Thursday, February 20, 2014

Istanbul-based Finansbank Manages Risk and Security Using HP ArcSight, Server Automation

Transcript of a sponsored BriefingsDirect podcast on how a large Turkish bank uses HP server tools for rapid applications deployment while ensuring heightened security.

Listen to the podcast. Find it on iTunes. Download the transcript. Sponsor: HP

Dana Gardner: Hello, and welcome to the next edition of the HP Discover Podcast Series. I’m Dana Gardner, Principal Analyst at Interarbor Solutions, your host and moderator for this ongoing sponsored discussion on IT innovation and how it’s making an impact on people’s lives.

Gardner
Once again, we’re focusing on how companies are adapting to the new style of IT to improve IT performance and deliver better user experiences, and business results. This time, we’re coming to you directly from the HP Discover 2013 Conference in Barcelona.

We’re here the week of December 9 to learn directly from IT and business leaders alike how big data, mobile, and cloud, along with converged infrastructure are all supporting their goals.

Our next innovation case study interview focuses on Finansbank, an Istanbul-based bank, and how they better manage risk. To learn how, we’re joined by Ugur Yayvak, Senior Designer of Infrastructure at Finansbank in Istanbul. Welcome.

Ugur Yayvak: Thank you.

Gardner: Tell us a bit about your organization and how you're operating in terms of keeping compliance and risk issues in check?

Yayvak
Yayvak: Finansbank is one of the largest banks in Turkey and it has more than 12,000 employees and 600 branches in the country. Banking is a competitive world in Turkey, and for compliance we have to be rapid. We have to do things faster. And security is a big deal for us.

Gardner: And what sort of challenges have you had in terms of managing your systems in order to keep up with their compliance and regulatory issues and needs?

Yayvak: Because we’re a bank, we need to obey the payment-card industry (PCI) and Sarbanes-Oxley (SOX) rules. To accomplish this, we had to create some scripts to check the data on the servers. It takes lots of time to do compliance reporting. Security is a must for the servers, because of attacks. We need to be compliant and secure and we need to move fast on the server side.

Gardner: And so as you began to look for solutions to these problems, how did you come up with a solution? Where did you go for help?

Compliance and integrity

Yayvak: First of all, we needed a compliance and integrity-check solution. We did a proof of concept (POC) with three different vendors and we checked for performance, compliance, tool support, ease of use, reporting tools, and the support that the vendor would give us. After all that, we chose HP Server Automation.

Gardner: Tell us a little bit about that process. How long have you been using HP Server Automation software?

Yayvak: We’ve been using it for six months. Three months was for the implementation process, but during implementation, we created our first rules. We did some basic agent rollouts on the servers. Now, we have 90 percent coverage on all of our UNIX servers on the Server Automation site.

Gardner: Have you been experimenting with other HP products, perhaps something around service management for ongoing operations?

Yayvak: We’re using Service Management and also the ArcSight tool. We integrated Server Automation with the Service Management, ArcSight, and also Operations Orchestration to do our jobs in less time.

Gardner: What have been some of the results that you’ve seen since you've been implementing these solutions? What have you been gaining in terms of better control and how are your auditors viewing this rollout?
With the help of the Server Automation, it’s very simple and we can get the results in much less  time.

Yayvak: We’re creating monthly reports for our audit teams, and it takes less time. With the help of Server Automation, we’ve scheduled our jobs and the audit rules and reports that we want to share with our audit teams.

It takes much less time than it did before. Also, with the help of the scripts, the daily system administration tasks are very easy. Previously, we were doing everything by hand. With the help of the Server Automation, it’s very simple and we can get the results in much less  time.

Gardner: As you gain more automation for your configuration and your servers, does that offer you some advantage if should you choose to migrate to a new platform or even to a different type of hosting environment?

If there is an opportunity to take this beyond just operations into transformation, should you want to move your servers to a co-lo or a managed service provider or even a cloud provider?

Yayvak: We don’t have a plan, but maybe after using this product, we might.

Looking to the future

Gardner: What about the future? Do you have plans to move further, perhaps using ArcSight? Are there other security benefits that you have in mind?

Yayvak: One is to improve audit server automation, because there are some scripts that we’ve changed. Those changes that we’ve done on the servers must be audited. We also want to integrate Server Automation with ArcSight to track the changes that we’ve made. And if we’ve made an error, we will be alerted by the ArcSight server.

Gardner: Because you’re such a large organization with many branch offices, is there full centralization? Is this all happening in one data center or are you able to use this across a wider distribution?

Yayvak: Right now, we’re using our central data center, and also the disaster recovery site. But maybe later on, we can implement this for the branches to take care of the data servers there.

Gardner: That usually means some significant cost savings.

Yayvak: For sure.
We need to be compliant and secure and we need to move fast on the server side.

Gardner: Okay, is there anything here at the Discover show in Barcelona that is intriguing to you? What announcements or advances in the products capture your interest?

Yayvak: The new version of Server Automation came out this year, and we wanted to know what has changed. Also Finansbank will use lots of HP's products like Service Manager, Orchestration Manager, Operations Manager. This event was a good place to learn what has changed across these services.

Gardner: Well great. I’m afraid we'll leave it there. We’ve been talking about how Finansbank in Istanbul has been improving their server automation and bringing a better compliance and audit capability as a result. I'd like to thank our guest, Ugur Yayvak, Senior Designer of Infrastructure at Finansbank.

I'd also like to thank our audience as well for joining us for this special new style of IT discussion coming to you directly from the HP Discover 2013 Conference in Barcelona.

I'm Dana Gardner; Principal Analyst at Interarbor Solutions, your host for this ongoing series of HP sponsored discussions. Thanks again for listening, and come back next time.

Listen to the podcast. Find it on iTunes. Download the transcript. Sponsor: HP.

Transcript of a sponsored BriefingsDirect podcast on how a large Turkish bank uses HP server tools for rapid applications deployment while ensuring heightened security. Copyright Interarbor Solutions, LLC, 2005-2014. All rights reserved.

You may also be interested in:

No comments:

Post a Comment