NetWorld UK - Home

   

Home

About Us

Customers

Webinars

Search Site   

 

 

                             I Catalogue I    I Support I   I Downloads/Pricing I   I Customer Area I

DeviceWall Software - From Centennial - Protecting your data from inappropriate use

Endpoint Security: Devices, Data and Desktops

 

DeviceWall from Centennial Software

 

 

 

DeviceWall 4.0 - Security Product of the Year 2006 - Techworld AwardsCSIA Claims Tested logo

Product Overview

 

Book a Free WebinarIf you care about data security, you need DeviceWall to prevent the unwanted transfer of files from company PCs to unauthorised local and wireless connections.

 

Centennial DeviceWall® helps protect your data, both on and off the network, by:

  • preventing the transfer of files to or from unauthorised portable devices

  • automatically encrypting data copied to approved devices

  • providing complete audit trails of device and file accesses

Device Control

DeviceWall prevents the unwanted transfer of data to or from portable devices such as USB flash drives, iPods, PDAs - and even wireless connections by automatically enforcing security policies. User access can be blocked, limited to read-only or left unrestricted according to the individual’s security privileges and device type in use.

 

Encryption

DeviceWall can automatically encrypt all data copied to authorised storage devices such as USB flash drives.

 

Using the latest Blowfish and AES 256-bit ciphers, DeviceWall ensures that even if data is lost in transit, it won’t create a costly and embarrassing security breach.

 

Access Auditing

DeviceWall provides complete visibility of all user and administrator actions, recording everything from individual device connections to the most popular files accessed on portable devices. A full audit trail of administrator actions helps ensure compliance with security management policies.

Regardless of whether the device is connected locally or wirelessly, if the PC is on the corporate network or offline, DeviceWall constantly manages device connections to ensure the integrity of your network is not compromised.

 

DeviceWall – Protection through strength and flexibility:

  • Complete device control – of all types of portable storage device, local and wireless connections.  Create device white lists with the Policy Customiser

  • Total auditing – of all device connections and attempted data transfers.  Tabular and graphical reports make it easy to monitor user behaviour

  • Encryption – super strength 256-bit encryption built-in, with choice of global and personal keys

  • Single-screen admin – all administration is done through the central policy Control Centre, including policy creation, distribution and reporting

  • Temporary access – react to special circumstances with time-limited access to devices, even when the PC is away from the network

Product Features

 

Supported Device Classes

 

With the vast majority of desktop and laptop PCs now featuring various disk writers and high-speed data ports, it has never been easier for a user to deliberately or accidentally remove sensitive data, introduce malicious code or transfer inappropriate content.

 

To guard against these risks, DeviceWall actively manages the connections that can be used to transfer data to and from the PC, such as:

 

DeviceWall Control CenterDeviceWall simplifies the task of controlling which devices can be connected to a PC by grouping them into the following classifications:

  • Encrypted USB Storage Devices

    • USB Flash Drives

  • Storage & Imaging Devices

    • USB flash memory / disks
    • DVD/CD -Rom Drives
    • Digital Media Players (iPod, MP3 etc)
    • Scanners
    • Digital Cameras and CompactFlash cards
    • Multi-Device USB Sticks
    • Diskette drives
  • PDAs

    • Blackberry (and other RIM devices)
    • Pocket PC's and Windows Mobile (includes: iPAQ, AXIM etc)
    • Palm OS devices (includes Zire, Tungsten, Treo, Clie etc.)
    • Smart Phones
  • Wireless Lock Down

    • Infra Red

    • Bluetooth

    • Wi-Fi Ports

  • Other

    • Other Disk Based Plug & Play storage (includes: portable hard drives etc.)

DeviceWall enables the policy to be set for each individual device class.

 

Managing wireless connections

 

With wireless data ports now a standard feature on many laptops and even desktops, organisations need to take steps to prevent these access points being used to transfer data to or from corporate-owned PCs.

