This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject
  • RSA.com
  • Home
  • Advisories
    • SecurID
    • SecurID Governance & Lifecycle
  • Documentation
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID App
      • SecurID Authenticator for macOS
      • SecurID SDK
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
    • Technology Partners
  • Downloads
    • SecurID
      • Authentication Agents
        • API / SDK
        • Apache Web Server
        • Citrix StoreFront
        • IIS Web Server
        • MFA Agent for macOS
        • MFA Agent for Windows
        • Microsoft AD FS
        • Microsoft Windows
        • PAM
      • Authentication Engine
      • Authentication Manager
      • Cloud Authentication Service
      • Hardware Appliance
        Component Updates
      • Hardware Tokens
      • Integrations
      • SecurID Authenticator for macOS
      • Software Tokens
        • Android
        • iOS
        • macOS
        • Token Converter
        • Windows
    • SecurID Governance & Lifecycle
  • Community
    • SecurID
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
    • SecurID Governance & Lifecycle
      • Blog
      • Discussions
      • Events
      • Idea Exchange
      • Knowledge Base
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Ideas & Suggestions
      • Community Support Articles
      • Community Support Forum
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Education
    • Blog
    • Browse Courses
      • SecurID
      • SecurID Governance & Lifecycle
    • Certification Program
    • New Product Readiness
    • Student Resources
Sign In Register Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 

SecurID® Governance & Lifecycle Datareach

  • SecurID Community
  • :
  • Products
  • :
  • SecurID Governance & Lifecycle
  • :
  • Documentation
  • :
  • Datareach
  • Options
    • My Contributions
    • Subscribe
    • Bookmark
    • Subscribe to RSS Feed
    • Invite a Friend
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 

Summary

RSA IGL Data Reach is a simple, scalable solution developed by RSA Professional Services for governing and provisioning multiple databases, Windows & UNIX endpoints. It is a challenge for lot of organizations, both administratively and from a performance perspective to collect access information from large number of endpoints. RSA IGL Data Reach simplifies this by acting as a single system that collects this information that can be readily consumed by RSA IGL for performing access certification, access requests or automated joiner/ lever processes.

A video demo of the solution can be found here: Video Link : 34019 

 

pastedImage_1.png

 

Use Cases

High level use cases which can be achieved with the help of this solution are:

  • The ability to audit/govern database administrative permissions for thousands of database endpoints.
  • The ability to audit/govern Windows or UNIX accounts and group permissions for thousands of endpoints.
  • Gracefully handle database connectivity failures (with reporting on such failures that can be used to alert DBA personnel).
  • Ability to automatically de-provision sensitive database, AWS, UNIX or Windows access from terminated personnel when they leave the organization or role.
  • Allow personnel to request additional access for themselves, a subordinate, or service account.

Collections

Here is an overview of how RSA Data Reach collections process works. Once the data is collected and staged, it can be consumed by RSA IGL to perform access requests, certifications and reporting.

PradeepKadambar_0-1616782505826.png

 

 

Provisioning

PradeepKadambar_1-1616782536857.png

 

 

Request a demo

Please contact your local Sales contact for more info and/or a demo.

 

Alternative you can reach out to us @ rsa.identity.ps.global.mailbox@rsa.com 

Architecture

pastedImage_1.png

 

Components

 

Master Controller is the component responsible for serving as a central configuration point. All agent configurations, drivers, certificates and data to be collected are centrally managed on the Master Controller. The Master Controller is also responsible for collating the data collected by all the agents, error handling and piping data to the Oracle database.

Agents are responsible for collecting data from endpoints. These endpoints can be any JDBC compliant databases, AWS, UNIX or Windows systems.

Database stores all the data and metadata collected from the target systems.  All the pruning and data validation stored procedures are contained in this database. Data Reach requires an Oracle 11g or above database for staging the collected data. This can be a standalone Oracle database, or the database used by RSA IGL.

Plugins provide optional integrations with third party system for host configurations (CMDB), credentials (PAM) and ticketing systems for error handling. The plugin architecture allows Data Reach to maintain a small footprint and features added as needed.

 

3rd Party Integrations

 

pastedImage_1.png

Host List Providers (Targets)

  • ServiceNow
  • JDBC

Credential Providers (Credentials)

  • HashiCorp Vault
  • Thycotic Secret Server
  • ManageEngine Password Manager Pro
  • Local (CSV)
  • CyberArk

Error Handlers (Error Reporting)

  • ServiceNow
  • Zendesk Support
  • Jira Service Desk
  • Slack

 

Deployment Types

 

Single Server In this scenario, all 3 components are installed directly on your IGL application server.

