Strategic Direction Session: Enhancing Data
Privacy With Data-Centric Security for Mainframe
Vikas Sinha
MFT13S
MAINFRAME
SVP Business Unit Executive
CA Technologies
VP Product Management
CA Technologies
Stuart McIrvine
Sr. Information Security Architect
Zions Bank
Peter Garza
2 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
For Informational Purposes Only
Terms of this Presentation
© 2017 CA. All rights reserved. All trademarks referenced herein belong to their respective companies. The presentation provided at
CA World 2017 is intended for information purposes only and does not form any type of warranty. Some of the specific slides with
customer references relate to customer's specific use and experience of CA products and solutions so actual results may vary.
Certain information in this presentation may outline CA’s general product direction. This presentation shall not serve to (i) affect the
rights and/or obligations of CA or its licensees under any existing or future license agreement or services agreement relating to any
CA software product; or (ii) amend any product documentation or specifications for any CA software product. This presentation is
based on current information and resource allocations as of November 1, 2017, and is subject to change or withdrawal by CA at any
time without notice. The development, release and timing of any features or functionality described in this presentation remain at
CA’s sole discretion.
Notwithstanding anything in this presentation to the contrary, upon the general availability of any future CA product release
referenced in this presentation, CA may make such release available to new licensees in the form of a regularly scheduled major
product release. Such release may be made available to licensees of the product who are active subscribers to CA maintenance and
support, on a when and if-available basis. The information in this presentation is not deemed to be incorporated into any contract.
3 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Abstract
With great power comes great responsibility. Mainframes have both: the power of data
and transactions that run the application economy, and the responsibility to keep that
data protected. Join this roadmap session to learn from CA data privacy leaders and see
the future of the data-centric security strategy, covering key products such as CA Data
Content Discovery for z/OS, CA Compliance Event Manager and more. Learn how to
enhance your data privacy and simplify regulatory compliance, plus get a view into the
roadmap of what's to come in the mainframe security and compliance portfolio.
Vikas Sinha
CA Technologies
SVP Business Unit
Executive
Stuart McIrvine
CA Technologies
VP Product Management
Peter Garza
Zions Bank
Sr. Information Security
Architect
4 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Agenda
DIGITAL TRUST DRIVES THE DIGITAL ECONOMY
THE MAINFRAME IS JUST LIKE ANY OTHER PLATFORM
CA MAINFRAME SECURITY HELPS YOU DELIVER TRUST
DATA-CENTRIC SECURITY AND COMPLIANCE
JOINING FORCES FOR ENHANCED SECURITY WITH Z14
ENSURE COMPLIANCE FOR USER ACCESS
1
2
3
4
5
6
5 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
GDPR Compliance
takes effect May 2018
Average cost per stolen
record is $1412
47% of breaches involve a
malicious or criminal attack2
Data-Centric Security and Compliance
Data Breaches
Insider Threats
Regulations
Ransomware
77% of data breaches derive
from internal sources1
Source: Verizon Data Breach Report1; Ponemon Institute Reputation Risk Study, 2017
6 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
$6.8B
in financial losses annual due to account takeover1
$3T
in business growth could be slowed due to cyber attacks2
Sources:
1. Forrester Research, RBA Wave Report 2017
2. McKinsey and World Economic Forum Report, July 2014
…and data breaches are
causing a loss of trust and
limiting growth
Digital Trust Drives the Digital Economy
7 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
The Mainframe Is Just Like Any Other Platform
Increased Data Breaches
Sensitive and regulated
data at risk to threat
Social Engineering
Access credentials
are vulnerable
Insider Threats
Misuse of access from
internal employees
8 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Mainframe Security and Compliance Overview
Ensuring Compliance With the Strictest Security Policies in the Data Center
Data Security &
Compliance
• Evolving mainframe
access control
compliance
• Data security controls for
mainframe
• User activity
Identity &
Access
Management
User
Activity
Monitoring
& Alerting
Auditing
Cleanup
PIV/CAC
RADIUS
9 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
How Do I Make Data-Centric Security and
Compliance A Competitive Advantage?
KEY CHALLENGES:
• Strict data protection requirements and heavy
penalties
• Expanded definitions of personal data
• Orphaned or unknown data location, especially as
data is taken off the mainframe for testing, pre-
production staging or analytics
SOLUTION:
Knowing what personal data you have, where it
resides, who has access, and how it’s protected.
