4-page Case Study - Posted 6/20/2007
Views: 420
Rate This Evidence:
Energy Services Company Improves PC Security with Easy-to-Manage Solution
ConEdison Solutions provides energy and energy services to a range of commercial and residential customers in 10 states and Washington, D.C. The company, which has about 110 employees, needed better technology for protecting its personal computers from e-mail viruses, spyware, and malicious software that can be inadvertently downloaded from Web sites. To enhance its security, ConEdison Solutions deployed Microsoft® Internet Security and Acceleration (ISA) Server 2006 along with SurfControl Web Filter for ISA Server. The solution provides a powerful, easy-to-manage proxy server and Web filter. The company's computers now have better protection from Internet threats, and the solution gives the IT staff tools for easily managing security procedures and for distributing reports that provide a clear understanding of the effectiveness of the company's Internet security.
Situation
 |
With ISA Server and SurfControl, we have solid protection in place, and being able to clearly see what is going on gives us confidence in our ability to keep malicious code out of our systems.  |
|
|
Frank Lulgjuraj Senior Systems Security Specialist ConEdison Solutions |
|
|
ConEdison
Solutions provides a range of energy procurement and management services to corporate and government customers to help them manage their energy needs, and provides similar services to residential and small business customers. With customers in 10 states and Washington, D.C., ConEdison
Solutions offers services such as lighting upgrades; installation and replacement of heating, ventilation, and air conditioning (HVAC) systems; and upgrades for power systems used by large organizations.
ConEdison Solutions has about 110 employees, including staff at its headquarters in White Plains, New York, and in regional offices, as well as a mobile sales force. The company has approximately the same number of personal computers in use, including workstations and portable computers.
In the past few years as viruses, malicious software, and spyware have become more prevalent, the security of the company’s computers had become a concern. The company’s IT department sought technology that could provide better security to protect against malicious code.
Moreover, the company wanted technology that could streamline the way the IT department managed computer security. For example, the IT infrastructure staff was spending a lot of time manually maintaining lists of prohibited Web sites and scrolling through logs to determine whether spyware existed on company computers.
ConEdison Solutions had some successes in enhancing security by running Microsoft® Internet Security and Acceleration (ISA) Server 2000, which had been in place since 2001. However, the growth of malware was making it increasingly difficult for the company to maintain a secure computer environment.
“A primary driver of our business is helping our customers use energy wisely,” says Frank Lulgjuraj, Senior Systems Security Specialist for ConEdison Solutions. “When we were evaluating the issue of computer security and discussing the problem with our executive management, we explained our thinking with a comparative analogy: The security issues we were encountering on our computers were interfering with the effective use of the energy of our employees for adding value to our company’s bottom line. Our goal was to use our employees’ energy wisely with better technology.”
Solution
ConEdison Solutions decided to deploy Microsoft Internet Security and Acceleration (ISA) Server 2006, an edge security gateway that helps protect IT environments from Internet-based threats. ISA Server 2006, a part of the Microsoft Forefront™ line of business security products, helps ConEdison Solutions protect its computer environment from Internet-based threats. Features include a hybrid proxy-firewall architecture, deep content inspection, granular management policies, and alerting and monitoring capabilities.
ConEdison Solutions also decided to deploy SurfControl Web Filter for ISA Server, a plug-in for the Microsoft product. Full integration of Web Filter from SurfControl, a Microsoft partner, extends the value of both products through administrative efficiency and multilayered protection technologies.
The solution delivers:
- The ability to continually monitor and analyze emerging Internet-based threats from the Web, and from e-mail, spyware, and malicious code.
- Functionality that stops viruses at the company’s Web gateway, thus preventing potentially crippling damage to the ConEdison Solutions network.
- A rules engine that lets ConEdison Solutions IT staff establish Internet use policies company-wide or for individual employees or departments.
- Rich reporting capabilities that provide visibility into internal and mobile Web use.
ConEdison Solutions deployed ISA Server 2006 along with SurfControl Web Filter in January 2007.
