ARTICLE
LOG IN
At Virtru, we believe that the ability to securely share data is essential — and that privacy is a human right that must be protected. It’s a mission we have stuck by since we started in 2011, and sees us supporting over 7,000 organisations worldwide to protect their most valuable asset, their data, with Zero-Trust security and powerful, granular policy controls that tie identity to data, everywhere it moves.
Now, Virtru is giving developers a new way to build security directly into their own applications. Our new open source project, OpenTDF, enables developers to build Zero Trust data controls directly into the apps they create. Developers can access the OpenTDF project on GitHub.
OpenTDF is a versatile security toolkit that can be used to govern sensitive data as it flows through documents, IoT sensors, video feeds, and multi-party analytics. Examples of how developers can leverage OpenTDF include:
OpenTDF is based on the Trusted Data Format (TDF), created by Virtru’s Co-Founder and CTO, Will Ackerly. TDF has long been an open spec for secure data sharing in the intelligence community, and the release of OpenTDF makes key capabilities of TDF more accessible to developers across public and private sectors, equipping them to build security and privacy into their applications from the ground up.
“Just as PDF helped accelerate digital document sharing, TDF is poised to become the standard method for securely sharing sensitive data. TDF keeps rightful owners in sovereign control of information they share regardless of file type, application of origin, or authentication mechanisms.” Will Ackerly, CTO and Co-Founder of Virtru.
We look forward to seeing what you create with OpenTDF. You can learn more about OpenTDF here. To start building, access our GitHub repo here.
cyber security, cybersecurity, open source, open-source, opentdf, security, tdf, trusted data format, virtru, zero trust, zero-trust
An official website of the United States government Here’s how you know
Best Practices to Protect Your Systems:
• Control access.
• Harden Credentials.
• Establish centralized log management.
• Use antivirus solutions.
• Employ detection tools.
• Operate services exposed on internet-accessible hosts with secure configurations.
• Keep software updated.
Cyber actors routinely exploit poor security configurations (either misconfigured or left unsecured), weak controls, and other poor cyber hygiene practices to gain initial access or as part of other tactics to compromise a victim’s system. This joint Cybersecurity Advisory identifies commonly exploited controls and practices and includes best practices to mitigate the issues. This advisory was coauthored by the cybersecurity authorities of the United States,[1],[2],[3] Canada,[4] New Zealand,[5],[6] the Netherlands,[7] and the United Kingdom.[8]
Download the PDF version of this report (pdf, 430kb).
Malicious actors commonly use the following techniques to gain initial access to victim networks.[TA0001]
Malicious cyber actors often exploit the following common weak security controls, poor configurations, and poor security practices to employ the initial access techniques.
Applying the following practices can help organizations strengthen their network defenses against common exploited weak security controls and practices.
[1] United States Cybersecurity and Infrastructure Security Agency
[2] United States Federal Bureau of Investigation
[3] United States National Security Agency
[4] Canadian Centre for Cyber Security
[5] New Zealand National Cyber Security Centre
[6] New Zealand CERT NZ
[7] Netherlands National Cyber Security Centre
[8] United Kingdom National Cyber Security Centre
[9] White House Executive Order on Improving the Nation’s Cybersecurity
[10] NCSC-NL Factsheet: Prepare for Zero Trust
[11] NCSC-NL Guide to Cyber Security Measures
[12] N-able Blog: Intrusion Detection System (IDS): Signature vs. Anomaly-Based
[13] NCSC-NL Guide to Cyber Security Measures
[14] National Institute of Standards and Technology SP 800-123 – Keeping Servers Secured
U.S. organizations: To report incidents and anomalous activity or to request incident response resources or technical assistance related to these threats, contact CISA at report@cisa.gov. To report computer intrusion or cybercrime activity related to information found in this advisory, contact your local FBI field office at www.fbi.gov/contact-us/field, or the FBI’s 24/7 Cyber Watch at 855-292-3937 or by email at CyWatch@fbi.gov. For NSA client requirements or general cybersecurity inquiries, contact Cybersecurity_Requests@nsa.gov.
Canadian organizations: report incidents by emailing CCCS at contact@cyber.gc.ca.
New Zealand organizations: report cyber security incidents to incidents@ncsc.govt.nz or call 04 498 7654.
The Netherlands organizations: report incidents to cert@ncsc.nl.
