SlideShare a Scribd company logo
Apollo Group
HP Enterprise Security Customer Case Study

“We are extremely pleased to have ArcSight
ESM as the basis for our security foundation. Its
versatility and raw ability to combat cyberthreats
and risk make it an excellent choice.”
—Scott Carlson, Principal Engineer, Apollo Group Data Center
Architecture

Customer Brief

HP Enterprise Security
Customer Case Study:
Apollo Group, parent
company of the
University of Phoenix
and several other
higher education
institutions, relies
on ArcSight ESM to
provide visibility and
intelligence into its
network and to protect
against zero day
cyberthreats.
Industry: Education

Apollo Group, Inc. is one of the world’s largest
private education providers and has been in
the education business for more than 35 years.
The company offers innovative and distinctive
educational programs and services both online
and on-campus at the high school, undergraduate,
master and doctoral levels through its subsidiaries:
University of Phoenix, Apollo Global, Institute for
Professional Development, College for Financial
Planning and Meritus University. The company’s
programs and services are provided in 40 states
and the District of Columbia; Puerto Rico; Canada;
Latin America; and Europe, as well as online
throughout the world.

Product(s)
•	 rcSight ESM
A

Business Benefits
•	 rcSight ESM enables Apollo Group to maximize
A
its visibility and intelligence into its network, and
protect against zero day cyberthreats
•	 eeds from numerous vendors are easily
F
correlated into events, allowing the security team
to act immediately
•	 pollo Group can prove it is meeting compliance
A
requirements and can respond to auditor
requests quickly and easily

The Apollo Group Challenge
Apollo Group is a publicly traded parent company that
owns the University of Phoenix and a number of other
subsidiaries in the education arena. With 300 physical
locations in six countries, 500,000 students, 50,000
faculty and 22,000 employees, Apollo Group has a
formidable challenge in securing all its systems, data
and endpoints.
Apollo Group needed to be able to meet rigorous audit
and compliance requirements for regulations such as
SOX and PCI. It also aimed to take its security to the next
level and do more real-time correlation and alerting of
security events across its entire infrastructure. In building
a more mature security operations center, Apollo Group
required a fully featured threat and risk management
system that could deliver.
Originally, Apollo Group had deployed a product to
address these challenges; however, it failed to meet the
organization’s requirements over time and had to be
re-evaluated. It simply could not scale along with the
pace of business. In a head-to-head competition,
ArcSight ESM performed better, offered more features
and flexibility, and also ranked highest among industry
thought leaders. It quickly became the clear choice.

The ArcSight Solution
ArcSight ESM enables Apollo Group to increase its
visibility and intelligence into its network and protect
against zero day cyberthreats. The organization has a
diverse population of technologies and security products
(McAfee, Blue Coat, Sourcefire, etc.) and the capability
of ArcSight ESM to correlate events across all those logs
in real time allows it to respond more quickly to risk and
threats.
With ArcSight ESM, Apollo Group has been able to
create unique use cases to identify events specific to its
environment. One example is preventing student misuse
of Internet resources. When students register for a
course, they are required to submit homework and
interact with their peers and instructor via message
boards contained on the classroom portal. With
ArcSight ESM, Apollo Group has the ability to monitor
for inappropriate actions and take decisive action before
anyone’s reputation is negatively impacted.
Apollo Group also specifically protects against data
leakage via mobile media. Student loan and other
personally identifiable information (PII), for example,
must be kept safe. Apollo Group has gone a step
beyond usual protocol and has written custom
connectors so that employees cannot move that type of
data inappropriately through the use of a USB flash
drive or email, for that matter.
ArcSight ESM features robust capabilities that can
proactively detect a vast range of threats and
compliance violations, and respond to them in a timely
manner. “The ArcSight solution has become the single
pane of glass we look through in our information security
operations center,” says Scott Carlson, Principal
Engineer of Apollo Group Data Center Architecture.