Benefits
By deploying ISA Server 2006 with SurfControl Web Filter, ConEdison Solutions has been able to enhance the security of its computer assets. The combined solution provides an easy-to-manage proxy server and Web filter that offers greater security from malicious code residing in e-mail messages or on the Web. It also offers the IT staff easier management of Internet security tasks, saving time that can be redirected to other work. And the solution’s rich reporting capabilities allow the IT staff to provide management with clear, easy-to-understand summaries of the state of the company’s computer security.
 |
By using ISA Server 2006 as the proxy server and making our computers the proxy clients, we can add a layer of protection for the computers against potential threats on the Internet.  |
|
|
Frank Lulgjuraj Senior Systems Security Specialist ConEdison Solutions |
|
|
Provides Greater Security
The combined features of ISA Server 2006 and SurfControl have increased the level of security provided to the computers on the ConEdison Solutions network.
“I’ve always been a big proponent of separating the layers of a network,” says Lulgjuraj. “By using ISA Server 2006 as the proxy server and making our computers the proxy clients, we can add a layer of protection for the computers against potential threats on the Internet.”
Since the solution was deployed in early 2007, Lulgjuraj says there have been a couple of incidents when access to certain Web sites was blocked. “Even though we thought these particular sites were benign, the security solution blocked access because it found malware,” Lulgjuraj says. “Seeing this kind of responsiveness to a potential threat makes me feel a lot more comfortable that our users are protected.”
The ISA Server and SurfControl solution also has blocked thousands of attempted spyware infiltrations since ConEdison Solutions deployed it. “In February 2007 alone, ISA Server and SurfControl blocked 638 connection attempts, with most of those coming from normal Internet surfing,” says Lulgjuraj. “Using spyware as the metric, we can see the improvement and the payoff of using the ISA Server and SurfControl combination.”
Simplifies Management Tasks
Lulgjuraj says that management tasks using the ISA Server and SurfControl products are straightforward and have simplified the routine chores that the ConEdison Solutions IT staff performs.
For example, the URL Category list in SurfControl Web Filter allows ConEdison Solutions administrators to easily set up lists to block Web sites that are known spyware hosts. By using the SurfControl Rules Administrator, the IT staff can easily customize Web filtering activities by time of day, browse time, or bandwidth allowance, to meet the needs of different users and groups.
They can also establish rules to prevent access to sources of spyware infection, such as peer-to-peer file sharing or potentially harmful downloadable files that have .exe or .vbs extensions.
“What is helpful is that the solution is also very easy to use,” says Lulgjuraj. “The steps to set up and modify both ISA Server and SurfControl are very intuitive. I can explain to one of our junior staff members in a short amount of time how to perform specific tasks, and they can take over.”
Offers Clear, Easy-to-Understand Reporting
The company is also benefiting from the rich reporting capabilities of the solution. Lulgjuraj set up weekly e-mail reports that are distributed to top management showing Internet content that has been blocked by the ISA Server and SurfControl software.
“The reporting capabilities have helped me make a strong business justification to our management that the solution has been worth the investment,” Lulgjuraj says. “The reports are easy to understand, and we’ve been able to obtain very accurate pictures of the potential risks posed by our Internet use. That, in turn, helps us to contain those risks so there is greater security for our users.
“In corporate environments, you cannot always be aware of how people are using the Internet,” he adds. “With ISA Server and SurfControl, we have solid protection in place, and being able to clearly see what is going on gives us confidence in our ability to keep malicious code out of our systems.”
With ISA Server and SurfControl, ConEdison Solutions IT staff members are now more productive. “We are able to refocus our energies to more productive tasks,” Lulgjuraj says, “rather than battling slow computers because of spyware.”
For More Information
For more information about Microsoft products and services, call the Microsoft Sales Information Center at (800) 426-9400. In Canada, call the Microsoft Canada Information Centre at (877) 568-2495. Customers who are deaf or hard-of-hearing can reach Microsoft text telephone (TTY/TDD) services at (800) 892-5234 in the United States or (905) 568-9641 in Canada. Outside the 50 United States and Canada, please contact your local Microsoft subsidiary. To access information by using the World Wide Web, go to:
http://www.microsoft.com/
For more information about SurfControl products and services, visit the Web site at:
http://www.surfcontrol.com/
For more information about ConEdison Solutions products and services, visit the Web site at:
http://www.conedsolutions.com/
Microsoft Forefront Product Portfolio
The Microsoft® Forefront™ comprehensive line of business security products provides greater protection and control through integration with your existing IT infrastructure and through simplified deployment, management, and analysis. Forefront is a comprehensive solution that helps provide protection for the client operating system, application servers, and the network edge.
For more information about the Forefront product portfolio, go to:
www.microsoft.com/forefront
This case study is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS SUMMARY.
Document published June 2007