IBM® WebSphere® MQ® is the de-facto standard for middleware messaging and is embedded in most key WebSphere products supplying the infrastructure for reliable communication protocols and enterprise integration for SOA implementations. Most WebSphere MQ installations are insecure due to mis or non-configuration of security parameters and the lack of security products.  Did you know the vast majority of the WMQ network is not properly secured leading to spoffing of the WMQ Administrative assess?  Did you know that security professionals are pointing to WMQ as the attack vector in the Hannaford Breach?  Did you know PCI Vendors are now assessing middleware and companies are failing PCI Audits?

With the integrity, confidentiality and availability of your corporate assets at risk, Evans Resource Groups’ WebSphere MQ experts in a program with IBM are providing FREE internal penetration assessments (IPAs).  In addition, we partner with the PCI Vendor community to provide a vigorous check of the security of WWQ against PCI DSS. After the assessment, which reviews such areas as Compliance, Security, Availability, Integrity, Confidentiality, Disaster Recovery, Versions, a report will be delivered to you detailing the findings and providing high level recommendations.

WebSphere MQ Internal Penetration Assessment:

Evans Resources’ CAP and certified MQ Solution Architects will provide a FREE WMQ Internal Penetration Assessment which includes the following activities:

• Compliance for PCI DSS, FISMA, GLB and HIPAA requirements
• A mapping of WMQ exposures to compliance requirements

• Provide information on misuses of WMQ

• Examine Channel, Queue Manager configurations, error logs and files
• Validate version usage and upgrade options/efforts


Deliverables include a Internal Penetration Assessment outlining findings in terms of criticality, descriptions of the findings, remediation recommendations and a map to the security requirement. An ERG CAP professional will review the report with compliance, risk and administrative personnel and prioritize recommendations.

 

Free Engagement: Requires 1 day of assessment (Completed IPA delivered within 1 week of assessment)
Pre-Requisites: Access to your system administrator or WMQ administrator who maintains your WebSphere MQ Infrastructure and Implementations
Fees: $0 (plus travel expenses - although in most cases no travel is required)


How do you get started:

The first step is a 30 minute call to make you aware of the issues due to mis-configuration or non-configuration of WMQ.