>> Case Study
IBM Filenet can control security policies of a document only till the time the document is resident within its perimeter. This in other words means that FileNet only provides “access control” to its information. Access control policies only control the download and upload of information from and to FileNet respectively. Once the document is downloaded/checked-out, FileNet cannot have control over what the user does with the document (e.g. can he print, edit, copy content, and/or distribute the information?). As a result of this, security of FileNet documents can be very easily breached.
Once the document is downloaded, the FileNet system, looses complete control on the document and cannot do any kind of audit trailing on the document thereafter. Also, FileNet can make changes to the access control policies only after the document in uploaded back into the FileNet system and these changes cannot be enforced on the documents that are already downloaded or forwarded by the FileNet-user. Thus protection of FileNet documents outside of the FileNet system becomes a concern to many organizations using FileNet.
Seclore FileSecure’s Information Rights Management (IRM) connector for FileNet empowers information owners to control documents even after it is downloaded from FileNet. Before the information is downloaded, Seclore FileSecure protects the information and restricts usage to only specific users or groups (WHO), specific actions like view, print, edit, copy content & distribute (WHAT), specific time of usage like “till 19th August 2009” or “2 days” (WHEN) and also restrict the usage to specific computers and network IP addresses (WHERE) thus providing an additional layer of control and security when providing access to information outside of IBM FileNet. Seclore FileSecure’s IRM protection for FileNet, ensures that security of information outside FileNet is not breached during the entire lifecycle (creation, storage, versioning, archival, delete) of the document
In addition to the above, by providing rights management capability to FileNet, Seclore FileSecure also provides complete audit trailing of downloaded content. Seclore FileSecure can provide history tracking of the usage of the information once it leaves FileNet. Authorized actions as well as unauthorized attempts can be tracked for all documents inside and outside of the FileNet system, and thereby provide protection to FileNet documents. This helps enterprises to comply with regulatory and compliance frameworks like ISO, Sarbanes-Oxley & HIPPA. More importantly it enables organizations to trace and perform forensics on any data breaches that occur inside and outside of the organization.