trust center | Dynatrace news The tech industry is moving fast and our customers are as well. Stay up-to-date with the latest trends, best practices, thought leadership, and our solution's biweekly feature releases. Thu, 02 Jul 2026 09:16:43 +0000 en hourly 1 Multicloud HIPAA compliance for healthcare: Dynatrace now supports AWS, Azure, and GCP https://www.dynatrace.com/news/blog/multicloud-hipaa-compliance-for-healthcare/ https://www.dynatrace.com/news/blog/multicloud-hipaa-compliance-for-healthcare/#respond Fri, 26 Jun 2026 16:22:00 +0000 https://www.dynatrace.com/news/?p=74687 Dynatrace and HIPPA

Dynatrace now supports HIPAA compliant observability for U.S. healthcare organizations across all major cloud providers — AWS, Microsoft Azure, and GCP. With Business Associate Agreements (BAAs) available and built in controls to limit Protected Health Information (PHI) exposure, healthcare teams can choose the hyperscaler that best fits their strategy.

The post Multicloud HIPAA compliance for healthcare: Dynatrace now supports AWS, Azure, and GCP appeared first on Dynatrace news.

]]>
Dynatrace and HIPPA

Dynatrace extends HIPAA compliance to Google Cloud Platform

Dynatrace has long supported HIPAA‑compliant deployments on Amazon Web Services (AWS) and Microsoft Azure. With the extension of HIPAA compliance to Google Cloud Platform (GCP), healthcare organizations in the United States can now standardize observability and security controls across all three major hyperscalers.

This expansion gives healthcare teams the flexibility to select the cloud platform that best supports their operational and innovation goals, while maintaining alignment with regulatory requirements. Dynatrace offers the option to enter into a BAA to support customers’ HIPAA obligations when Dynatrace services are used in regulated environments.

By delivering consistent, enterprise‑ready observability across AWS, Azure, and GCP, Dynatrace helps healthcare organizations modernize applications, improve system reliability, and strengthen security oversight.

HIPAA compliance: A business and trust imperative

HIPAA protects PHI and establishes safeguards for its storage, access, and monitoring. Compliance is not just a legal obligation; it is fundamental to:

  • Maintaining patient trust
  • Protecting sensitive data
  • Avoiding costly regulatory penalties

Dynatrace solves healthcare observability challenges while keeping PHI where it belongs

Healthcare providers must balance rising patient expectations, modernization initiatives, and cost pressures, without sacrificing compliance or security. While cloud platforms often offer agility and scalability, regulatory requirements such as HIPAA can constrain technology choices.

Dynatrace HIPAA compliance is built on a shared responsibility model. Our platform is architected so that PHI does not need to flow through observability data. Customers retain responsibility for ensuring PHI and Personally Identifiable Information (PII) are masked at the source, and Dynatrace provides the tools to make that straightforward. Dynatrace offers built-in data masking and sensitive data protection features that allow teams to:

  • Mask or obfuscate PHI and PII before data is ingested into the platform. The original data doesn’t leave the monitored environment. Once masked, sensitive data can’t be re-engineered.
  • Define custom masking rules across logs, traces, and user session data.
  • Reduce the risk of inadvertent PHI exposure
  • Permanently delete unintended PHI ingestion with the Sensitive Data Center’s cleanup workflow

Dynatrace automatically discovers and maps every application, service, process, and infrastructure component across clouds.

Capability HIPAA relevance
Data masking and obfuscation Reduces PHI and PII exposure outside the monitored environment
Role-based access control (RBAC) and audit logs Aligns with HIPAA Security Rule access and monitoring requirements
Multicloud observability Enables consistent compliance controls across AWS, Azure, and GCP

For healthcare organizations, this means that Dynatrace delivers:

  • Real-time observability across applications, infrastructure, and security.
  • Standardized compliance controls across providers.
  • Audit trails, access logging, and RBAC are aligned with HIPAA security rule requirements.
  • A single source of truth for AI-first developers, IT operations, security, and compliance teams, eliminating tool sprawl and data silos.

Dynatrace multicloud HIPAA compliance supports healthcare organizations’ strategy to:

  • Confidently evaluate GCP alongside AWS and Azure.
  • Strengthen security and compliance visibility from a single platform.
  • Invest in innovation, without compliance as a constraint.

Frequently asked questions

Is Dynatrace HIPAA‑compliant on AWS, Azure, and GCP?

Yes. Dynatrace supports HIPAA‑compliant deployments across Amazon Web Services, Microsoft Azure, and Google Cloud Platform for U.S. healthcare organizations.

Does Dynatrace ingest or process PHI?

Dynatrace operates on a privacy-by-design architecture, meaning it provides engineers with built-in tools to block PHI before it ever reaches the cloud. By default, Dynatrace does not need or use Protected Health Information (PHI) to monitor your application, but it can accidentally capture PHI if your systems leak sensitive data into logs, URLs, or payload traces. By signing a BAA with Dynatrace, your organization is assured that, if PHI is ever accidentally transmitted to Dynatrace, the data is protected under the necessary federal safeguards.

Are Business Associate Agreements available?

Yes. Dynatrace offers the option to enter into a BAA to support customers’ HIPAA obligations.

Getting started

This announcement is part of a larger Dynatrace commitment to ensuring observability is not constrained  by cloud provider choices.

Healthcare organizations can now deploy Dynatrace on GCP with HIPAA assurance, leveraging the same enterprise-grade observability available across AWS and Azure.