 

DeviceWall provides managers with the means to disable any on-board wireless data ports including Wifi, Bluetooth and Infra Red.

 

DeviceWall - Managing wireless connections
Unlike the USB ports - where complete lockdown would also prevent connection from human interface devices - wireless connections tend to only be used to transfer data, so disabling these ports is an effective security measure

 

Organisations also need to determine what are the legitimate reasons why certain individuals may need access to any specific type of device. Once you know these exceptions you should quite simply block all other scenarios from occurring.

 

Determine your permissible use policy and then isolate your company from the accidental or malicious use for the rest. By controlling access to these devices and more, DeviceWall will substantially reduce the security risk of non company devices interfacing with your network.

Top

User/Group based Policies

 

DeviceWall enables administrators to enforce security policies based on users rather than just PCs.

 

This means that user without security clearance cannot use a more senior member of staff’s machine to access certain devices – while also ensuring that employees such as senior managers take their privileges with them wherever they go in the enterprise.

 

The DeviceWall Access Control List (ACL) allows administrators to quickly determine which device permissions to apply to any user or group across the network.

 

DeviceWall - Permissible Users
Permissible Users

 

Organisations need to understand that some users will have a legitimate requirement to use certain classes of device. A ‘Permissible Use’ table can help define these needs and determine how privileges in DeviceWall are allocated to different user groups

 

 

Do these sample employee groups require access to the following classes of device?

 

User/device

USB Sticks

PDA

CD Writer

IT Admin

YES/Read Only

No

YES/Full Access

Field Sales

No

YES\Full Access

No

Finance

No

No

No

General Users

No

No

No

Marketing

No

No

Yes/Read Only

 

Silent’ or ‘High Visibility’ modes

DeviceWall allows organisations to choose if the solution should run in the background, simply stopping the connection of unauthorised  device types, or whether they want to proactively remind users of the security restrictions that apply to them. In ‘silent’ mode, DeviceWall runs with no user alerts or notifications (other than standard Windows dialogues). In ‘high visibility’ mode, DeviceWall notifies users of their privileges both a log-on and if an attempt is made to connect a blocked device.

 

Active Directory support

For those organisations who have already invested in Active Directory, DeviceWall will seamlessly integrate with existing user groups to populate the Access Control List as well as provide full browsing of computers, users and user groups.

 

DeviceWall integrates with Active Directory to enable the Access Control List to be managed as well as to allow computers, users and user groups to be browsed for deployment of the client service.

 

Top

Giving Temporary Device Access

 

DeviceWall is designed to provide the highest levels of security without impacting on business productivity. As such, it provides the flexibility to quickly react to exceptions where a user may legitimately require access to a normally restricted device.

 

Online Users

For users connected to the network, the administrator simply updates the policy for the affected user, granting temporary access to the specified class of device.

 

DeviceWall - Temporary Device Access
Offline Users

There will inevitably be times where an off-site employee, with no access to the network, needs access to a blocked device. In these instances, DeviceWall has a special mechanism to permit temporary access to a specified device type until they end their current Windows session.

 

 

The combination of an effective security mechanism plus the capability to handle one-time exceptions means that DeviceWall is the ideal solutions looking to protect the integrity of the network with affecting business productivity.

 

The process of granting temporary permissions creates an audit log entry which records the person to whom one-time privileges were given, what type of device was unblocked and why. The audit log is time-stamped and maintained for subsequent review.

 

Granting Temporary Access

 

A User that is denied access to a Device Class can be granted "Temporary Access" using the DeviceWall Temporary Access Tool. The Temporary Access Tool can be launched from the Windows Start Menu, or from the Tools Menu in the DeviceWall Control Center.

 

Temporary Access can be granted simultaneously to up to 3 specific Device Classes, or to all Device Classes.
Temporary Access can be set to last until the user ends his current Windows session, or it can be set to begin and end at specific times.

