Forcepoint > Case Studies > Payment Leader Achieves PCI Compliance with Next-Gen CASB

Payment Leader Achieves PCI Compliance with Next-Gen CASB

Forcepoint Logo
Company Size
1,000+
Region
  • America
Country
  • United States
Product
  • Bitglass CASB
Tech Stack
  • Google's G Suite
  • Bitglass AD sync agent
Implementation Scale
  • Enterprise-wide Deployment
Impact Metrics
  • Cost Savings
  • Digital Expertise
Technology Category
  • Cybersecurity & Privacy - Cloud Security
Applicable Industries
  • Finance & Insurance
Applicable Functions
  • Business Operation
Use Cases
  • Cybersecurity
Services
  • Cloud Planning, Design & Implementation Services
  • Cybersecurity Services
About The Customer
The customer is a leader in payment and debit-card processing. They have a diverse workforce consisting of regular employees and contractors, who use a mix of managed and BYOD mobiles and laptops. The workforce is geographically distributed, adding to the complexity of their operations. The company had standardized on Google's G Suite but was struggling to achieve PCI compliance for its auditors. The compliance team had specific requirements for access control, wanting to restrict contractors to browser access and only on the corporate network, while allowing regular employees full access on managed devices and corporate networks, but restricted access on BYOD.
The Challenge
The payment and debit-card processing leader standardized on Google's G Suite, but struggled to achieve PCI compliance for its auditors. With a mix of regular employees and contractors, managed and BYOD mobiles and laptops, as well as a geographically distributed work force proved challenging when it came to achieving PCI compliance. The compliance team wanted to restrict contractors to browser access and only on the corporate network, whilst allowing regular employees full access on managed devices and corporate networks, but restricted access on BYOD.
The Solution
Bitglass delivered a complete solution out of the box. The Bitglass solution included SAML single sign-on, so the customer terminated its contract with Okta and configured Bitglass to be the identity provider for G Suite. Installing the Bitglass AD sync agent automatically provisioned users on Bitglass mirroring user groups and privileges. Configuring WYSWIG access-control policies on the Bitglass console enforced the rules that were required for compliance. And Bitglass’s unique AJAX-VM technology meant that no agents or configuration or spoofed certificates were required on either managed or unmanaged laptops. Users simply logged into G Suite and were automatically redirected via the Bitglass proxy service.
Operational Impact
  • The Bitglass solution provided a complete, out-of-the-box solution for the customer's compliance needs.
  • The solution included SAML single sign-on, eliminating the need for a separate contract with Okta.
  • The Bitglass AD sync agent automatically provisioned users on Bitglass, mirroring user groups and privileges.
  • The solution's WYSWIG access-control policies enforced the rules required for compliance.
  • Bitglass’s unique AJAX-VM technology meant that no agents or configuration or spoofed certificates were required on either managed or unmanaged laptops.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

Related Case Studies.

Contact us

Let's talk!
* Required
* Required
* Required
* Invalid email address
By submitting this form, you agree that IoT ONE may contact you with insights and marketing messaging.
No thanks, I don't want to receive any marketing emails from IoT ONE.
Submit

Thank you for your message!
We will contact you soon.