The post Multicloud HIPAA compliance for healthcare: Dynatrace now supports AWS, Azure, and GCP appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/multicloud-hipaa-compliance-for-healthcare/feed/ 0
How to build trust in Digital Experience Monitoring https://www.dynatrace.com/news/blog/how-to-build-trust-in-digital-experience-monitoring/ https://www.dynatrace.com/news/blog/how-to-build-trust-in-digital-experience-monitoring/#respond Fri, 08 May 2026 12:51:07 +0000 https://www.dynatrace.com/news/?p=73862 Digital Experience graphic

Digital Experience Monitoring (DEM) is essential for understanding how users interact with your applications—from failed payments and slow user journeys to crashes and stability regressions.
At the same time, DEM often intersects with personal or other sensitive data, a risk that industries such as banking, retail, and healthcare are especially sensitive to. To drive adoption across teams, organizations need confidence that DEM can deliver critical insights without compromising on privacy or compliance.

The post How to build trust in Digital Experience Monitoring appeared first on Dynatrace news.

]]>
Digital Experience graphic

To help address this challenge, Dynatrace introduced new documentation and best practices for handling sensitive data.

This blog explains why the topic matters, what risks teams are trying to avoid, and how Dynatrace is designed to support privacy-first DEM adoption.

How privacy concerns slow DEM adoption

Across industries, we see the same patterns: Teams want granular and precise visibility to identify meaningful patterns and tailor improvements, while security, privacy, and compliance teams require strong guarantees around sensitive data handling. As a result, DEM adoption can be delayed or remain limited to basic use cases.

This is especially common in regulated environments such as banking and healthcare, where even well-intentioned monitoring can raise questions like:

  • Are we collecting more data than necessary?
  • Who can access personal data, and under what conditions?
  • Are we handling sensitive data appropriately?
  • Are we compliant with all our regulatory requirements?

Without clear answers and support, organizations may delay rollout, restrict access too aggressively, or avoid certain capabilities altogether.

Privacy by default in Dynatrace DEM

Dynatrace is designed with privacy-by-design principles:

  • User sessions are anonymized out of the box
  • Sensitive data can be masked at capture, storage, and read
  • Access to sensitive fields is controlled through fine-grained permissions

Privacy settings are configured per frontend (web or mobile) and can be set independently based on each frontend’s risk profile and regulatory context.

Configure Dynatrace DEM for end-to-end compliance

Privacy and compliance should not be blockers to Digital Experience Monitoring, but they do require clear guidance and intentional configuration. Our DEM compliance guide explores two relevant use cases to help organizations identify which configuration options should be considered for their environments:

  • Complaint resolution in an e-commerce web app: teams can utilize user tags to quickly identify affected sessions and resolve issues, while access to personal data remains tightly controlled.
  • Troubleshooting performance issues in a mobile banking app: teams can gain insights and fix stability or performance issues while fully masking all personally identifying information.

Learn more

To meet data compliance requirements set by industry regulations, organizations must identify specific requirements and outline the steps to protect sensitive data. The new documentation helps organizations to expand or refine their use of Digital Experience Monitoring by demonstrating how to:

  • Configure privacy settings for frontends
  • Limit data collection
  • Control access to sensitive fields
  • Support troubleshooting and performance optimization without compromising compliance

Explore how Dynatrace helps organizations address regulatory and compliance requirements.

The post How to build trust in Digital Experience Monitoring appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/how-to-build-trust-in-digital-experience-monitoring/feed/ 0
Dynatrace secures Dubai’s digital future with DESC certification https://www.dynatrace.com/news/blog/dynatrace-secures-dubais-digital-future-with-desc-certification/ https://www.dynatrace.com/news/blog/dynatrace-secures-dubais-digital-future-with-desc-certification/#respond Tue, 20 Jan 2026 05:50:04 +0000 https://www.dynatrace.com/news/?p=72540 Dynatrace secures Dubai’s digital future with DESC certification

Dynatrace has taken another significant step in achieving compliance and quality by obtaining DESC certification from the Dubai Electronic Security Center (DESC). This underscores our commitment to protecting Dubai’s digital infrastructure and supporting its vision for secure, smart, and sustainable cities.

The post Dynatrace secures Dubai’s digital future with DESC certification appeared first on Dynatrace news.

]]>
Dynatrace secures Dubai’s digital future with DESC certification

Established by the Government of Dubai, DESC sets rigorous cybersecurity standards to safeguard critical systems, promote secure cloud adoption, and support transformational smart city initiatives. DESC certification confirms that Dynatrace meets and exceeds these standards, giving Dubai government entities confidence to deliver seamless, secure digital services to their citizens.

Overcoming challenges in public sector IT compliance

Dynatrace collaborates closely with public sector organizations in the UAE and worldwide to support government and educational institutions in delivering secure, reliable, and efficient services. Such organizations are obliged to implement adequate controls to ensure the integrity and security of their data. Government agencies are under added pressure; as they continue to digitally transform and their data is distributed across multiple platforms and applications, the complexity of their systems increases. Delivering secure, resilient, and optimized operations within these environments requires a platform that provides actionable insights and intelligent automation from vast amounts of cloud data, all while adhering to stringent cybersecurity requirements.