Protection for data in
motion
PII, sensitive data and
custom pattern
scanning
User access and Log
management - historical
and predictive
Real-time alerting with
Security Incident and
Event Management
10 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Increase Your Data Privacy and Simplify Compliance
FIND
Data that may be lost,
hidden or abandoned
CLASSIFY
Based on sensitivity level
for compliance
PROTECT
With more informed data
protection strategies
ALERT
In real-time of abnormal
access attempts
INSPECT
With advanced reporting
and forensics
11 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
The Solution: Enterprise Data Protection
of the world’s data transacts on the mainframe. Protect
it with CA Data Content Discovery.70%+
Find ProtectClassify
“The most valuable feature of CA Data Content Discovery is the ability to recognize, in
an intelligent and accessible way, which data sets on the mainframe contain
sensitive data that need to be protected from a governance and regulatory
perspective.” – Chief Strategist 1
Sources: 1 - IT Central Station, CA Data Content Discovery review, Dec 6, 2016
12 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Joining Forces With IBM z14 for Enhanced
Enterprise Security
1
• Pervasive Encryption
• Real-Time Machine
Learning
• Connected Ecosystem
• Container Pricing
#trustIBMz
• Identify where sensitive data is and
show who has access to it
• Receive alerts in real-time for
abnormal access attempts
• Ensure more granular security for
sensitive data
13 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Data-Centric Security to Simplify GDPR Compliance
Find, classify and understand who
has access to sensitive and
regulated data
Add additional controls such as
encryption, masking or
tokenization
Monitor data activity and receive
alerts when policies are violated
14 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Large Regional Bank
Western US Bank offering a full suite of financial services needed a solution to quickly meet audit and
compliance requirements to ensure all sensitive financial information was located and secured
CHALLENGE:
Increased transaction volumes made it difficult to find, classify and
protect all regulated financial data on the mainframe
CA Data Content Discovery.
Initial scans
identified 5%
had unknown
sensitive data
Increased risk
assessment
through automated
efforts
Improved
business
agility by
automating
scans
The answer?
The Benefits of Enhancing Enterprise Data Privacy
15 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
How Do I Ensure Compliance for User Access?
KEY CHALLENGES:
• Systems must be auditable with granular logging
• Streamlining management of all privileged user IDs
• Ensuring consistent two-factor authentication
• Auditing and logging suspicious activity
• Lack of enterprise visibility and control
SOLUTION:
Tighter control and tracking of users with access to
the most sensitive corporate data.
Advanced authentication
for mainframe
Privileged access
management for
mainframe
Granular, role-based
security controls
Secure and frictionless
access for employees,
customers and partners
16 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
The Solution: Access Control
Advanced
Authentication
Event EnrichmentPrivileged Access
Management
Built on the foundation of CA ACF2TM and CA Top Secret®
CA Trusted Access
Manager for Z
CA Advanced
Authentication Mainframe
CA Compliance Event
Manager
• Reduce insider threats
• Increase business efficiency
• Elevate existing user IDs
• 100% on the mainframe
• PIV, CAC, Smart Card,
RADIUS
• Via RSA SecurID
• Support for IBM RACF
• Ensure compliance for user
access
• Event enrichment and
reporting
17 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
VERIFY
PEOPLE
PROTECT
DATA
ENSURE
SYSTEMS
Digital Trust Is the Currency of Digital Enterprise
1
Partner with your Line of Business to establish a digital trust
strategy at the core of your organization to capitalize on new
digital business opportunities faster than your competitors,
because it reduces risk and improves your agility to scale to
reach millions and billions of users and things
18 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
CA Mainframe Security Helps You Build Trust
Correlation and
Insight
Compliance
Management
Data Security
Identity and Access
Management
Event Filtering; SIEM;
Analytics
User Activity Monitoring; Data Compliance;
Reporting
Data Discovery - Static and In Motion; Data
Protection
Advanced Authentication - RSA, CAC/PIV, OTP;
Privileged Access Management
19 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
A Discussion With Zions Bank
20 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
What were some of the challenges
Zions Bank was facing prior to CA Data
Content Discovery?
21 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
How would you say CA Data Content
Discovery is used in your organization
today versus last year?
22 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
What are some of the interesting things
you’ve done with the solution recently?
23 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
What do you see in the future for and
data security market at large?