United Kingdom organizations: report a significant cyber security incident: ncsc.gov.uk/report-an-incident (monitored 24 hours) or, for urgent assistance, call 03000 200 973.
The information you have accessed or received is being provided “as is” for informational purposes only. CISA, the FBI, NSA, CCCS, NCSC-NZ, CERT-NZ, NCSC-NL, and NCSC-UK do not endorse any commercial product or service, including any subjects of analysis. Any reference to specific commercial products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply their endorsement, recommendation, or favoring.
This document was developed by CISA, the FBI, NSA, CCCS, NCSC-NZ, CERT-NZ, NCSC-NL, and NCSC-UK in furtherance of their respective cybersecurity missions, including their responsibilities to develop and issue cybersecurity specifications and mitigations. This information may be shared broadly to reach all appropriate stakeholders.
This product is provided subject to this Notification and this Privacy & Use policy.
Please share your thoughts.
We recently updated our anonymous product survey; we’d welcome your feedback.
(888)282-0870
Send us email
Download PGP/GPG keys
Submit website feedback
Receive security alerts, tips, and other updates.
CISA is part of the Department of Homeland Security
Getty Images/iStockphoto
The rise in remote workforces has prompted many organizations to search for a viable document management system.
But to justify its adoption, an organization must study the DMS tools and ensure that they meet the organization’s needs. With more options becoming available due to improved technology and awareness, it can be difficult to know what to look for.
Document management systems help teams go beyond the limits of paper-based workflows to bring all their business systems online. They also provide a more structured alternative to simple file management systems that improve security, sharing and connectivity across workflows and applications.
A document is the universal API of business information exchange. Every business document, including invoices, contracts, bills of materials and purchase orders, is packaged into universal-sized pieces of paper. Document management systems bring order and consistency to these manual processes.
The need of every enterprise is different. Smaller companies might appreciate the opportunity to digitize manual and physical processes. Larger firms may appreciate new capabilities for integrating document data across various customer, financial, legal and compliance workflows more efficiently and with a higher level of granularity. And these more sophisticated capabilities are becoming more accessible and cost-effective thanks to improvements in AI, robotic process automation (RPA) and the cloud.
A document management system is a critical step in automating business processes. Timeshatter, a timeshare negotiations consultancy, turned to a document management system to improve complex workflows around timeshare contracts.
Implementing a document management system helped eliminate human error, according to Timeshatter CEO Brian Donovan. It also improved access and reduced the time spent ruffling through filing cabinets to find documents.
Companies with a high volume of critical documents will likely see the most significant gains from deploying a DMS platform.
Ephesoft, an intelligent document management system vendor, sees significant adoption among financial services companies, healthcare organizations, government agencies, education institutions and manufacturing firms, according to Dave Beery, data science team lead at the company.
Intelligent document processing (IDP) is an emerging capability for further automating DMS capabilities. Key IDP enhancements apply optical character recognition to identify text, AI to interpret the layout and meaning of the text and RPA to automate document workflows. Along with that, the cloud improves document workflows and data exchange with other applications through more sophisticated APIs.
The combination of IDP and cloud can help organizations build more sophisticated AI and machine learning models. For example, financial companies can use IDP to automatically extract more granular data from bank statements, pay stubs, tax documents and other essential documents. This capability leads to more accurate models to predict credit risks, identify fraud and improve planning, said Sam Bobley, CEO and co-founder of Ocrolus, a financial document automation platform.
It is important to look for certain document management system tools to determine if a platform is the right choice.
Cloud access is crucial because it allows users to access all documents from any device. It also helps mitigate the risk that data cannot be lost or deleted, while permissions are a great way to enable and restrict document access to different people.
It is vital to ensure various ways to bring documents into the platform, said Eric McGee, senior network engineer at TRG Datacenters. It’s best to ensure that a document management system allows for documents’ input through different sources such as email, scanners, apps and bulk uploads, he said. And if it’s an essential source in an organization, the organization should investigate how seamlessly it works with the necessary workflows. For example, does email upload require an extra step, or could the accounts receivable team kick off an invoice payment process with a single click, or better yet, no clicks?
Document version control features can help teams coordinate changes for communicating about complex products, particularly in manufacturing, said Maximilian zur Muehlen, business strategy manager at VEM Tooling Group, an injection molding company in China. For example, teams may work on different documents, such as a bill of material or a procurement request. Robust version control features have helped zur Muehlen’s team identify and avoid communication hiccups when documents get out of step.