Dynatrace: Certified solutions to complex problems

The Dynatrace® AI-powered observability platform is purpose-built to process and analyze massive volumes of data, with robust controls in place to protect customer data. The platform continuously invests in advanced capabilities to stay ahead of evolving market standards, as well as regional and sector-specific requirements. Key Dynatrace capabilities that help Dubai governmental entities protect their data include the following:

  • End-to-end observability — Real-time insights into applications, infrastructure, and user experience across hybrid/multicloud environments.
  • AI-powered automation — Predictive analysis, root-cause detection, and instant remediation to accelerate resolution.
  • Application security — Continuous threat detection and automated mitigation aligned with DESC requirements.
  • UAE data residency — While operating globally, Dynatrace stores UAE public-sector data securely within the UAE’s borders.
  • Independent validation — Assessment against DESC’s cybersecurity framework by qualified third-party auditors.

Empowering secure digital transformation for Dubai’s public sector

Our partnership with Microsoft Azure UAE and the Dubai Government reflects a shared vision of creating smarter, safer, and more sustainable cities. Dynatrace’s intelligent observability and integrated security capabilities empower organizations to:

  • Accelerate digital transformation with speed, confidence, and resilience.
  • Enhance citizen experiences by delivering secure, high-performance, and reliable digital services.
  • Foster trust by safeguarding data privacy and following UAE regulations.

Dubai’s ambition to lead the world in smart city innovation, sustainability, and digital empowerment is at the heart of this collaboration. Dynatrace’s achievement of DESC certification on Microsoft Azure in the UEA aligns seamlessly with this vision, delivering:

  • A secure foundation for smart cities — Safeguarding interconnected systems that drive smart infrastructure and digital ecosystems.
  • Enhanced citizen engagement — Enabling secure, seamless, and efficient services that elevate the quality of life for residents and visitors.
  • Sustainability through efficiency — Harnessing AI-powered automation and intelligent observability to optimize resource consumption and operations, advancing Dubai’s environmental goals.

Together, we’re building the foundation for a future-ready digital ecosystem that empowers Dubai to thrive as a global leader in innovation, sustainability, and security.

Join us in shaping the future

At Dynatrace, we’re committed to driving innovation and helping organizations thrive in the digital age. Achieving DESC certification on Microsoft Azure in the UAE is just one of the many ways we’re delivering on this promise.

We invite all government agencies, critical non-government entities, and forward-thinking private sector organizations seeking secure, compliant, and innovative cloud solutions to discover what Dynatrace on Microsoft Azure in the UAE can do for the future of smart cities and secure digital transformation.

Get started today with a free trial and transform your own enterprise with an AI-powered observability platform, purpose-built for Azure cloud native and AI environments. Or start your free trial via the Azure Marketplace.

Contact us to discover how the Dynatrace platform can enhance your operations and accelerate innovation.

The post Dynatrace secures Dubai’s digital future with DESC certification appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-secures-dubais-digital-future-with-desc-certification/feed/ 0
Enterprise-grade user account protection: Protecting local user accounts for compliance and operational continuity https://www.dynatrace.com/news/blog/enterprise-grade-user-account-protection-protecting-local-user-accounts-for-compliance-and-operational-continuity/ https://www.dynatrace.com/news/blog/enterprise-grade-user-account-protection-protecting-local-user-accounts-for-compliance-and-operational-continuity/#respond Wed, 14 Jan 2026 19:53:13 +0000 https://www.dynatrace.com/news/?p=72440 Access management graphic

As enterprises scale their digital operations, securing user accounts becomes critical to prevent operational disruptions, reputational damage, and compliance risks. Dynatrace protects that local user accounts with enterprise-grade security measures, enabling you to focus on innovation without worrying about account takeovers or compliance gaps.

The post Enterprise-grade user account protection: Protecting local user accounts for compliance and operational continuity appeared first on Dynatrace news.

]]>
Access management graphic

The critical role of user account protection in enterprise security

Most enterprises rely on federated identity providers (IdPs), such as Azure AD or Okta, for user authentication and authorization. Utilizing federated identities is also the most common method for securely accessing Dynatrace. However, hybrid setups that combine federated identities with local Dynatrace accounts are frequently employed in specific scenarios, including:

  • External collaborators: Contractors, partners, or users from other organizations who need temporary access.
  • Short-lived access: Project-based or engagement-specific accounts that don’t justify full IdP integration.
  • Administrative or super-user accounts: Critical roles that require guaranteed access, independent of SAML federation, for operational continuity.

These local accounts can be vulnerable to attacks if not properly secured. Dynatrace addresses these risks with robust security measures tailored to protect local user identities.

Figure 1. Configure multi-factor authentication via email or the authenticator app to secure your user accounts.
Figure 1. Configure multi-factor authentication via email or the authenticator app to secure your user accounts.

How Dynatrace safeguards local user accounts

Dynatrace User Account Protection (UAP) is a critical pillar in safeguarding your most valuable asset, your data. While our fine-grained authorization framework ensures that every user only accesses the data they’re entitled to, UAP complements this by securing the identities behind those permissions. Together, these measures form a unified approach to data protection and compliance: robust access policies prevent unauthorized visibility, and strong account security prevents unauthorized entry. By combining fine-grained access controls with user account protection, Dynatrace delivers a secure, compliant, and trustworthy observability experience.

Dynatrace access via local user account (Dynatrace IdP) via federated user account (Customer IdP)
Where credentials are stored Dynatrace Identity Provider Customer’s Identity Provider (for example, Azure AD, Okta)
Security posture provided by Dynatrace (password policy, MFA enforcement, takeover prevention) Customer (IdP configuration, MFA, policies)
Password policy Strong password policy enforced by Dynatrace Defined by customer IdP
Account takeover prevention ✅ Login throttling
✅ reCAPTCHAs
✅ Email notifications for suspicious logins
✅ MFA integration
Depends on customer IdP configuration (features vary by provider)

Figure 2. Account protection comparison: local users vs. federated users

Dynatrace offers a comprehensive suite of features to safeguard local user accounts stored in the Dynatrace Identity Provider (IdP):

Password policy

Strong password policies are crucial for minimizing the risk of unauthorized access and safeguarding sensitive data. To prevent brute-force attacks, every password must meet strict requirements: it should be a minimum of 12 characters and can be up to 120 characters in length. Additionally, passwords must contain a mix of character types, including at least one uppercase letter, one lowercase letter, one numeral, and one special character.