24 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Recommended Sessions
SESSION # TITLE DATE/TIME
MFT46T Optimize Data-Centric Security on the Mainframe 11/15/2017 at 2:30 pm
MFT48T Defend Against Mainframe Privileged User Risks 11/16/2017 at 12:45 pm
MFT14S
Panel Discussion: Cybersecurity and Regulatory
Compliance, and the Latest Approaches to Improving
Your Data Privacy Posture
11/16/2017 at 2:30 pm
25 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Must See Demos
CA Data
Content
Discovery
Mainframe Theatre
CA
Compliance
Event
Manager
CA Trusted
Access
Manager for
Z
Mainframe Theatre
CA
Advanced
Authentication
Mainframe
Mainframe TheatreMainframe Theatre
26 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Questions?
27 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Stay connected at communities.ca.com
Thank you.
28 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
www.mainframe.ai
28 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
29 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
Mainframe
For more information on Mainframe,
please visit: http://cainc.to/CAW17-Mainframe

More Related Content

PDF
Securing Your Enterprise Continuous Delivery Pipelines with CA Automation Sol...
PDF
Blockchain: Strategies for Moving From Hype to Realities of Deployment
PDF
Pre-Con Ed: Privileged Identity Governance: Are You Certifying Privileged Use...
PDF
Making Security Work—Implementing a Transformational Security Program
PDF
Case Study: Privileged Access in a World on Time
PDF
The Unmet Demand for Premium Cloud Monitoring Services—and How Service Provid...
PDF
The Next Big Service Provider Opportunity—Beyond Infrastructure: Architecting...
PDF
Keynote: Making Security a Competitive Advantage
Securing Your Enterprise Continuous Delivery Pipelines with CA Automation Sol...
Blockchain: Strategies for Moving From Hype to Realities of Deployment
Pre-Con Ed: Privileged Identity Governance: Are You Certifying Privileged Use...
Making Security Work—Implementing a Transformational Security Program
Case Study: Privileged Access in a World on Time
The Unmet Demand for Premium Cloud Monitoring Services—and How Service Provid...
The Next Big Service Provider Opportunity—Beyond Infrastructure: Architecting...
Keynote: Making Security a Competitive Advantage

What's hot (19)

PDF
Case Study: How SGN Used Attack Path Mapping to Control Privileged Access in ...
PDF
Leveraging Monitoring Governance: How Service Providers Can Boost Operational...
PDF
Emerging Managed Services Opportunities in Identity and Access Management
PDF
Application Experience Analytics Services: The Strategic Digital Transformati...
PPTX
Overcoming the Challenges of Architecting for the Cloud
PDF
Security Opening Keynote Address: Security Drives DIGITAL TRANSFORMATION in...
PPTX
Empowering Digital Transformation in Financial Services
PPTX
Cloud vs. On-Premises Security: Can you afford not to switch?
PDF
[Cisco Connect 2018 - Vietnam] Yedu s. introducing cisco dna assurance
PDF
Security Across the Cloud Native Continuum with ESG and Palo Alto Networks
PPTX
Three ways-zero-trust-security-redefines-partner-access-v8
PPTX
Zscaler mondi webinar
PDF
Building Digital Trust
PPTX
Accelerate your digital transformation
PDF
Distributor-Cloud-Marketplaces
PPTX
Webinar: Maximizing the ROI of IT by Simplifying Technology Complexity
PDF
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
PDF
Cisco Connect 2018 Philippines - introducing cisco dna assurance
PDF
Value Plus July Edition - 2015
Case Study: How SGN Used Attack Path Mapping to Control Privileged Access in ...
Leveraging Monitoring Governance: How Service Providers Can Boost Operational...
Emerging Managed Services Opportunities in Identity and Access Management
Application Experience Analytics Services: The Strategic Digital Transformati...
Overcoming the Challenges of Architecting for the Cloud
Security Opening Keynote Address: Security Drives DIGITAL TRANSFORMATION in...
Empowering Digital Transformation in Financial Services
Cloud vs. On-Premises Security: Can you afford not to switch?
[Cisco Connect 2018 - Vietnam] Yedu s. introducing cisco dna assurance
Security Across the Cloud Native Continuum with ESG and Palo Alto Networks
Three ways-zero-trust-security-redefines-partner-access-v8
Zscaler mondi webinar
Building Digital Trust
Accelerate your digital transformation
Distributor-Cloud-Marketplaces
Webinar: Maximizing the ROI of IT by Simplifying Technology Complexity
Cisco Connect 2018 Malaysia - software-defined access-a transformational appr...