Top

USB Data Encryption

 

To ensure that data copied onto a USB flash drive doesn't end up in the wrong hands.

 

DeviceWall offers the option to automatically encrypt all files as they are transferred from the PC. The encryption process is transparent to end users and has no negative effects on employee productivity.

 

Using a choice of industry-standard 256-bit AES and Blowfish encryption ciphers, DeviceWall can transform any USB flash drive into a secure means of transporting sensitive company and customer information.

 

Data on a DeviceWall-encrypted device can only be accessed through a PC carrying the organization’s unique DeviceWall keycode – preventing files from being accessed on non-authorised systems or networks.

 

Encryption Considerations

 

DeviceWall’s 256-bit data encryption is super-secure. So secure, in fact, that if you lose your key, you won’t be able to retrieve any data from the USB flash drive. Ever.

 

Likewise, reformatting a device will delete any data already resident on it.

 

As such, Centennial Software strongly recommends that encrypted USB flash drives are ONLY used to transport COPIES of files between locations or PCs. An encrypted USB flash drive must never be the sole means of data back-up or be used to hold the only copy of sensitive files

Top

Audit Log:

 

To ensure you can track security policy enforcement, DeviceWall automatically creates a permanent audit trail of all policy deployments, changes in privileges and temporary access rights.

 

Device Access Auditing Overview

 

Centennial DeviceWall* maintains an "audit log" of Device Access for users on the network. The audit log data is stored centrally in an SQL database and can be viewed and exported via the Centennial DeviceWall Control Center.

 

The data recorded includes:

  • The class of the device connected to a computer.

  • The time and date at which the connection occurred.

  • The user who was logged in at the time.

  • The computer on which the connection occurred.

  • Whether access to the device was allowed (authorized) or blocked.

  • For disk-like devices, details of the files that were accessed or copied to and from the device.

File Access Audit

 

Automatically log file movements to monitor user activity and reduce the risk of data leakage.

 

In addition to the existing comprehensive and intuitive auditing of supported device connections

and policy changes, DeviceWall 4.5 will introduce the ability to automatically audit user attempts

to read/write, delete or rename files on portable devices*.

 

Data recorded by DeviceWall will be reported in the policy control centre and will comprise:

  • Device class

  • File name accessed

  • Access type (read/write/rename/delete)

  • Date/Time of access

  • User accessing the file (may be different to currently logged-in user)

  • Process used to access file (e.g. notepad.exe or explorer.exe)

  • Was attempted access allowed or blocked

DeviceWall 4.5 will automatically audit all supported file actions, or administrators can manually

select the processes and file types to be monitored.

 

* Applies to Windows 2000/XP/2003, File Transfer Audit is not supported on Windows NT. Local system users not supported.

 

Tracking DeviceWall Deployments

 

Each time DeviceWall is installed or updated on a PC, a record is automatically kept in the control centre. This audit trail can be reviewed at any time to help administrators check the policy and client software running on a PC currently or at a previous point in time.

 

Recording Temporary Access Rights

 

When a user is granted temporary access to particular device type, DeviceWall enables administrators to log the user, device type and reason for exception. This entry is then time-stamped and stored in the audit trail for later review.

Top

Deploying the Client Agent

 

The IT system administrator simply installs the software and sets up a policy defining the trustees, any authorised user and/or groups of users selected from Active Directory using the DeviceWall control centre which operates as a remote deployment tool.

 

DeviceWall Deployment ScreenAn access control list is built up consisting of the trustees who are set permissions, either being ‘allowed’, "read only" or ‘denied’ access any supported device class(es).

 

The Client service is then deployed from the DeviceWall control centre, across all computers to which control of the use of the supported device classes is required. With just a few clicks from the control centre your entire PC network can be updated with policy enforcement instructions.

 

If an unauthorised  user subsequently attempts to perform an operation for which he or she does not have the necessary permissions set, DeviceWall blocks access to the device and Microsoft Windows displays an ‘Access Denied’ error dialog - the unauthorised user is unable to proceed.