Multi-factor authentication (MFA)

Multi-factor authentication (MFA) significantly reduces the risk of account compromise, safeguarding both individual accounts and the overall environment. Dynatrace provides multiple MFA features to enhance protection. Users can enable login MFA with time-based one-time passwords, which are configured through their preferred authenticator app and required as a second factor during login. For environment access, administrators can enforce MFA to ensure only verified users can access critical resources.

This environment protection can be achieved through an MFA-authenticated session or step-up authentication, where a one-time password is sent to the user via email as an additional verification step. These measures provide a robust defense against unauthorized access.

User account takeover prevention

Dynatrace continuously monitors and prevents suspicious login attempts. These proactive measures make it harder for attackers to exploit accounts, providing early warnings to users:

  • Login throttling: Limits repeated failed login attempts; users can retry after a short timeout (typically 3–5 minutes).
  • reCAPTCHA integration: Adds human verification for email and password entry, making automated brute-force attacks costly and difficult.
  • Suspicious login notifications: Users receive email notifications if unusual authentication activity is detected.

Best practices to secure your Dynatrace user accounts

To provide robust security for user accounts, enterprises should adopt a combination of proactive measures and continuous monitoring.

Key best practices:

  • Apply environment MFA: Protect critical information by enforcing multi-factor authentication at the environment level.
  • Encourage MFA for non-federated users: Ensure that non-federated users turn on MFA with TOTP for an additional layer of security.
  • Monitor user activity and token usage: Regularly track user activity and the use of tokens to detect anomalies or inactive accounts.

Implementing these practices will enhance your overall account security and mitigate potential risks.

Protect your user accounts

Dynatrace provides real, enterprise-grade protection for local user accounts, enabling you to stay ahead of modern security threats. For more details on how to set it up properly, please go to our user and group management documentation.

The post Enterprise-grade user account protection: Protecting local user accounts for compliance and operational continuity appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/enterprise-grade-user-account-protection-protecting-local-user-accounts-for-compliance-and-operational-continuity/feed/ 0
Unified privacy and sensitive data management for logs with the Sensitive Data Center https://www.dynatrace.com/news/blog/unified-privacy-and-sensitive-data-management-for-logs-with-the-sensitive-data-center/ https://www.dynatrace.com/news/blog/unified-privacy-and-sensitive-data-management-for-logs-with-the-sensitive-data-center/#respond Fri, 05 Dec 2025 18:02:28 +0000 https://www.dynatrace.com/news/?p=72151 Unified privacy and sensitive data management

Managing sensitive data in log files is getting even easier with Dynatrace. Our new Sensitive Data Center unifies privacy request workflow, data cleanup, and the new Sensitive Data Scanner to help you streamline working with sensitive data in Dynatrace. It allows teams to respond to data subject rights with confidence, remove records safely when required, […]

The post Unified privacy and sensitive data management for logs with the Sensitive Data Center appeared first on Dynatrace news.

]]>
Unified privacy and sensitive data management

Managing sensitive data in log files is getting even easier with Dynatrace. Our new Sensitive Data Center unifies privacy request workflow, data cleanup, and the new Sensitive Data Scanner to help you streamline working with sensitive data in Dynatrace. It allows teams to respond to data subject rights with confidence, remove records safely when required, and proactively discover and govern sensitive data ingested into Grail®. Sensitive Data Scanner will be available in a limited preview release by the end of 2025.

Handle sensitive data throughout your growing data ecosystem

Organizations face increasing pressure to demonstrate responsible practices for managing sensitive data while maintaining efficient operations and minimizing downtime. In addition to meeting end users’ data subject rights requests, such as the export or deletion of personal data, organizations must take proactive steps to prevent unnecessary exposure and storage of sensitive information. Achieving these objectives is challenging, especially with fragmented tools, siloed teams, and manual processes. As telemetry volumes increase, these inefficiencies lead to slower response times, higher operational overhead, and increased compliance risks.

Streamline privacy operations in Dynatrace with the Sensitive Data Center

The Sensitive Data Center brings privacy operations and sensitive data management together in a single app on the Dynatrace platform and complements existing privacy controls with an additional layer of control. Aligning scanning, cleanup, and data subject rights workflows with where your data resides helps teams reduce manual work and improve accuracy, all in a transparent process where every scan, cleanup, and request is logged and auditable, supporting your regulatory obligations with clarity and control.

Continuously scan for unintentionally ingested sensitive data in Logs on Grail

Imagine a service administrator who suspects that sensitive data might have been unintentionally ingested in their observability data. They need a quick way to confirm whether it happened and, if so, where the sensitive data resides and what type of sensitive data is affected—ideally without having to build custom scripts or pull engineers off priority work. The Sensitive Data Scanner is a new module in the Sensitive Data Center that helps you discover sensitive data at the time of ingestion, allowing you to govern it more effectively in three steps:

  1. Configure the scanner
  2. Review the scan results
  3. Mitigate any potential findings

Configure scans in the Sensitive Data Scanner

The setup is straightforward. You can choose to monitor specific buckets or the entire environment. Select the sensitive data type or types from built-in rules such as email, credit card, or IP address. You can set up several fine-grained scans with different scopes to accommodate different scan areas. A scan runs at a defined cadence every 6, 12, or 24 hours, depending on your compliance needs, and alerts you when data matching the selected criteria is found.

