINT, SECURE_PRINT)
n/a Screen Capture (PRINT_SCREEN)
20Confidential
Direct File Access in SharePoint--------------------Opening a protected document in the protected library
*In case of PDF file, user will be asked to download a copy (protected) at local PC
21Confidential
Direct File Editing/Saving in SharePoint--------------------Saving a protected document directly to the same library
*In case of PowerPoint, direct editing is restricted, and user must download a copy (protected), and upload the revised file.
22External Communication
Persistent Protection & Dynamic Permission Control---------------------If a protected document (lock icon) is saved at PC, local copy maintains a consistent policy of the protected library/object store folder.
23External Communication
Secure Extract---------------------If a protected document is edited at PC, its derivative (e.g., PDF) maintains a consistent policy of the protected library/object store folder.
24External Communication
Secure Copy & Paste---------------------Copy/cut & paste (drag & drop) is only allowed within/between protected documents, and does not allow users (w/ edit capability) to extract content from protected document to unprotected file.
25External Communication
Screen Capture Prevention (1)---------------------Screen capture can only be allowed when user has appropriate user credentials.
26External Communication
Screen Capture Prevention (2)---------------------Screen capture can only be allowed when user has appropriate user credentials.
27External Communication
Customer Benefit
Raising Competitive Advantages
Optimizing Productivity
Protecting sensitive information
to prevent data breach events
Simplifying secure inter-
organizational collaboration
Complying w/ regulations
Building reputation & gaining
customer trust
Enabling better managed
workflows via data-centric
security
Offering flexibilities to users to
improve productivity
Enforcing automated encryption
via user/group based policies
Data-Centri
c Securi
ty
28External Communication
Fasoo Enterprise DRM (FED)Suite
Desktop
Repository
External
Display
Mobile
Pattern-Based
Context-Aware
29External Communication
Key Differentiator---------------------Longevity, Breadth of Solution
Longevity‐ Fasoo is a leading DRM/IRM company in the global
market. Since 2000, Fasoo has focused its efforts on protecting clients' critical information from unauthorized users. Most other DRM/IRM focused companies have been acquired or altered their focus.
Breadth of solution‐ Based on the 14+ years of DRM/IRM focus, Fasoo has
been able to build an extremely broad solution set with the ability to handle the enterprise requirements of data stored in repositories, created on local devices and transmitted through Ad-hoc means. Fasoo continues to develop products to meet the changing requirements including adding Mobile Device Support (iOS, Android), Cloud Sharing Support (like Dropbox) and soon to be released support for Mac. No other products in the market can satisfy the enterprise requirements like Fasoo.
30External Communication
Key Differentiator---------------------Flexibility, Scalability
Flexibility‐ Fasoo understands that the market is extremely broad
and while current solutions can integrate with key market leading products like SharePoint (repository) Outlook (email), organizations may have proprietary needs. As a result, Fasoo has SDKs with APIs available in Java, C and C++ for integration into any document repository.
Scalability‐ Fasoo has proven to scale within some of the largest
environments in the world. Large portion of Fasoo customers have the deployment of over 10,000 users enterprise-wide, and more than 20 customers have the deployment of over 100,000 users worldwide.
31External Communication
Key Differentiator---------------------Extensive Application Coverage, Mobile Platforms
Extensive application coverage‐ Fasoo supports an extremely broad base of rendering
applications. While most companies only support Microsoft Office and Adobe PDF, Fasoo extends to nearly 50 applications and exponentially more file types. Fasoo has the ability to extend the application support upon client's request.
Mobile platforms‐ Access to content is no longer restricted to the PC. With
the mobile device explosion, it is critical that DRM/IRM solutions enable at a minimum the ability to view files on a iOS or Android device. As a result in 2011, Fasoo released its proprietary iOS and Android App.
32
Wrap-up and Q&[email protected]