OpenSolaris Drives Payment Card Industry Data Security Standard (PCI) Compliance Solution to a Significantly Lower CostReliant Security provides information security products and services that help merchants secure and protect the confidentiality and integrity of a client’s information. The company's solutions are simple, inexpensive, and easy to deploy and manage. Most importantly, they help merchants comply with Payment Card Industry Data Security Standard (PCI) requirements. Customer Challenges
SolutionReliant Security depends on OpenSolaris, Solaris 10 and Sun servers to run its Payment Card Industry (PCI) compliant information security products. Many companies in the retail industry have adopted it's secure, low cost PCI compliant solution enterprisewide. Business Results
Story DetailsProtecting consumers' credit card and transaction data is a major concern for most retailers, because they must comply with Payment Card Industry Data Security Standard (PCI) and other information security requirements. For many retailers, PCI is an overwhelming security requirement, addressing encryption, system integrity, logging, intrusion detection, vulnerability scanning, wireless protection, configuration management, and system hardening. To meet these requirements retailers often must deploy a complex mix of point solutions from various vendors. The cost to deploy and maintain these solutions can climb to the tens of thousands of dollars per store, and there is no guarantee that the solutions will be compatible — or reliable enough to ensure that confidential information won't be compromised. Sun partner Reliant Security provides data security products and services that help retailers and other merchants comply with PCI and other security requirements. The company's Managed PCI System (MPS) provides a full suite of security controls in a turnkey solution for merchants with distributed store or branch environments. “Our goal with MPS was to meet a very large and complex security requirement [PCI] with a solution that dramatically lowered the cost point for retailers and could replace multiple point solutions in a mission-critical environment,” says Richard Newman, co-founder and president of Reliant Security. “We wanted to keep the in-store solution to four figures or less. The [in-store] network appliance is about the size of a paperback book and is competitively priced.”
"
The level of enterprise customer service support that comes with Sun is exponentially better than what you get with other open source products and solutions. When you compare Sun with vendors such as Red Hat or Novell in the platform space, the difference is like night and day.
"
— Richard Newman, president and cofounder, Reliant Security
The Managed PCI System is built on both Solaris 10 and the OpenSolaris Operating System, providing a very scalable, virtualized platform. Typically the Sun Fire T1000 server is used for large scale SSL VPN end-point aggregation, and the Sun Fire X2200 M2 servers support a head-end server side virtualized environments for multiple security applications and Web 2.0 portal. “With Sun, our approach is to take the best that’s available from the open source community and provide the specific, programmatic software integration,” says Newman. “We make it all work together, package it, and virtualize it using an industrial strength operating system and run it at the store environment on low-cost, off-the-shelf embedded systems hardware.” Reliant originally developed its MPS on BSD Unix and then migrated to Solaris 10 and OpenSolaris. “We needed better virtualization than BSD provided, and Solaris 10 with Containers gave us the best balance between operating system virtualization and shared virtual resources,” says Newman. “We also needed networking support and saw such strength in Sun's solutions. So, we turned to Crossbow, the OpenSolaris network virtualization project. It provided us with a very advanced, virtualized networking environment. It's exactly what we needed.” Reliant Security evaluated VMware but quickly realized that it was far too expensive to implement. “For this type of solution where we're putting hundreds or thousands of boxes into retail stores, paying for a VMware license in each location made VMware cost-prohibitive,” says Newman. Because retailers operate on very thin margins, an open source solution particularly when backed by a large company like Sun is very compelling. Solaris Operating System and Containers offer a better licensing model for putting low-cost boxes in multiple stores or branch locations. Newman says support and service were definitely important factors in choosing the Sun platform on which to develop MPS. “The Sun name makes our customers feel very comfortable,” says Newman. He adds that the level of support and service that Sun provides far exceeds that of other open source vendors or the open source community. “In the open source community, you find individuals that are doing their own open source work part-time, at home or at night. That's not the same as having an organization like Sun truly standing behind it.” says Newman. “And from a hardware perspective, you have a close pairing of the strong open source operating system in both Solaris 10 and OpenSolaris with hardware sets that come from one organization — no other vendor can provide that.” A key deciding factor for Reliant Security's customers is price. Its in-store management network appliance uses off-the-shelf components — no custom hardware is required. As a result, Reliant Security's MPS is a dramatically lower cost solution than that of other vendors. “We have seen retailers that had to add three, four, five, or even 10 people to their existing support team to manage multiple solutions,” says Newman. The small in-store footprint also reduces retailers' power and cooling costs. Knowing that MPS meets or exceeds PCI requirements and is audit-ready gives customers peace of mind, and it's hard to overvalue that. Reliant Security plans to develop more security applications on the Sun platform. “With Sun we get leading-edge virtualization from a well-established technology solution provider with a great pedigree,” says Newman. “Sun has strength and experience in security and in overall enterprise management. And it is able to bring both software and hardware solutions to the table from one organization.” |
Interested in Sun's Open Storage?
Download this paper today to learn about the tools, trends and key features of Sun's Open Storage solutions.
| |