Sensitive data scans set up

Review scan results

A dashboard provides a clear overview of scan statuses and highlights when sensitive data is found. From there, you can drill down into a specific scan to review detailed findings and understand exactly what was detected.

Sensitive data scan dashboard

You can review the results and examine the data flow from ingestion to the storage location.

Sensitive data scan dashboard

Mitigate potential findings

With these results, you can immediately take action. You can configure or adjust masking rules to prevent similar data from being ingested in the future, change access to stored data, update retention periods, or utilize the cleanup functionality to delete the data as needed.

Sensitive Data Scanner preview

The Sensitive Data Scanner will be available in a preview release by the end of 2025. As we gather feedback, we will continue to refine the experience and expand coverage, allowing teams to move confidently from identification to action within the same app.

Act decisively with precise, auditable cleanup

Data cleanup is available directly within the Sensitive Data Center, allowing you to take action when your organization’s regulatory obligations or policies require the removal of data.

The “Cleanup data” workflow in Sensitive Data Center allows you to easily locate, review, and delete an entire time frame of data, as well as any selected individual records that contain sensitive data defined in your DQL search query. To improve accuracy and minimize the risk of accidentally deleting data, you can also select a reviewer who will review and approve deletion requests before the data is deleted. Learn more about deleting data in Grail.

Efficiently locate, export, and delete end users’ personal data

Let’s walk through another common scenario. The services administrator, ensuring Dynatrace is operating smoothly, receives an urgent request from the privacy legal team: “Please locate, compile, and delete all personal data associated with this email address in Dynatrace as part of our end-user’s right to be forgotten.” Privacy requests in the Sensitive Data Center offer an end-to-end experience for managing data subject rights requests within the Dynatrace platform, allowing for quick, compliant, and efficient handling of sensitive data.

Dynatrace empowers you with a ready-made solution for submitting, tracking, and verifying the status of requests. With a user interface designed for compliance needs, you can efficiently manage data export and deletion requests. A dashboard summarizes key details, including the request reference, status, and due date alignment.

Sensitive data scan dashboard

Together, scanning and cleanup ensure that only the sensitive data you intend to process is stored in Logs on Grail, while privacy requests provide the workflows and approvals necessary to comply with user privacy rights for lawfully processed personal data.

Try Sensitive Data Center in the Dynatrace Playground.

This blog may contain forward-looking statements about our product plans, upcoming features, and anticipated improvements.  These statements are for informational purposes only and are not promises or guarantees.  The development, release, and timing of any features or functionality described remain at the sole discretion of Dynatrace LLC and may be modified, delayed, or canceled without notice.  We encourage readers to make decisions based on the product’s current capabilities and features.

The post Unified privacy and sensitive data management for logs with the Sensitive Data Center appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/unified-privacy-and-sensitive-data-management-for-logs-with-the-sensitive-data-center/feed/ 0
Dynatrace achieves QC1 certification from the Italian Agency for National Cybersecurity https://www.dynatrace.com/news/blog/dynatrace-achieves-qc1-certification-from-the-italian-agency-for-national-cybersecurity/ https://www.dynatrace.com/news/blog/dynatrace-achieves-qc1-certification-from-the-italian-agency-for-national-cybersecurity/#respond Thu, 23 Oct 2025 18:14:49 +0000 https://www.dynatrace.com/news/?p=71523 Dynatrace achieves QC1 certification from the Italian Agency for National Cybersecurity

We're pleased to announce that the Dynatrace® platform is now QC1 certified following the Italian Agency for National Cybersecurity (ACN) cloud qualification process. The cloud qualification process provided by the ACN is a qualification and control process aimed at ensuring the security and reliability of cloud services used by the Italian public administration (PA). This process was introduced to verify that cloud service providers adhere to a set of specific security, quality, and reliability requirements, thereby contributing to the protection of the country’s critical data and infrastructure. This milestone confirms Dynatrace’s commitment to high standards of security, compliance, and operational excellence, enabling Italian public sector organizations to accelerate digital transformation with confidence in our platform.

The post Dynatrace achieves QC1 certification from the Italian Agency for National Cybersecurity appeared first on Dynatrace news.

]]>
Dynatrace achieves QC1 certification from the Italian Agency for National Cybersecurity

Rising cybersecurity risks in the public sector

Modern public sector organizations manage and store increasingly large volumes of sensitive data, elevating cloud security as a top priority. At the same time, these organizations face mounting pressure to innovate and modernize, all while maintaining rigorous standards for data protection and regulatory compliance.

Qualification of cloud infrastructure and services is a central pillar of the Italian Cloud Strategy, issued by the Department for Digital Transformation and the Agenzia per la Cybersicurezza Nazionale (ACN). The strategy provides guidelines for migrating data and digital services of the Italian Public Administration to the cloud, ensuring that security and resilience are foundational at every stage.

To this end, the Italian government—through ACN—has established a robust framework for qualifying cloud solutions that manage all levels of public sector data and workloads. This framework ensures that only providers who meet strict criteria for security, reliability, and transparency are eligible to serve the public administration. The QC1 certification, in particular, is designed to simplify, regulate, and secure how cloud services are acquired by Italian administrative bodies. It aligns with the objectives of the National Cybersecurity Strategy, which aims to plan, coordinate, and implement measures to make Italy safer and more resilient.

