Skip to main content

Wyeth implements assessment technology to address Web site compliance and security.

Published on 24-Jan-2008

"The issues we find with the AppScan technology help our site owners to identify and address certain areas of noncompliance and improve the sites. This helps improve the environment of trust and helps prolong customer relationships." - —Courtney Leo, Internet compliance manager, Wyeth

Customer:
Wyeth

Industry:
Life Sciences

Deployment country:
United States

Overview

Wyeth implements assessment technology to address Web site compliance and security.

Business need:
Wyeth needed to ensure that its more than 350 global Web sites were in compliance with various international legal regulations as well as its own rigorous internal security standards.

Solution:
The company utilizes IBM Rational® Policy Tester™ and IBM Rational AppScan® software to automate online compliance-related testing and application security testing

Benefits:
Managed by the Wyeth Internet management committee, the com-pany’s new automated compliance and security testing program hasincreased productivity and impro-ved customer confidence in the company’s online brand integrity.

Case Study

For more than a century, Wyeth has been a leader in the world of prescrip-tion pharmaceuticals, nonprescription consumer healthcare products and pharmaceuticals for animal health. The company employs approximately 50,000 people and operates in more than 145 countries across the globe. Wyeth strives to provide top-notch products and services, including numerous Web sites that offer a wealth of features and resources to benefit its customers and partners.

Challenged to ensure consistent quality
Maintaining online compliance for a global brand like Wyeth is more than just a quality assurance (QA) issue. When a company operates in as many countries as Wyeth and has as many Web sites, it needs a comprehensive compliance program that combines people, processes and technology to help deliver the same high standards across all its sites and brands.

As the Internet compliance manager at Wyeth—and a certified information privacy professional (CIPP)—Courtney Leo oversees the ongoing review of Wyeth’s Web sites. With more than 350 corporate sites, Wyeth needs to con-duct thorough quality tests in a timely manner to identify potential application security, quality and compliance issues.

Not only did Wyeth need a tool that could scale to support its massive operations, it also needed an auto-mated process that could help it deliver consistent quality across all its sites. And the company needed to ensure that the technology could support its comprehensive information compliance and security program as managed by Wyeth’s Internet man-agement committee.

Automating the analysis of tens of thousands of Web pages
After working for more than a year, Wyeth developed a corporate standard for Web site best practices. Consequently, the company needed to implement these standards across all its groups by addressing Web practices that could poten­tially open security holes, produce poor quality content or fail to comply with numerous international standards.

Wyeth utilizes Policy Tester and AppScan software to help it identify and prioritize Web site issues for resolution. The software enables Wyeth to automatically analyze content and applications spanning tens of thousands of dynamic Web pages.

Implementing the solution globally
Wyeth integrated the technology into its global vulnerability management and compliance program—leveraging its people, processes, education and training as the cornerstones of the program. The Internet management committee at Wyeth uses the tools to help them address compliance management issues from the ground up: from application development through deployment. The Policy Tester software, an automated online risk management solution, is used to audit and manage quality, privacy, accessibility and compliance-related issues in Wyeth’s corporate Web properties. And the AppScan tool is used to identify, analyze and remediate security issues early in development.

Protecting Wyeth’s brands while saving time and money
Armed with the Policy Tester application, the Wyeth Internet management commit­tee is able to help ensure that its numerous Web sites meet customer expectations for quality and privacy. The application helps Wyeth improve its QA and compliance management, along with its productivity: automating what were once manual tasks has helped the company improve utilization rates and reduce costs.

Wyeth’s Web site owners, who are located in a number of countries, take advantage of the Policy Tester application to perform privacy and quality compliance-related testing, as well as to verify and check their sites for third-party cookies, Web beacons and Secure Sockets Layer (SSL) configuration details. Having worked with the tool for a reasonable amount of time, the site owners report that they feel more secure about the functionality and quality of their sites. Policy Tester has enabled Wyeth to automate a significant part of the process, giving the company’s staff more time to focus on the tasks that require human attention. As a result, Wyeth has been able to significantly reduce its volume of work while continuing to improve the company’s online presence.

“The issues we find with the AppScan technology help our site owners to identify and address certain areas of noncompliance and improve the sites. This helps improve the environment of trust and helps prolong customer relationships,” says Leo.

In addition to privacy and quality compliance-related testing, the Web security team uses AppScan software to automate application security testing. The team leverages the tool as part of its application building process, which helps team members cut costs and reduce time to market. Wyeth has found that detecting potential vulnerabilities early in the software development lifecycle often makes those issues cheaper and easier to fix.

Wyeth also puts its third-party applications to the test. Virtually all third-party-developed applications must pass the stringent standards of the Internet management committee, which sometimes means full security testing as well as a battery of compliance and functionality testing.
“The products have helped Wyeth merge our people, process and technology, and that has increased cost savings and efficiency throughout the corporation,” explains Leo. “It’s crucial that all these factors work together.”

For more information
To learn more about IBM Rational Web application security software, contact your IBM representative or IBM Business Partner, or visit:
ibm.com/software/rational/offerings/testing/webapplicationsecurity

Products and services used

IBM products and services that were used in this case study.

Software:
Rational AppScan Standard Edition, Rational Policy Tester Privacy Edition

Legal Information

© Copyright IBM Corporation 2007 IBM CorporationSoftware GroupRoute 100Somers, NY 10589U.S.A. Produced in the United States of America12-07All Rights Reserved. AppScan, IBM, the IBM logo, Policy Tester and Rational are trademarks or registered trademarks of International Business Machines Corporation in the United States, other countries, or both. Other company, product and service names may be trademarks or registered trademarks or service marks of others. The information contained in this documentation is provided for informational purposes only. While efforts were made to verify the completeness and accuracy of the information contained in this docu­mentation, it is provided “as is” without warranty of any kind, express or implied. In addition, this infor­mation is based on IBM’s current product plans and strategy, which are subject to change by IBM without notice. IBM shall not be responsible for any dam­ages arising out of the use of, or otherwise related to, this documentation or any other documentation. Nothing contained in this documentation is intended to, nor shall have the effect of, creating any warran­ties or representations from IBM (or its suppliers or licensors), or altering the terms and conditions of the applicable license agreement governing the use of IBM software. IBM customers are responsible for ensuring their own compliance with legal requirements. It is the customer’s sole responsibility to obtain advice of competent legal counsel as to the identification and interpretation of any relevant laws and regula­tory requirements that may affect the customer’s business and any actions the customer may need to take to comply with such laws. RAC14017-USEN-00

Bookmark this page