Agent, Local Database In this scenario, the master controller and the database are installed on the IGL application server, while agents are deployed throughout your environment.

Agent, Dedicated Database In this scenario, agents are deployed throughout your environment.  The dedicated Oracle database instance separate from IGL must be provided by the organization. In this deployment, the master controller can be installed on any of the systems.

 

Feature Releases

 

Feb 2021 - Support for collecting AWS IAM information for multiple AWS accounts under multiple AWS Organizations.

 

Dec, 2020 - Out of the box collection package for MongoDB accounts.

 

Jul, 2020 - Out of the box collection package for Solaris accounts and group entitlements.

 

Jun, 2020 - Support for CyberArk Central Credential Provider (CCP) as a supported credential provide plugin.

 

Jan, 2020 - Out of the box collection package for AIX accounts and group entitlements.

 

Dec, 2019 - Multi Windows provisioning service.

 

Roadmap

 

Q1 2021

AWS Bulk Collections Support - Data Reach will support collection of IAM data from multiple accounts under a one or more organizations. This will allow accounts to be dynamically available for collections. The collections will support the following data elements

  • Accounts
  • Account Policies (Inline and Managed)
  • Groups
  • Group Policies (Inline and Managed)
  • Group Members
  • Roles
  • Role Policies (Inline and Managed)
  • Policies

 

Q2 2021

Support provisioning micro services

Support Model

RSA Datareach follows the Custom Application Support (CAS) model.

For more information please contact your local sales team

Sales Questions

How do I find out more? Please contact your local sales team or email: rsa.identity.ps.global.mailbox@rsa.com
I am only a small customer, can I still take advantage of this service? Yes absolutely, regardless of your company size, RSA Data Reach can add value. Please contact us to discuss your use case and book in a demo.

Does RSA Data Reach come with maintenance or a support contract? 

Yes, RSA Data Reach follows the Custom Application Support (CAS) model.

If you have any questions, please contact us: rsa.identity.ps.global.mailbox@rsa.com

Question Answer

 

General Questions

Is Data Reach a replacement for OEM StealthAudit? Data Reach is intended to be a complementing solution to OEM StealthAudit. While OEM StealthAudit mainly focuses on unstructured data, Data Reach handles structured data from databases, Windows and UNIX systems.
Is Data Reach included as part of RSA IGL? No, Data Reach is a separately licensed product.
How long does it take to get started? On average, anything from 2 days, you can be started and running
How will RSA Data Reach help me to reduce identity risk?  

If you have any questions, please contact us: rsa.identity.ps.global.mailbox@rsa.com 

Question Answer

 

Technical Questions

What version of RSA IGL is required to run RSA Data Reach? Data Reach supports all version of RSA IGL currently supported by RSA.
What endpoints are supported with RSA Data Reach? Data Reach supports any JDBC compliant database, an SSH enabled UNIX/Linux systems and Windows Remote Management (WinRM) enabled Windows Servers.
When I upgrade RSA IGL, do I also need to upgrade RSA Data Reach? No, RSA IGL version upgrades or patching does not require an upgrade to Data Reach.
Can RSA Data Reach be run on AWS/Azure? Yes, Data Reach can be deployed on any Linux operating system. If deployed on AWS or Azure, the Data Reach agents must have a network path to the target systems.

If you have any questions, please contact us: rsa.identity.ps.global.mailbox@rsa.com

Question Answer

Getting Started

Technical Info

Support

FAQ

Product Resources

  •   Advisories
    •   Product Advisories
    •   Security Advisories
    •   Technical Advisories
  •   Blog
  •   Community Exchange
    •   Integrations
    •   Recipes
  •   Discussions
  •   Documentation
    •   Product Documentation
    •   Datareach
    •   G&L Cloud
    •   Integrations
  •   Downloads
  •   Events
  •   Ideas
  •   Knowledge Base
  •   Partner Hub
  •   Training
  •   Videos

Most Popular Posts

No Popular Blog Posts available

Cloud Application Integrations
Upgrading Data Reach Components
Dec 13, 2021
DataReach Platform DataSheet
Jul 1, 2021
RSA IGL Datareach - FAQ
Mar 26, 2021
RSA IGL Datareach - Technical Info
Mar 26, 2021
RSA IGL Data Reach - Getting Started
Mar 26, 2021
View All
Videos
RSA IGL Datareach - overview and product demo
Sep 26, 2019
View All
Labels
  • Videos 1
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • Customer Success
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Provide Feedback
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.