For technology vendors, achieving ACN QC1 is not merely a regulatory requirement; it is a demonstration of trustworthiness and a prerequisite for participating in Italy’s digital future. Without this qualification, cloud solutions will not be considered by public sector entities—ultimately limiting both innovation and public benefit.

Empowering Secure Digital Transformation for Italy’s Public Sector

Dynatrace’s attainment of the ACN QC1 qualification directly addresses the complex requirements of Italy’s public sector. By certifying our platform against the rigorous standards established by the Italian Cloud Strategy and the ACN, Dynatrace allows public sector organizations to adopt advanced observability and automation aligned with the security, compliance, and resilience requirements defined by the ACN.

The Dynatrace platform represents a new era in observability, uniting analytics, AI, and automation to help organizations thrive in the age of agentic AI. The latest Dynatrace platform is engineered to contextualize vast streams of observability data, transforming it into real-time intelligence that powers actionable insights, automation, and the path toward autonomous operations.

QC1 certification confirms that Dynatrace has implemented comprehensive technical and organizational safeguards to protect data, prevent unauthorized access, and ensure the reliability of services. This independent validation gives public sector customers confidence that they can accelerate their digital transformation initiatives on a secure, compliant, and future-ready platform.

What ACN QC1 means for Dynatrace customers

With ACN QC1 qualification, Italian government agencies and public sector bodies can now confidently adopt Dynatrace for their mission-critical workloads. Key benefits include:

  • Assured compliance: Independent validation that Dynatrace meets or exceeds all ACN QC1 requirements for managing ordinary data.
  • Accelerated procurement: Simplified onboarding through the ACN marketplace, reducing procurement friction and time-to-value.
  • Operational transparency: Ongoing alignment with Italian cybersecurity regulations, with clear documentation and audit readiness.
  • Trusted innovation: Access to the full capabilities of the Dynatrace platform, enabling secure cloud native transformation and intelligent automation.

At Dynatrace, every certification we achieve unlocks a new level in our mission to empower our customers worldwide with cutting-edge, secure, and compliant solutions. Visit the Dynatrace Trust Center to review all our certifications and accreditations and to learn more about the Dynatrace approach to security and compliance by design.

Request a demo to learn more about how the Dynatrace platform can improve your operations and accelerate innovation.

The post Dynatrace achieves QC1 certification from the Italian Agency for National Cybersecurity appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-achieves-qc1-certification-from-the-italian-agency-for-national-cybersecurity/feed/ 0
Salesloft Drift Incident: Dynatrace’s Response https://www.dynatrace.com/news/blog/salesloft-drift-incident-dynatraces-response/ https://www.dynatrace.com/news/blog/salesloft-drift-incident-dynatraces-response/#respond Mon, 08 Sep 2025 16:03:03 +0000 https://www.dynatrace.com/news/?p=70957 Observability data

In August 2025, a cyberattack on Salesloft’s Drift application resulted in unauthorized access to Salesforce CRM data from companies using the third-party app. Salesloft and Salesforce have since taken steps to disable the compromised connections and notify their affected customers. Like many companies, Dynatrace was among those affected by the Salesloft incident. We took immediate […]

The post Salesloft Drift Incident: Dynatrace’s Response appeared first on Dynatrace news.

]]>
Observability data

In August 2025, a cyberattack on Salesloft’s Drift application resulted in unauthorized access to Salesforce CRM data from companies using the third-party app. Salesloft and Salesforce have since taken steps to disable the compromised connections and notify their affected customers. Like many companies, Dynatrace was among those affected by the Salesloft incident. We took immediate steps to protect our systems and customers. As of September 7th, we have been notified by Salesloft that the connections have been re-enabled.

Dynatrace Response

Upon learning of the incident, we disabled Drift in our environment and launched an investigation with the assistance of third-party cybersecurity experts. Our investigation found the activity was limited solely to Salesforce, our CRM platform, which we use for customer management and marketing purposes. No Dynatrace products or services, including any systems containing customer data or any services that directly interface with customer systems, were affected. Moreover, Dynatrace does not use the case function in Salesforce and, as such, no case information was accessible as a result of the incident. The potentially affected data is limited to business contact information, including first and last names of customer contacts and company identifiers. There has been no disruption to our operations.

Guidance for customers

Because the data involved may include business contact information, we encourage customers to exercise extra caution. The following steps can help protect against phishing or social engineering attempts that could arise from this type of incident:

  • Be alert to phishing or social engineering attempts using your information. Dynatrace will never contact you by phone or email to request passwords, multi-factor authentication codes, or other sensitive credentials.
  • Confirm that all communications and links originate from trusted Dynatrace domains. When in doubt, go directly to the Dynatrace website or use your normal support channel rather than clicking unfamiliar links.

If you have any questions or concerns, please contact your account team or trustcenter@dynatrace.com. At Dynatrace, safeguarding our customers’ privacy and security is paramount.

The post Salesloft Drift Incident: Dynatrace’s Response appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/salesloft-drift-incident-dynatraces-response/feed/ 0
Dynatrace achieves High certification under Spain’s National Security Framework (ENS) https://www.dynatrace.com/news/blog/dynatrace-achieves-high-certification-under-spains-national-security-framework-ens/ https://www.dynatrace.com/news/blog/dynatrace-achieves-high-certification-under-spains-national-security-framework-ens/#respond Thu, 31 Jul 2025 16:04:41 +0000 https://www.dynatrace.com/news/?p=70196

We’re proud to announce that the Dynatrace® platform is now certified in accordance with Esquema Nacional de Seguridad (ENS), Spain’s National Security Framework by OCA CERT. The ENS is an official cybersecurity framework established by the Spanish government to ensure the protection of information and services in the public sector and among regulated service providers. […]

The post Dynatrace achieves High certification under Spain’s National Security Framework (ENS) appeared first on Dynatrace news.