 

Policy Updates

DeviceWall clients automatically check for updates when a user logs on to the network or at configurable time intervals (the default setting is every six hours), so there is no administrative overhead involved in ensuring that all clients are running the latest version of the security policy.

 

Updating The Client Software

DeviceWall has an intuitive console that identifies the current version of the client software deployed on each PC it protects.

 

A simple one-click process enables the Administrator to push a client update to selected users / machines.

Top

Technical Specification Guide

 

Server

  • Processor: Pentium Class

  • Memory: Minumum 128MB

  • Disk Space: Minumum 512MB

  • Operating System: MS Windows 2000, XP, 2003 (32-bit editions)

  • Database: MS SQL 2000, 2005, 2005 Express

Client PC's

  • Operating System: MS Windows NT, 2000, XP, 2003

  • Hardware Requirements: DeviceWall will work on any machine capable of supporting the above operating systems

Control Centre

  • MS Windows 2000/2003/XP

  • Requires MS IIS 5 or later

Network Environment

  • Apache Web Serer (Supplied), Microsoft IIS 5.0+

  • Active Directory is recommended, but not required

Real-time Access Rights and unattended policy updates

These features uses MS IIS to automatically update the client service when a policy update is made by the administrator. This ensures simple and rapid deployment across network with minimal interruption to users.

 

Transparent network deployment

Client software can be silently deployed without interrupting user

Top

 

DeviceWall Free Trial Download

 

Download Free Evaluation/Trial Download

 

Download the full Centennial DeviceWall product limited to a  30 Day Evaluation Key, see for yourself why so many  organisations rely on Centennial DeviceWall to protect their electronic data.

 

The Evaluation Copy can be installed on a Live or Test Environment allowing for full product review to take place.

 

An activation key will be sent to you by email once you have completed the download request.. 

 

To continue downloading the Evaluation version please Click Here 

 

______________________________________________________________________________

 

If you have any difficulties downloading please contact our on support department 

or telephone 024 76 456174

 

 

 

 

 

 

 

DeviceWall Pricing Models:

 

Purchasing Licences -Options  Support Contract Pricing  On-Line Price Guides and Requests

 

Centennial Software offers several pricing models. These models are designed to offer organisations the option of purchasing the Centennial DeviceWall Software in the manner that best suits the organisations buying criteria or project requirement.

 

Purchasing Models Available:

  • Outright Purchase - with 12, 24, and 36 months support contract option.

  • Project Licences - 30 or 90 days includes support for duration purchased (Project Licences can be upgraded to a full licence and will be reduced by 50% of the cost of the projects licences paid and the outright purchase cost of either the Std or Web Editions).

  • Annual Subscription - licences are provided at a reduced cost than the outright purchase option and include support for the subscription period. (Annual Subscription licences can be upgraded to a full licence by paying 60% of the outright purchase cost)

  • Public Sector Pricing is available for both outright purchase and annual subscription licences.

Top

Support Contract Pricing:

 

Support and Maintenance contracts are available over either a 12, 24, and 36 Month Periods

 

Support and Maintenance costs are based on the current retail price per licence and are calculated using an agreed % rate for the period required.

 

Product Support Includes:

  • Telephone Technical Support

  • E-mail Technical Support

  • Access to Centennials On-Line Knowledge Base of Known Problems and Solutions

  • Full Provision of Product Version Upgrades

  • Full Provision of Product Minor Updates

  • Access to Centennial Discovery Software User Group and Forum

Please note that expired contract rates differ from the usual rates, NetWorld UK would be pleased to provide you details on request. Contact NetWorld UK Sales regarding renewal or expired rate support and maintenance contracts. click here

Top

 

On Line Pricing Requests:

 

Want an idea of the Centennial DeviceWall Software costs for your organisations IT environment?