Security should be a top priority in any newly integrated software or technology. Things to look for include in-transit and at-rest encryption, support for role-based access, comprehensive audit trails and revision indexing abilities. These are all valuable for their own sake and to simplify compliance.
The more documents users add to the database, the more complex, in theory, it becomes to manage. Pay close attention to the tagging, rating and other categorization capabilities as these will help users locate the necessary files more efficiently.
Research the tools’ advanced document indexing capabilities. Proper document indexing improves document retrieval, access controls and reporting. Some of the most popular DMS document indexing features include metadata indexing, content recognition and indexing, version and revision indexing and automatic document numbering.
Tightly regulated firms may also want to consider pull printing support, which keeps documents from printing until users have authenticated themselves at the device, suggested Bob Burnett, director of B2B solutions deployment and planning for Brother International Corporation. This protects documents from being taken by unauthorized personnel and can help avoid large crowds around the machine, aiding employees in feeling more comfortable being back in the office after the pandemic.
RPA can help automate DMS workflows, but someone has to create the RPA bots manually. Hyper-automation is an emerging capability for automating the process of creating automation. Look for human-in-the-loop capabilities that can “watch” how people process documents. This can accelerate efforts to combine the benefits of AI, RPA and cloud initiatives, Bobley said.
The top 5 content management trends in 2022
E-Handbook: Automated document management system tools transform workflows
Up Next
Advanced technologies, e-signature proliferation and COVID-19’s impact are speeding the transformation from paper-based to automated document management processes.
With numerous options to choose from, picking the right document management system for your organization depends on a careful examination of its tools and features.
Companies in the throes of digital transformation find the e-signature process to be a major catalyst in automating their document management systems and smoothing workflows.
Document management plays a key role in aiding hybrid workforces, so organizations must ensure their document management strategies enable safe and accessible hybrid collaboration.
The collaboration between the data cloud vendor and robotic process automation vendor will enable joint customers to automate …
As the volume and complexity of data grows, organizations need AI and ML capabilities to surface insights and augment the …
Coming after the addition of natural language processing capabilities, the new embedded analytics tool strengthens the BI …
The open source Apache Kafka streaming technology and commercial vendor Confluent have grown over the last decade as …
Data quality is essential to operate a successful data pipeline and enable data-driven decision-making. These seven data quality …
The Facebook parent company, along with multiple contributors, including Ahana, Voltron Data and Intel, are developing a new open…
Both RFID and barcodes are valuable in the supply chain, but each is more useful for particular scenarios. Learn what to consider…
Lack of communication between a company’s finance and IT departments can cause problems with organizational goals and decisions. …
Navrina Singh, CEO of Credo AI, discusses the limits of MLOps and algorithmic auditing in providing governance for responsible AI.
With its Cerner acquisition, Oracle sets its sights on creating a national, anonymized patient database — a road filled with …
Oracle plans to acquire Cerner in a deal valued at about $30B. The second-largest EHR vendor in the U.S. could inject new life …
The Supreme Court ruled 6-2 that Java APIs used in Android phones are not subject to American copyright law, ending a …
SAP Multi-Bank Connectivity has added Santander Bank to its partner list to help companies reduce the complexity of embedding …
Over its 50-year history, SAP rode business and technology trends to the top of the ERP industry, but it now is at a crossroads …
Third-party support providers make a pitch that they can provide greater flexibility at a lower cost, but customers should think …
All Rights Reserved, Copyright 2011 – 2022, TechTarget
Privacy Policy
Cookie Preferences
Do Not Sell My Personal Info
Getty Images
OpenText added more features to its Cloud Editions 21.4 fourth-quarter update. With the planned acquisition of Dallas-based email encryption company Zix for $860 million cash, email security features may soon follow.
OpenText does not have email encryption across its wide portfolio of enterprise content management, document security and process automation tools and applications, so Zix fills a gap. The deal is expected to close within 90 days.
“When we announce the closing of the acquisition, we will very quickly come up with plans for how we’d integrate and which areas it supports,” said Muhi Majzoub, OpenText executive vice president and chief product officer. “When the acquisition closes and this product becomes part of the OpenText portfolio, it will be a new product that we could integrate into many areas, including threat intelligence and document management.”