“Even with the complexity of adding new data centers,
tools and devices over time, ArcSight ESM can handle
it,” says Bill Thorn, Senior Manager of IT Services for
Apollo Group. “Our ability to respond instantly to
incidents as they’re occurring, wherever they’re
occurring, is a huge benefit and limits any possible
damage.”
An important area where ArcSight ESM has helped
Apollo Group is in eliminating viruses from the network.
Even the latest anti-virus technology cannot catch
everything that’s out there. The number of variants is just
too great.
“Right away, ArcSight ESM helped us identify systems
that had updated anti-virus and endpoint protection, but
that were still infected,” says Thorn. “We were able to
remediate these systems and eliminate that threat from
our environment.”
The comprehensive correlation and reporting capabilities
within ArcSight ESM enable Apollo Group to effectively
process billions of security events and maintain
compliance with SOX and PCI regulations. “With
ArcSight ESM, we now have a very solid solution. It
provides us with real-time testable security, as opposed
to a reactive model where we would generate and keep
nightly reports for analysis,” says Carlson. “With
ArcSight ESM, not only can we catch a security event
very close to when it happens; we can also prove that
we’re doing it.”
Looking forward, Apollo Group will continue to
integrate, automate and maximize its visibility into what
exactly is happening on its network at any given time. It
will be aggressively looking at how employees are using
the Internet and how malware is coming into the
company. “The ability to identify where we’re exposed
with malware is going to be very big for us,” says
Carlson. “We are extremely pleased to have ArcSight
ESM as the basis for our security foundation. Its
versatility and raw ability to combat cyberthreats and
risk make it an excellent choice.”

The ArcSight Impact
The University of Phoenix, the company’s largest entity,
provides industry-leading education to adult learners. A
primary goal of Apollo Group was to match that level of
leadership and expertise with a world-class security
solution that could discover, analyze and remediate
cyberthreats. The University of Phoenix needs to
constantly adapt to educational trends and student
desires for higher learning, and the IT and IS
infrastructure supporting it needs to be nimble enough
to keep pace.

© Copyright 2011 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties
for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be
construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.
All other product and company names may be trademarks or registered trademarks of their respective owners.
ESP-CCS030-031911-03, Created August 2011

More Related Content

PPT
B.tech cloud technology and information security
PDF
Owasp o
PDF
App sec owasp from developers prospective
PDF
Strategies for Managing OT Cybersecurity Risk
PPT
Integrated mca cloud technology & information security
PDF
vip_day_2._1130_cloud
PPTX
SplunkLive! Atlanta Mar 2013 - University of Alabama at Birmingham
PPTX
SIEM - Your Complete IT Security Arsenal
B.tech cloud technology and information security
Owasp o
App sec owasp from developers prospective
Strategies for Managing OT Cybersecurity Risk
Integrated mca cloud technology & information security
vip_day_2._1130_cloud
SplunkLive! Atlanta Mar 2013 - University of Alabama at Birmingham
SIEM - Your Complete IT Security Arsenal

Similar to HP Enterprise Security Customer Case Study - Apollo Group (20)

PDF
Lessons Learned: Protecting Critical Infrastructure from Cyber Attacks
PDF
Talos threat-intelligence
PDF
PAS: Leveraging IT/OT - Convergence and Developing Effective OT Cybersecurity
PDF
Hans Bos
PDF
Cisco amp for endpoints
PPTX
Splunk for Enterprise Security featuring UBA Breakout Session
PPTX
Why 2024 will become the Year of SaaS Security Meetup 24012024.pptx
PDF
Posco IPPC acquires a new approach towards cybersecurity with Seqrite EPS
PDF
Security Enhanced Applns For Info Systems C Kalloniatis
DOCX
Microsoft Strategic InitiativeCharls Yang, Yining Xie, Andres .docx
PDF
Claroty Award Write Up
PPTX
Splunk for Enterprise Security Featuring UBA
PDF
Top Cyber News MAGAZINE. Dr. Bradford L. Sims. Capitol Technology University
PDF
2021. Top Cyber News MAGAZINE Dr. Bradford L. Sims CapTechU
PDF
Company_Profile_Updated_17032016
PDF
AI for Cyber Security and Adversarial AI
PPTX
Open Threat Management Platform in USA.pptx
PDF
Cisco amp everywhere
PDF
Cisco amp for networks
PDF
Security operations center inhouse vs outsource
Lessons Learned: Protecting Critical Infrastructure from Cyber Attacks
Talos threat-intelligence
PAS: Leveraging IT/OT - Convergence and Developing Effective OT Cybersecurity
Hans Bos
Cisco amp for endpoints
Splunk for Enterprise Security featuring UBA Breakout Session
Why 2024 will become the Year of SaaS Security Meetup 24012024.pptx
Posco IPPC acquires a new approach towards cybersecurity with Seqrite EPS
Security Enhanced Applns For Info Systems C Kalloniatis
Microsoft Strategic InitiativeCharls Yang, Yining Xie, Andres .docx
Claroty Award Write Up
Splunk for Enterprise Security Featuring UBA
Top Cyber News MAGAZINE. Dr. Bradford L. Sims. Capitol Technology University
2021. Top Cyber News MAGAZINE Dr. Bradford L. Sims CapTechU
Company_Profile_Updated_17032016
AI for Cyber Security and Adversarial AI
Open Threat Management Platform in USA.pptx
Cisco amp everywhere
Cisco amp for networks
Security operations center inhouse vs outsource
Ad