 

NetWorld UK offer you the facility to obtain an immediate On-Line Price Guide based on the Outright Purchase costs, please use the following links: 

If you require a formal quotation please use e-mail our sales department using the following link:

A NetWorld UK representative will forward your quotation to the e-mail address you provide.

 

Centennial DeviceWall Product Training and Consultancy:

 

NetWorld UK provide full installation/implementation and product training which will enhance the customer experience of using the Centennial DeviceWall Software.

 

Although we do not mandate any of our services as a purchase requirement, for those organisations wishing to take advantage of our experience and expertise with this product we would be pleased to provide full details and costs of all our service.

 

Please See the Services Tab at the top of this page to review our service offerings:

Top

 

Centennial DeviceWall Services

 

Standard Support and Maintenance Contracts

Centennial Certified Engineers

Support and Maintenance contracts are available over either a 12, 24, 36, 48 and 60 Month Periods

 

Support and Maintenance costs are based on the current retail price per licence and are calculated using an agreed

% rate for the period required.

 

Product Support Includes:

  • Telephone Technical Support

  • E-mail Technical Support

  • Access to Centennials On-Line Knowledge Base of Known Problems and Solutions

  • Full Provision of Product Version Upgrades

  • Full Provision of Product Minor Updates

  • Access to Centennial Discovery Software User Group and Forum

Please note that expired contract rates differ from the usual rates, NetWorld UK would be pleased to provide you details on request.

 

If you would like NetWorld to provide you a quotation for renewal of your support and maintenance agreement please click here:

 

Click Here For Our Support Desk Contact Details:

 

DeviceWall Training

 

Centennial Certified EngineersNetWorld UK offer a range of hands-on bespoke on-site Centennial DeviceWall Training workshops designed specifically using the clients actual Centennial DeviceWall Installation . The courses cover User and Administrator training and included the following elements: 

 

User/Administrator Training 

 

Overview:

This course is designed to meet the needs of both Support Management and Staff who Administer the

 

Centennial Discovery Software Application and thus require detailed Technical Knowledge of the structure of the application to ensure successful usage.

 

The course will detail all aspects of the Centennial Discovery Application. Upon completion of the course delegates will have a good working knowledge of the Centennial Discovery Application. 

 

Course material (Tailored Training Manuals) will be provided electronically.

 

Duration: 2 Days (1 Day On Client Site, 1 Day Off Site for Document Preparation)

Cost: £negotiable per day per 4 delegates + Travelling and Subsidence

Course Code: CDSDW001

Topics covered include:

  • Installing the application software

  • Overview of Screens

  • Working with Views

  • Setting Alert Options

  • Deploying the client software

  • Policy Configuration

  • Understanding the audit result files

  • Report Reviews

  • Exporting data

  • Device Configurations

Pre-requisites:

All delegates must have good technical understanding of computer technologies and terminologies

 

Contact Us regarding Centennial Bespoke User/Administrator Training

 

Top

 

DeviceWall Consultancy

NetWorld UK - Professional Consultancy Services.

 

Centennial Certified Engineers

NetWorld UK's technical staff are all Centennial Certified Engineers.

 

NetWorld UK are therefore, able to provide highly trained experienced Technical Consultants whom are qualified to customise the DeviceWall Software and offer suggestions based on their experiences of previous audit projects.

 

Please see below for a sample of the Technical Services NetWorld UK provide, although none of these services are mandatory we would recommend a detailed discussion with one of our Pre-Sales Consultants before commencing any Software Purchase.

 

 

NetWorld UK Centennial Software Consultancy and Product Training Services are offered as either daily services or packaged solutions dependent on the level of expertise and available resources within client organisations.

 

1) Project Planning (Pre, During & Post Project Implementation)

2) Software Installation

3) Software Customisation

4) Pilot Audit (Test Environment Prior To Live Roll Out)

5) Skills Transfer (Product Training- See further up this page)

7) Administration Training (Product Training- See further up this page)font>

8) End User Training (Product Training - See further up this page))

9) Documented Completion Report

 

Contact Us regarding Centennial DeviceWall Software Professional Services

 

Top

 

Centennial DeviceWall FAQ's

 

______________________________________________________________________________________

 

Q: What is DeviceWall?