Tech acquisition prices have gone sky-high since last year as stock prices soar and many companies are flush with cash. Recent deals in the customer experience industry, for example, include Slack (almost $28 billion), SurveyMonkey ($4 billion) and MailChimp ($12 billion). In comparison, Zix is a “good deal,” said Deep Analysis founder Alan Pelz-Sharpe, probably in part because the email encryption company that caters to small and medium-sized businesses wasn’t profitable. OpenText must take on Zix’s estimated $200 million debt.
The Zix acquisition, Pelz-Sharpe predicted, will slot right into the OpenText product universe and fill an immediate need for its customers, some of which are large enterprises who didn’t support full-time remote workers before 2020.
“They have a lot of customers that maybe didn’t allow remote work before and sent their employees home,” Pelz-Sharpe said. “Suddenly, there’s a need among a mass of OpenText customers to employ email encryption.”
While OpenText released numerous Cloud Editions 21.4 features last month, more will be revealed on Tuesday at the company’s OpenText World virtual user conference. Among them is an integration with Google Marketing Platform, mostly an advertising and analytics cloud, to enable media management and high-volume email campaigns. OpenText has integrated its customer data platform with Google Marketing Platform, as well as its TeamSite web content management platform. This release is the latest in a years-long partnership between OpenText and Google Cloud that started in 2019.
Also new to OpenText Cloud Editions are developer tools for the OpenText Developer Cloud, which include API services and new consumption-pricing models as well as an improved developer site that consolidates available services that previously were spread across many sites.
Developers, Majzoub said, typically build apps that are connectors between OpenText applications and other applications on their networks to automate workflows. Increasingly, however, they’re building apps to tap into OpenText content services such as data security, document scanning or Intelligent Capture, which applies optical character recognition and machine learning classification to document ingestion processes.
Also new to Cloud Editions is an integration between Microsoft Office 365 and OpenText Core Content, a OneDrive and Box document cloud competitor. Pelz-Sharpe said that while Microsoft tries to induce Office365 users to store their files in OneDrive, many organizations whose enterprise content operations are built on OpenText or its competitors will never rip and replace massive online document repositories with OneDrive, so Microsoft must give its customers what they need: flexibility to save content where they want it, where they’ve set up their compliance and security workflows.
“Based on feedback that I’ve heard from [our] customers, they have been telling Microsoft that they don’t want the content always stored in a Microsoft system,” Majzoub said. “Their content strategy is to store in content suite in [OpenText] Documentum and Core Content. They want to keep that strategy, they want to drive it for the whole enterprise, and they don’t want to be forced to store the content in OneDrive or SharePoint.”
Don Fluckinger covers enterprise content management, CRM, marketing automation, e-commerce, customer service and enabling technologies for TechTarget.
The collaboration between the data cloud vendor and robotic process automation vendor will enable joint customers to automate …
As the volume and complexity of data grows, organizations need AI and ML capabilities to surface insights and augment the …
Coming after the addition of natural language processing capabilities, the new embedded analytics tool strengthens the BI …
The open source Apache Kafka streaming technology and commercial vendor Confluent have grown over the last decade as …
Data quality is essential to operate a successful data pipeline and enable data-driven decision-making. These seven data quality …
The Facebook parent company, along with multiple contributors, including Ahana, Voltron Data and Intel, are developing a new open…
Both RFID and barcodes are valuable in the supply chain, but each is more useful for particular scenarios. Learn what to consider…
Lack of communication between a company’s finance and IT departments can cause problems with organizational goals and decisions. …
Navrina Singh, CEO of Credo AI, discusses the limits of MLOps and algorithmic auditing in providing governance for responsible AI.
With its Cerner acquisition, Oracle sets its sights on creating a national, anonymized patient database — a road filled with …
Oracle plans to acquire Cerner in a deal valued at about $30B. The second-largest EHR vendor in the U.S. could inject new life …
The Supreme Court ruled 6-2 that Java APIs used in Android phones are not subject to American copyright law, ending a …
SAP Multi-Bank Connectivity has added Santander Bank to its partner list to help companies reduce the complexity of embedding …
Over its 50-year history, SAP rode business and technology trends to the top of the ERP industry, but it now is at a crossroads …
Third-party support providers make a pitch that they can provide greater flexibility at a lower cost, but customers should think …
All Rights Reserved, Copyright 2011 – 2022, TechTarget
Privacy Policy
Cookie Preferences
Do Not Sell My Personal Info




