[CygnaCom Solutions logo]
Login    Contact Us   
  Products   Services   Corporate   Labs   Careers
Search
Security Testing and Evaluation Labs
 
 
Security Evaluation Laboratory
 
Overview (pdf)
 
Common Criteria
 
Evaluated Products
 
More Information...
 
CC Assurance Index
 
CC Function Index
 
 
Cryptographic Equipment Assessment Laboratory
Careers
 
Contact Us


Entrust Home
Security Testing
 

Security Testing and Evaluation Labs

Security Evaluation Laboratory (SEL)


AmberPoint : AmberPoint's Management Foundation product

Sponsor:AmberPoint, Inc.
Point of Contact:Bob Dever Phone: (510)433-6553
Assurance Level:EAL2
Status:Pre-Evaluation

AmberPoint SOA Management

AmberPoint addresses the critical need to manage and secure SOA implementations. Due to the distributed, heterogeneous, evolutionary nature of services-based systems, they create management challenges that are beyond the scope of traditional Network Systems Management (NSM) and Enterprise Systems Management (ESM) systems. Organizations must address these runtime governance requirements before they can reliably take their SOA-based applications into production. Organizations looking to gain business value from SOA must:

  • Ensure operational health
  • Manage applications spanning multiple machines
  • Address heightened security concerns
  • Enable online upgrades and versioning
  • Detect and handle exceptional conditions
  • Set and maintain appropriate service levels

AmberPoint has a non-invasive approach to management that abstracts the management layer from the Web services, allowing systems to evolve and grow without constant recoding. AmberPoint’s native support for both Java and .NET enables its management solutions to leverage the advantages of the leading platforms. AmberPoint’s comprehensive runtime governance capabilities include the following:

Discovery and Dependency Tracking

Helping to reduce system complexity, AmberPoint automatically discovers services and displays interdependencies across service-oriented systems. AmberPoint dashboards depict these services graphically, helping organizations to understand the impact of system changes and to better perform root-cause analysis.

Service Level Management

AmberPoint provides comprehensive service level governance capabilities. When first starting with Web services, organizations must define, track and control appropriate service levels over the course of a pilot project. When implementing Web services, they need to review and analyze quality-of-service (QoS) metrics in order to plan for growth, minimize risk and justify additional investments. And once they’ve migrated to more complex, federated SOA systems, they must evaluate service level goals over extended periods of time, across continuous and discontinuous processes and prioritize shared Web services resources by relevant business context—such as customer type, product line or business unit.

Exception Management

In services-based systems, exceptions and errors that occur at runtime can have far reaching impact, but yet be hard to pinpoint the root cause. Errors in a single, shared service can adversely impact many different business processes and customers. AmberPoint helps to solve this crippling issue by enabling organizations to manage all types of exceptions—from simple data entry errors to complex business conditions, such as orders lost in processing. It provides centralized visibility into system-wide services-based interactions. It scans messages to detect user-defined exception conditions, alert individuals and other systems and route exceptions to an automated handler based on user-defined rules. It enables users to assess the business impact of exceptions and the services impacted the most.

SOA Security

AmberPoint products help to provide a secure environment for distributed, service-oriented applications. They integrate with existing security infrastructure to address requirements for authentication, authorization, integrity, confidentiality and non-repudiation.

  • Content-based security policies for XML-Signatures, XML-Encryption and authorization
  • Bi-directional, distributed enforcement with centralized control
  • Comprehensive solution compliant with WS-Security standards
  • Provision existing security infrastructure as needed, including platforms, ID management vendors and XML firewalls

Back to SEL Main Page

 
 
   Privacy Statement    Legal    Contact Us