Cisco Connect 2018 Philippines - introducing cisco dna assurance
Value Plus July Edition - 2015
Ad

Similar to Strategic Direction Session: Enhancing Data Privacy with Data-Centric Security for Mainframe (20)

PDF
Strategic Direction Session: Deliver Next-Gen IT Ops with CA Mainframe Operat...
PPTX
Ping Identity: Corporate Overview Financial Services
PDF
Establish Digital Trust as the Currency of Digital Enterprise
PDF
Establish Digital Trust as the Currency of Digital Enterprise
PPTX
Practical Security for the Cloud
PPTX
File Sharing Use Cases in Financial Services
PPTX
BREACHED: Data Centric Security for SAP
PDF
Protecting What Matters Most – Data
PDF
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
PDF
Manage Risk by Protecting the Apps and Data That Drive Business Productivity
PDF
Clearswift f5 integration
PPTX
Hadoop and Financial Services
PDF
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
PDF
Big Data LDN 2017: Data Governance Reimagined
PPTX
Strengthen Cloud Security
PDF
Security and Data Breach
PPTX
Innovation Without Compromise: The Challenges of Securing Big Data
PPTX
Cyberlink Deck
PPTX
GDPR Part 4: Better Together Quest & SonicWall
PDF
Protect Against Security Breaches by Securing Endpoints with Multi-Factor Aut...
Strategic Direction Session: Deliver Next-Gen IT Ops with CA Mainframe Operat...
Ping Identity: Corporate Overview Financial Services
Establish Digital Trust as the Currency of Digital Enterprise
Establish Digital Trust as the Currency of Digital Enterprise
Practical Security for the Cloud
File Sharing Use Cases in Financial Services
BREACHED: Data Centric Security for SAP
Protecting What Matters Most – Data
The ForgeRock Identity Platform Extends CIAM, Fall 2017 Release
Manage Risk by Protecting the Apps and Data That Drive Business Productivity
Clearswift f5 integration
Hadoop and Financial Services
Symantec Webinar Part 1 of 6 The Four Stages of GDPR Readiness
Big Data LDN 2017: Data Governance Reimagined
Strengthen Cloud Security
Security and Data Breach
Innovation Without Compromise: The Challenges of Securing Big Data
Cyberlink Deck
GDPR Part 4: Better Together Quest & SonicWall
Protect Against Security Breaches by Securing Endpoints with Multi-Factor Aut...
Ad

More from CA Technologies (17)

PPTX
CA Mainframe Resource Intelligence
PDF
Mainframe as a Service: Sample a Buffet of IBM z/OS® Platform Excellence
PDF
Case Study: How CA Went From 40 Days to Three Days Building Crystal-Clear Tes...
PDF
Case Study: How The Home Depot Built Quality Into Software Development
PDF
Case Study: Putting Citizens at The Center of Digital Government
PDF
Keynote: Making Security a Competitive Advantage
PDF
Application Experience Analytics Services: The Strategic Digital Transformati...
PDF
How Components Increase Speed and Risk
PDF
The CA Technologies | Veracode Platform: A 360-Degree View of Your Applicatio...
PDF
When You Test Matters: Why Testing Early in the SDLC is Important
PDF
Application Security in a DevOps World
PDF
Case Study: How The Home Depot Built Quality Into Software Development
PDF
Case Study: How CA Went From 40 Days to Three Days Building Crystal-Clear Tes...
PDF
Case Study: Continuous Delivery in a Tech Debt Laden World by Talk Talk.
PDF
Case Study: United Airlines Transforms Release Management for Its Modern Soft...
PDF
Keynote: Unlock the Power of Continuous Delivery with End-to-End, Integrated ...
PDF
Industry Keynote: Redefine Operations in a DevOps World—The New Role for Site...
CA Mainframe Resource Intelligence
Mainframe as a Service: Sample a Buffet of IBM z/OS® Platform Excellence
Case Study: How CA Went From 40 Days to Three Days Building Crystal-Clear Tes...
Case Study: How The Home Depot Built Quality Into Software Development
Case Study: Putting Citizens at The Center of Digital Government
Keynote: Making Security a Competitive Advantage
Application Experience Analytics Services: The Strategic Digital Transformati...