]]>

We’re proud to announce that the Dynatrace® platform is now certified in accordance with Esquema Nacional de Seguridad (ENS), Spain’s National Security Framework by OCA CERT.

The ENS is an official cybersecurity framework established by the Spanish government to ensure the protection of information and services in the public sector and among regulated service providers. By aligning to ENS standards, organizations guarantee that their technology, processes, and people meet stringent requirements set forth by the Spanish government, fostering greater trust and reliability in digital services.

Partnering with the Spanish public sector

Many public sector organizations across Spain and the broader EU are eager to accelerate their digital transformation. They want to deliver faster services, better user experiences, and smarter operations. Due to the criticality and sensitivity of the information handled by public sector institutions, finding the right balance between innovation and regulatory adherence is a constant challenge. Regulations such as ENS are designed to ensure that data remains protected while enabling digital progress.

This dynamic often slows down transformation efforts, leaving teams reliant on legacy monitoring tools that lack scalability, cloud-readiness, and automation. To move forward, public institutions must rely on technology partners who not only deliver innovation but do so with trust, accountability, and a deep understanding of national cybersecurity standards.

We’re proud to support this mission and honored to stand alongside our customers in Spain as a trusted partner for their secure digital future.

Dynatrace: Security meets intelligence

The Dynatrace® platform is reimagining observability by combining the power of analytics, AI, and automation to drive organizations forward in the age of agentic AI. The 3rd generation platform has been built to harness a goldmine of observability data in context and turn that data into real-time knowledge for AI, creating actionable insights and automation, and paving the way for autonomous intelligence. The ENS certification reinforces our commitment to delivering trustworthy, compliant, and secure cloud services, enabling organizations to innovate with confidence.

Certification comes with practical advantages

  • Public sector onboarding: Spanish government agencies and regulated entities can now confidently adopt the Dynatrace platform and meet local compliance requirements.
  • Enterprise risk reduction: Organizations in finance, healthcare, and other critical sectors benefit from reduced risk and a proven security framework, simplifying their own compliance efforts.
  • Accelerated RFP and procurement: ENS certification streamlines the procurement process, enabling faster onboarding and go-live timelines for projects subject to regulatory scrutiny.

Example use cases include deploying digital citizen services, secure data analytics platforms for healthcare, and compliant hosting environments for fintech applications, all leveraging the Dynatrace ENS-certified platform, a solution that combines world-class observability with government-grade security. The bigger story is what this allows: faster innovation, smarter public services, and more trust between citizens and their institutions.

How ENS High elevates Dynatrace security and trust for the public sector

ENS certification reinforces Dynatrace’s already robust security foundation, which includes:

  • Enhanced data protection mechanisms that offer access, confidentiality, integrity, traceability, authenticity, and conservation of data.
  • Formalized incident response protocols for quick detection and remediation of potential threats.
  • Advanced risk management strategies, including regular vulnerability assessments.
  • Increased transparency and monitoring of operational activities.

The bottom line is, with Dynatrace, Spanish public sector organizations have gained the performance insights they need, supported by the compliance and security standards required for regulated environments.

Compliance without compromise

Achieving ENS High certification is one of many testaments to our dedication to setting industry benchmarks. Visit the Dynatrace Trust Center to review all our certifications and accreditations and to learn more about the Dynatrace approach to security and privacy by design.

Request a demo to learn more about how Dynatrace can help you accelerate your digital transformation and innovate faster.

The post Dynatrace achieves High certification under Spain’s National Security Framework (ENS) appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-achieves-high-certification-under-spains-national-security-framework-ens/feed/ 0
How Dynatrace supports the evolving sovereignty needs of EU organizations https://www.dynatrace.com/news/blog/how-dynatrace-supports-the-evolving-sovereignty-needs-of-eu-organizations/ https://www.dynatrace.com/news/blog/how-dynatrace-supports-the-evolving-sovereignty-needs-of-eu-organizations/#respond Thu, 17 Jul 2025 20:40:11 +0000 https://www.dynatrace.com/news/?p=70050 Security graphic

As digital transformation accelerates across Europe, data sovereignty has become a growing area of focus for public sector entities, financial institutions, telecom providers, and many other organizations operating in the EU. EU organizations are increasingly seeking to maintain control over their data, striving to ensure compliance with regional regulations and address geopolitical risk considerations. While […]

The post How Dynatrace supports the evolving sovereignty needs of EU organizations appeared first on Dynatrace news.

]]>
Security graphic

As digital transformation accelerates across Europe, data sovereignty has become a growing area of focus for public sector entities, financial institutions, telecom providers, and many other organizations operating in the EU. EU organizations are increasingly seeking to maintain control over their data, striving to ensure compliance with regional regulations and address geopolitical risk considerations. While most sectors don’t require full sovereign cloud solutions, there is an observable trend toward enhanced data sovereignty, encryption control, and transparency into data flows.