More from Scott Carlson (15)

PDF
What are Blockchain & Tokens and are they useful ?
PPTX
RSA APJ - BLOCKCHAIN SECURITY – IS IT REALLY DIFFERENT THAN ANYTHING ELSE ?
PPTX
Just Trust Everyone and We Will Be Fine, Right?
PPTX
DCD Converged Brazil 2016
PPTX
Trust But Control: Managing Privileges without killing productivity
PDF
RSA 2015 Realities of Private Cloud Security
PDF
RSA 2016 Realities of Data Security
PPTX
Will Your Cloud Be Compliant? OpenStack Security
PPTX
Interop Las Vegas Cloud Connect Summit 2014 - Software Defined Data Center
PPTX
Can Security & Agility Co-Exist
PPTX
You Can't Correlate what you don't have - ArcSight Protect 2011
PDF
Marriage of ESX and OpenStack - PayPal - VMWorld US 2013
PDF
McAfee Focus 2011 - Security in the Age of a Mobile Workforce and Mobile Devices
PPTX
Marriage of Openstack with KVM and ESX at PayPal OpenStack Summit Hong Kong F...
PPTX
High Availability OpenStack at PayPal - OpenStack Summit Fall Hong Kong 2013
What are Blockchain & Tokens and are they useful ?
RSA APJ - BLOCKCHAIN SECURITY – IS IT REALLY DIFFERENT THAN ANYTHING ELSE ?
Just Trust Everyone and We Will Be Fine, Right?
DCD Converged Brazil 2016
Trust But Control: Managing Privileges without killing productivity
RSA 2015 Realities of Private Cloud Security
RSA 2016 Realities of Data Security
Will Your Cloud Be Compliant? OpenStack Security
Interop Las Vegas Cloud Connect Summit 2014 - Software Defined Data Center
Can Security & Agility Co-Exist
You Can't Correlate what you don't have - ArcSight Protect 2011
Marriage of ESX and OpenStack - PayPal - VMWorld US 2013
McAfee Focus 2011 - Security in the Age of a Mobile Workforce and Mobile Devices
Marriage of Openstack with KVM and ESX at PayPal OpenStack Summit Hong Kong F...
High Availability OpenStack at PayPal - OpenStack Summit Fall Hong Kong 2013
Ad