How Components Increase Speed and Risk
The CA Technologies | Veracode Platform: A 360-Degree View of Your Applicatio...
When You Test Matters: Why Testing Early in the SDLC is Important
Application Security in a DevOps World
Case Study: How The Home Depot Built Quality Into Software Development
Case Study: How CA Went From 40 Days to Three Days Building Crystal-Clear Tes...
Case Study: Continuous Delivery in a Tech Debt Laden World by Talk Talk.
Case Study: United Airlines Transforms Release Management for Its Modern Soft...
Keynote: Unlock the Power of Continuous Delivery with End-to-End, Integrated ...
Industry Keynote: Redefine Operations in a DevOps World—The New Role for Site...

Recently uploaded (20)

PPTX
Internet of Everything -Basic concepts details
PDF
Transform-Your-Supply-Chain-with-AI-Driven-Quality-Engineering.pdf
PDF
Lung cancer patients survival prediction using outlier detection and optimize...
DOCX
Basics of Cloud Computing - Cloud Ecosystem
PDF
The AI Revolution in Customer Service - 2025
PDF
A hybrid framework for wild animal classification using fine-tuned DenseNet12...
PDF
Early detection and classification of bone marrow changes in lumbar vertebrae...
PDF
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
PDF
Dell Pro Micro: Speed customer interactions, patient processing, and learning...
PDF
ment.tech-Siri Delay Opens AI Startup Opportunity in 2025.pdf
PDF
A symptom-driven medical diagnosis support model based on machine learning te...
PDF
MENA-ECEONOMIC-CONTEXT-VC MENA-ECEONOMIC
PPTX
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
PDF
NewMind AI Weekly Chronicles – August ’25 Week IV
PDF
Planning-an-Audit-A-How-To-Guide-Checklist-WP.pdf
PPTX
Module 1 Introduction to Web Programming .pptx
PDF
4 layer Arch & Reference Arch of IoT.pdf
PDF
Transform-Your-Streaming-Platform-with-AI-Driven-Quality-Engineering.pdf
PDF
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
PDF
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf
Internet of Everything -Basic concepts details
Transform-Your-Supply-Chain-with-AI-Driven-Quality-Engineering.pdf
Lung cancer patients survival prediction using outlier detection and optimize...
Basics of Cloud Computing - Cloud Ecosystem
The AI Revolution in Customer Service - 2025
A hybrid framework for wild animal classification using fine-tuned DenseNet12...
Early detection and classification of bone marrow changes in lumbar vertebrae...
Transform-Your-Factory-with-AI-Driven-Quality-Engineering.pdf
Dell Pro Micro: Speed customer interactions, patient processing, and learning...
ment.tech-Siri Delay Opens AI Startup Opportunity in 2025.pdf
A symptom-driven medical diagnosis support model based on machine learning te...
MENA-ECEONOMIC-CONTEXT-VC MENA-ECEONOMIC
AI-driven Assurance Across Your End-to-end Network With ThousandEyes
NewMind AI Weekly Chronicles – August ’25 Week IV
Planning-an-Audit-A-How-To-Guide-Checklist-WP.pdf
Module 1 Introduction to Web Programming .pptx
4 layer Arch & Reference Arch of IoT.pdf
Transform-Your-Streaming-Platform-with-AI-Driven-Quality-Engineering.pdf
The-2025-Engineering-Revolution-AI-Quality-and-DevOps-Convergence.pdf
zbrain.ai-Scope Key Metrics Configuration and Best Practices.pdf

Strategic Direction Session: Enhancing Data Privacy with Data-Centric Security for Mainframe

  • 1. Strategic Direction Session: Enhancing Data Privacy With Data-Centric Security for Mainframe Vikas Sinha MFT13S MAINFRAME SVP Business Unit Executive CA Technologies VP Product Management CA Technologies Stuart McIrvine Sr. Information Security Architect Zions Bank Peter Garza
  • 2. 2 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS For Informational Purposes Only Terms of this Presentation © 2017 CA. All rights reserved. All trademarks referenced herein belong to their respective companies. The presentation provided at CA World 2017 is intended for information purposes only and does not form any type of warranty. Some of the specific slides with customer references relate to customer's specific use and experience of CA products and solutions so actual results may vary. Certain information in this presentation may outline CA’s general product direction. This presentation shall not serve to (i) affect the rights and/or obligations of CA or its licensees under any existing or future license agreement or services agreement relating to any CA software product; or (ii) amend any product documentation or specifications for any CA software product. This presentation is based on current information and resource allocations as of November 1, 2017, and is subject to change or withdrawal by CA at any time without notice. The development, release and timing of any features or functionality described in this presentation remain at CA’s sole discretion. Notwithstanding anything in this presentation to the contrary, upon the general availability of any future CA product release referenced in this presentation, CA may make such release available to new licensees in the form of a regularly scheduled major product release. Such release may be made available to licensees of the product who are active subscribers to CA maintenance and support, on a when and if-available basis. The information in this presentation is not deemed to be incorporated into any contract.
