Security Overview - Documentation for Bmc Helix Subscriber Information

BMC understands that the confidentiality, integrity and availability of your operational information are vital to your organization. BMC uses a multi-layered approach to protect your data, constantly monitoring and improving applications, systems, and processes. The BMC Security Operations Center (SOC) and Network Operations Center (NOC) teams work 24 hours a day, seven days a week, and 365 days a year to ensure the continuous and secure operation of your service.

The NOC makes extensive use of BMC’s world class monitoring and automation solutions. All customer environments are monitored 24 hours a day and seven days a week. The NOC frequently resolves potential incidents before they impact customers.

Should your service be impacted, automated root cause analysis data is provided via the BMC TrueSight Operations Management solution and extensive automations using BMC Atrium Orchestrator dramatically reduce the Mean Time to Repair (MTTR).

BMC’s security strategy includes the following layers:

  • Governance
  • Physical
  • Perimeter
  • Network
  • Endpoint
  • Application
  • Data

Governance

The Governance layer comprises all other controls and incorporates policies, procedures, and awareness-related activities. This layer emphasizes governance, organization information security awareness, and external validation of the effectiveness of related controls. 

Key features of this layer include:

  • Policies and procedures
  • Quality Management System
  • Architecture and design
  • Threat intelligence
  • Risk analysis and management
  • Penetration testing and vulnerability assessments
  • Security awareness training
  • Security technology
  • Assessment/evaluation

Physical

The BMC Helix physical platform is provided by top-tier data center providers globally. These data centers incorporate fully redundant power, cooling, and battery backup systems to provide continuous and safe physical and environmental operation of BMC Helix services and solutions. 

Key features of this layer include:

  • Prominent data center partners providing geographically-dispersed Tier III (as defined by the Uptime Institute) facilities
  • Secure, nondescript facilities
  • On-site security 24x7x365 with closed-circuit TV monitoring
  • Automated and manual inspections of access points
  • Secure access to all facilities requiring two-factor building access with key card, PIN in addition to biometrics

See Service locations for additional details.

Marcus Vance

Marcus Vance

Cybersecurity & Digital Privacy Researcher

Marcus Vance is a cybersecurity auditor and technology writer dedicated to educating the public about online safety, data privacy regulations, enterprise security, and emerging cyber threats.

Share this article
Twitter Facebook Pinterest