A: DeviceWall is a software solution designed to give organisations control over unauthorised use of specific portable devices (Flash Storage Disks, Mobile Phones, PDA's, Music Players etc) based upon user profiles.

Top

______________________________________________________________________________________

 

Q: Which devices does DeviceWall support?

A: DeviceWall can actively manage a wide range of devices such as PDAs, iPods and other music players, USB sticks and external storage devices (including CD writers, Zip drives and external hard drives). DeviceWall also manages internal diskette and optical (CD and DVD) drives.

Top

______________________________________________________________________________________

 

Q: Which platforms does DeviceWall support?

A: DeviceWall works with the most common enterprise IT operating systems, Windows NT4, 2000, XP and 2003. DeviceWall does not currently support earlier versions of Windows or non-Windows operating environments.

Top

______________________________________________________________________________________

 

Q: How does DeviceWall work?

A: DeviceWall is an innovative solution that applies security policies selectively to specific classes of device. If a user attempts to access a blocked device, such as a USB drive, Windows will simply generate an Access Denied message. Access policies (or Access Control Lists) in DeviceWall are managed directly from a single Control Centre.

Top

______________________________________________________________________________________

 

Q: How will DeviceWall be installed?

A: The DeviceWall Client Service must be installed on every computer where control of devices for user access is required. DeviceWall installs the Client Service seamlesslessly from a centralised management console on the server (the DeviceWall Control Centre), without any interruption to the user. IT administrators can manage and deploy the DeviceWall Client Service on every computer in their network from the Control Centre. The administrator simply sets the permissions required to allow or deny the user or groups of users (forming an Access Control List) and simply deploys the service.

Top

______________________________________________________________________________________

 

Q: Do IT Administrators need to manually connect to each computer in the network to make changes to permissions?

A: No. DeviceWalls unique Control Centre technology enables this procedure to be achieved centrally simplifying the process.

Top

______________________________________________________________________________________

 

Q: Can users disable DeviceWall once a permission has been set?

A: No. Only IT administrators have the authority to control the permissions according to their network set-up and configuration. They should ensure users do not have the authority to make administrative changes.

Top

______________________________________________________________________________________

 

Q: Can DeviceWall be remotely deployed?

A: Yes. Administrators can perform this procedure from the Control Centre. Permissions can only be set from the Control Centre.

Top

______________________________________________________________________________________

 

Q: Does DeviceWall manage users or PCs?

A: Devicewall enables administrators to set permissions to access various classes of portable media device by users or groups of users. The actual computer upon which the client is installed will allow permitted users to access permitted devices but will block any activity by unauthorized users.

Top

______________________________________________________________________________________

 

Q: Can DeviceWall protect users computers who are offline and not on the network?

A: Yes. The security policy applied to a user is valid regardless of whether the PC is connected to the network or not.

Top

______________________________________________________________________________________

 

Q. Can DeviceWall enable a policy to be updated quickly if a legitimate need arises?

A. Yes. An updated policy can be instantly pushed to a PC in the instance of a normally-restricted user needing legitimate access to a certain device. Where the PC is not connected to the network (i.e it is Ôoffline), DeviceWall has the capability to grant one time access to a specific class of device until the end of the current Windows session. This unique feature means that organisations can maintain a high level of security by default while still reacting quickly and effectively to exceptional requirements on a case-by-case basis.

Top

______________________________________________________________________________________

 

Q: Does DeviceWall work with Microsoft Active Directory?

A: Yes. DeviceWall integrates with Active Directory to enable the Access Control List to be managed as well as to allow computers users and user groups to be browsed for deployment of the client service. However, Active Directory is not a