  • 3. 3 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Abstract With great power comes great responsibility. Mainframes have both: the power of data and transactions that run the application economy, and the responsibility to keep that data protected. Join this roadmap session to learn from CA data privacy leaders and see the future of the data-centric security strategy, covering key products such as CA Data Content Discovery for z/OS, CA Compliance Event Manager and more. Learn how to enhance your data privacy and simplify regulatory compliance, plus get a view into the roadmap of what's to come in the mainframe security and compliance portfolio. Vikas Sinha CA Technologies SVP Business Unit Executive Stuart McIrvine CA Technologies VP Product Management Peter Garza Zions Bank Sr. Information Security Architect
  • 4. 4 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Agenda DIGITAL TRUST DRIVES THE DIGITAL ECONOMY THE MAINFRAME IS JUST LIKE ANY OTHER PLATFORM CA MAINFRAME SECURITY HELPS YOU DELIVER TRUST DATA-CENTRIC SECURITY AND COMPLIANCE JOINING FORCES FOR ENHANCED SECURITY WITH Z14 ENSURE COMPLIANCE FOR USER ACCESS 1 2 3 4 5 6
  • 5. 5 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS GDPR Compliance takes effect May 2018 Average cost per stolen record is $1412 47% of breaches involve a malicious or criminal attack2 Data-Centric Security and Compliance Data Breaches Insider Threats Regulations Ransomware 77% of data breaches derive from internal sources1 Source: Verizon Data Breach Report1; Ponemon Institute Reputation Risk Study, 2017
  • 6. 6 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS $6.8B in financial losses annual due to account takeover1 $3T in business growth could be slowed due to cyber attacks2 Sources: 1. Forrester Research, RBA Wave Report 2017 2. McKinsey and World Economic Forum Report, July 2014 …and data breaches are causing a loss of trust and limiting growth Digital Trust Drives the Digital Economy
  • 7. 7 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS The Mainframe Is Just Like Any Other Platform Increased Data Breaches Sensitive and regulated data at risk to threat Social Engineering Access credentials are vulnerable Insider Threats Misuse of access from internal employees
  • 8. 8 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Mainframe Security and Compliance Overview Ensuring Compliance With the Strictest Security Policies in the Data Center Data Security & Compliance • Evolving mainframe access control compliance • Data security controls for mainframe • User activity Identity & Access Management User Activity Monitoring & Alerting Auditing Cleanup PIV/CAC RADIUS
  • 9. 9 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS How Do I Make Data-Centric Security and Compliance A Competitive Advantage? KEY CHALLENGES: • Strict data protection requirements and heavy penalties • Expanded definitions of personal data • Orphaned or unknown data location, especially as data is taken off the mainframe for testing, pre- production staging or analytics SOLUTION: Knowing what personal data you have, where it resides, who has access, and how it’s protected. Protection for data in motion PII, sensitive data and custom pattern scanning User access and Log management - historical and predictive Real-time alerting with Security Incident and Event Management
  • 10. 10 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Increase Your Data Privacy and Simplify Compliance FIND Data that may be lost, hidden or abandoned CLASSIFY Based on sensitivity level for compliance PROTECT With more informed data protection strategies ALERT In real-time of abnormal access attempts INSPECT With advanced reporting and forensics
  • 11. 11 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS The Solution: Enterprise Data Protection of the world’s data transacts on the mainframe. Protect it with CA Data Content Discovery.70%+ Find ProtectClassify “The most valuable feature of CA Data Content Discovery is the ability to recognize, in an intelligent and accessible way, which data sets on the mainframe contain sensitive data that need to be protected from a governance and regulatory perspective.” – Chief Strategist 1 Sources: 1 - IT Central Station, CA Data Content Discovery review, Dec 6, 2016
  • 12. 12 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Joining Forces With IBM z14 for Enhanced Enterprise Security 1 • Pervasive Encryption • Real-Time Machine Learning • Connected Ecosystem • Container Pricing #trustIBMz • Identify where sensitive data is and show who has access to it • Receive alerts in real-time for abnormal access attempts • Ensure more granular security for sensitive data