HP Enterprise Security Customer Case Study - Apollo Group

  • 1. Apollo Group HP Enterprise Security Customer Case Study “We are extremely pleased to have ArcSight ESM as the basis for our security foundation. Its versatility and raw ability to combat cyberthreats and risk make it an excellent choice.” —Scott Carlson, Principal Engineer, Apollo Group Data Center Architecture Customer Brief HP Enterprise Security Customer Case Study: Apollo Group, parent company of the University of Phoenix and several other higher education institutions, relies on ArcSight ESM to provide visibility and intelligence into its network and to protect against zero day cyberthreats. Industry: Education Apollo Group, Inc. is one of the world’s largest private education providers and has been in the education business for more than 35 years. The company offers innovative and distinctive educational programs and services both online and on-campus at the high school, undergraduate, master and doctoral levels through its subsidiaries: University of Phoenix, Apollo Global, Institute for Professional Development, College for Financial Planning and Meritus University. The company’s programs and services are provided in 40 states and the District of Columbia; Puerto Rico; Canada; Latin America; and Europe, as well as online throughout the world. Product(s) • rcSight ESM A Business Benefits • rcSight ESM enables Apollo Group to maximize A its visibility and intelligence into its network, and protect against zero day cyberthreats • eeds from numerous vendors are easily F correlated into events, allowing the security team to act immediately • pollo Group can prove it is meeting compliance A requirements and can respond to auditor requests quickly and easily The Apollo Group Challenge Apollo Group is a publicly traded parent company that owns the University of Phoenix and a number of other subsidiaries in the education arena. With 300 physical locations in six countries, 500,000 students, 50,000 faculty and 22,000 employees, Apollo Group has a formidable challenge in securing all its systems, data and endpoints. Apollo Group needed to be able to meet rigorous audit and compliance requirements for regulations such as SOX and PCI. It also aimed to take its security to the next level and do more real-time correlation and alerting of security events across its entire infrastructure. In building a more mature security operations center, Apollo Group required a fully featured threat and risk management system that could deliver. Originally, Apollo Group had deployed a product to address these challenges; however, it failed to meet the organization’s requirements over time and had to be re-evaluated. It simply could not scale along with the
  • 2. pace of business. In a head-to-head competition, ArcSight ESM performed better, offered more features and flexibility, and also ranked highest among industry thought leaders. It quickly became the clear choice. The ArcSight Solution ArcSight ESM enables Apollo Group to increase its visibility and intelligence into its network and protect against zero day cyberthreats. The organization has a diverse population of technologies and security products (McAfee, Blue Coat, Sourcefire, etc.) and the capability of ArcSight ESM to correlate events across all those logs in real time allows it to respond more quickly to risk and threats. With ArcSight ESM, Apollo Group has been able to create unique use cases to identify events specific to its environment. One example is preventing student misuse of Internet resources. When students register for a course, they are required to submit homework and interact with their peers and instructor via message boards contained on the classroom portal. With ArcSight ESM, Apollo Group has the ability to monitor for inappropriate actions and take decisive action before anyone’s reputation is negatively impacted. Apollo Group also specifically protects against data leakage via mobile media. Student loan and other personally identifiable information (PII), for example, must be kept safe. Apollo Group has gone a step beyond usual protocol and has written custom connectors so that employees cannot move that type of data inappropriately through the use of a USB flash drive or email, for that matter. ArcSight ESM features robust capabilities that can proactively detect a vast range of threats and compliance violations, and respond to them in a timely manner. “The ArcSight solution has become the single pane of glass we look through in our information security operations center,” says Scott Carlson, Principal Engineer of Apollo Group Data Center Architecture. “Even with the complexity of adding new data centers, tools and devices over time, ArcSight ESM can handle it,” says Bill Thorn, Senior Manager of IT Services for Apollo Group. “Our ability to respond instantly to incidents as they’re occurring, wherever they’re occurring, is a huge benefit and limits any possible damage.” An important area where ArcSight ESM has helped Apollo Group is in eliminating viruses from the network. Even the latest anti-virus technology cannot catch everything that’s out there. The number of variants is just too great. “Right away, ArcSight ESM helped us identify systems that had updated anti-virus and endpoint protection, but that were still infected,” says Thorn. “We were able to remediate these systems and eliminate that threat from our environment.” The comprehensive correlation and reporting capabilities within ArcSight ESM enable Apollo Group to effectively process billions of security events and maintain compliance with SOX and PCI regulations. “With ArcSight ESM, we now have a very solid solution. It provides us with real-time testable security, as opposed to a reactive model where we would generate and keep nightly reports for analysis,” says Carlson. “With ArcSight ESM, not only can we catch a security event very close to when it happens; we can also prove that we’re doing it.” Looking forward, Apollo Group will continue to integrate, automate and maximize its visibility into what exactly is happening on its network at any given time. It will be aggressively looking at how employees are using the Internet and how malware is coming into the company. “The ability to identify where we’re exposed with malware is going to be very big for us,” says Carlson. “We are extremely pleased to have ArcSight ESM as the basis for our security foundation. Its versatility and raw ability to combat cyberthreats and risk make it an excellent choice.” The ArcSight Impact The University of Phoenix, the company’s largest entity, provides industry-leading education to adult learners. A primary goal of Apollo Group was to match that level of leadership and expertise with a world-class security solution that could discover, analyze and remediate cyberthreats. The University of Phoenix needs to constantly adapt to educational trends and student desires for higher learning, and the IT and IS infrastructure supporting it needs to be nimble enough to keep pace. © Copyright 2011 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. All other product and company names may be trademarks or registered trademarks of their respective owners. ESP-CCS030-031911-03, Created August 2011