  • 13. 13 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Data-Centric Security to Simplify GDPR Compliance Find, classify and understand who has access to sensitive and regulated data Add additional controls such as encryption, masking or tokenization Monitor data activity and receive alerts when policies are violated
  • 14. 14 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Large Regional Bank Western US Bank offering a full suite of financial services needed a solution to quickly meet audit and compliance requirements to ensure all sensitive financial information was located and secured CHALLENGE: Increased transaction volumes made it difficult to find, classify and protect all regulated financial data on the mainframe CA Data Content Discovery. Initial scans identified 5% had unknown sensitive data Increased risk assessment through automated efforts Improved business agility by automating scans The answer? The Benefits of Enhancing Enterprise Data Privacy
  • 15. 15 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS How Do I Ensure Compliance for User Access? KEY CHALLENGES: • Systems must be auditable with granular logging • Streamlining management of all privileged user IDs • Ensuring consistent two-factor authentication • Auditing and logging suspicious activity • Lack of enterprise visibility and control SOLUTION: Tighter control and tracking of users with access to the most sensitive corporate data. Advanced authentication for mainframe Privileged access management for mainframe Granular, role-based security controls Secure and frictionless access for employees, customers and partners
  • 16. 16 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS The Solution: Access Control Advanced Authentication Event EnrichmentPrivileged Access Management Built on the foundation of CA ACF2TM and CA Top Secret® CA Trusted Access Manager for Z CA Advanced Authentication Mainframe CA Compliance Event Manager • Reduce insider threats • Increase business efficiency • Elevate existing user IDs • 100% on the mainframe • PIV, CAC, Smart Card, RADIUS • Via RSA SecurID • Support for IBM RACF • Ensure compliance for user access • Event enrichment and reporting
  • 17. 17 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS VERIFY PEOPLE PROTECT DATA ENSURE SYSTEMS Digital Trust Is the Currency of Digital Enterprise 1 Partner with your Line of Business to establish a digital trust strategy at the core of your organization to capitalize on new digital business opportunities faster than your competitors, because it reduces risk and improves your agility to scale to reach millions and billions of users and things
  • 18. 18 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS CA Mainframe Security Helps You Build Trust Correlation and Insight Compliance Management Data Security Identity and Access Management Event Filtering; SIEM; Analytics User Activity Monitoring; Data Compliance; Reporting Data Discovery - Static and In Motion; Data Protection Advanced Authentication - RSA, CAC/PIV, OTP; Privileged Access Management
  • 19. 19 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS A Discussion With Zions Bank
  • 20. 20 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS What were some of the challenges Zions Bank was facing prior to CA Data Content Discovery?
  • 21. 21 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS How would you say CA Data Content Discovery is used in your organization today versus last year?
  • 22. 22 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS What are some of the interesting things you’ve done with the solution recently?
  • 23. 23 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS What do you see in the future for and data security market at large?
  • 24. 24 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Recommended Sessions SESSION # TITLE DATE/TIME MFT46T Optimize Data-Centric Security on the Mainframe 11/15/2017 at 2:30 pm MFT48T Defend Against Mainframe Privileged User Risks 11/16/2017 at 12:45 pm MFT14S Panel Discussion: Cybersecurity and Regulatory Compliance, and the Latest Approaches to Improving Your Data Privacy Posture 11/16/2017 at 2:30 pm
  • 25. 25 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Must See Demos CA Data Content Discovery Mainframe Theatre CA Compliance Event Manager CA Trusted Access Manager for Z Mainframe Theatre CA Advanced Authentication Mainframe Mainframe TheatreMainframe Theatre
  • 26. 26 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Questions?
  • 27. 27 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Stay connected at communities.ca.com Thank you.
  • 28. 28 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS www.mainframe.ai 28 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS
  • 29. 29 COPYRIGHT © 2017 CA. ALL RIGHTS RESERVED#CAWORLD #NOBARRIERS Mainframe For more information on Mainframe, please visit: http://cainc.to/CAW17-Mainframe