Understanding the drivers of EU sovereignty needs

During discussions with our customers, we noticed several developments that are contributing to the increased emphasis on sovereignty in the EU cloud landscape:

  • Regulatory: Regulations such as the General Data Protection Regulation (GDPR), Digital Operational Resilience Act (DORA), NIS2 Directive, and national-level data protection laws require organizations to retain control over data access, processing, and storage.
  • Geopolitical: Government agencies and regulated sectors seek to increase security and trust by reducing reliance and dependency on foreign jurisdictions, and by placing increased emphasis on minimizing unauthorized access and ensuring that data remains within their jurisdiction.
  • Economic: Organizations aim to future-proof their digital systems by increasing customer trust through transparency, autonomy, and improving operational and business resilience.
  • Strategic autonomy: EU initiatives, such as GAIA-X and related national programs, reflect policy interest in greater digital and technological independence.

How Dynatrace currently supports sovereignty requirements

Dynatrace provides capabilities designed to help organizations address sovereignty-related expectations while benefiting from SaaS observability:

  • EU hosting: Dynatrace allows customers to select data center regions within the EU when deploying on AWS, Azure, or GCP. This supports data residency requirements.
  • Security certifications: Dynatrace aligns with internationally recognized standards, including ISO 27001, SOC 2, and CSA STAR, and supports GDPR compliance. Visit the Dynatrace Trust Center for the full list.
  • Compliance and governance capabilities: Role-based access control (RBAC), SSO, SCIM provisioning, sensitive data handling, audit logging support, adherence to organizational security and regulatory practices, and more as described in Dynatrace Documentation.
  • Observability-driven sovereignty: With PurePath®, Smartscape®, and other core platform capabilities, Dynatrace provides end-to-end tracing, real-time topology mapping, and further support for data visibility and system behavior.
  • All data transfers are governed by EU Standard Contractual Clauses (SCCs) in alignment with GDPR requirements

Looking ahead: Enhancing support for data sovereignty

Dynatrace plans to expand support for sovereignty-focused use cases. Some of the upcoming developments include the release of Bring Your Own Key (BYOK) and Sensitive Data Scanner*.

BYOK is expected to allow customers to manage and retain control over the encryption keys used for securing observability data. This is intended to support:

  • Jurisdictional control: Customers can benefit from increased governance by managing their own encryption keys.
  • Trust and transparency: Organizations can align with internal data protection policies and sector-specific requirements.

Sensitive Data Scanner adds another level of protection to Dynatrace’s existing sensitive data masking capabilities. It monitors Grail for unintentionally ingested sensitive data in logs, allowing customers to validate their masking configuration, quickly identify and respond to inconsistencies, and take precise and targeted corrective action for future data ingestion and sensitive data that has already been ingested, such as adjusting access permissions and retention periods, deleting sensitive data, and updating masking rules to prevent sensitive data types from being stored in the future.

Supporting the public sector and regulated industries

For use cases that require enhanced privacy or offline environments, Dynatrace also offers Dynatrace Managed as an on-premises solution, giving you greater control over operations and data. This alternative can be particularly relevant for highly regulated government entities that require such control.

Dynatrace recognizes that sovereignty requirements vary by sector and region. We’re focused on providing secure and flexible observability solutions that support compliance and transparency in accordance with customer and regulatory expectations.

Sovereignty isn’t just about where your data lives—it’s about who governs it. And Dynatrace can help you govern your data better.

What’s next

Share this blog post with your security or compliance teams to help them understand how Dynatrace supports their data and digital sovereignty requirements. (To email this blog post, select the email icon at the top of the page.)

Contact us if you want to learn more and discuss how Dynatrace supports your data and digital sovereignty requirements.

* This blog post contains forward-looking statements. These statements reflect current views and assumptions, but results might differ due to various risks or plan changes.

The post How Dynatrace supports the evolving sovereignty needs of EU organizations appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/how-dynatrace-supports-the-evolving-sovereignty-needs-of-eu-organizations/feed/ 0
Unlocking sovereignty with Dynatrace and Deloitte https://www.dynatrace.com/news/blog/unlocking-sovereignty-with-dynatrace-and-deloitte/ https://www.dynatrace.com/news/blog/unlocking-sovereignty-with-dynatrace-and-deloitte/#respond Wed, 04 Jun 2025 18:11:54 +0000 https://www.dynatrace.com/news/?p=69371 Gen AI graphic

Organizations are under growing pressure to exercise autonomy over their digital assets while maintaining operational performance in hybrid and multi-cloud environments. The concept of cloud sovereignty — minimizing external dependencies and exerting full control over data, applications, and infrastructure — has become a critical business imperative. In collaboration with Deloitte, Dynatrace has crafted a comprehensive […]

The post Unlocking sovereignty with Dynatrace and Deloitte appeared first on Dynatrace news.

]]>
Gen AI graphic

Organizations are under growing pressure to exercise autonomy over their digital assets while maintaining operational performance in hybrid and multi-cloud environments. The concept of cloud sovereignty — minimizing external dependencies and exerting full control over data, applications, and infrastructure — has become a critical business imperative.

In collaboration with Deloitte, Dynatrace has crafted a comprehensive whitepaper, “Observability for sovereignty: The keystone for compliance & control,” exploring how enterprise observability can drive sovereignty and showcasing real-world use cases and practical insights.

The importance of observability to sovereignty

Cloud sovereignty is more than just data residency compliance; it encompasses security, resilience, and operational traceability. With increasing political scrutiny and more stringent cybersecurity regulations, organizations must have comprehensive observability to monitor, detect, and respond to ICT risks across their operational ecosystems.

With a comprehensive observability platform, organizations can take advantage of the following benefits:

  • Support in operational compliance and regulatory adherence. The Dynatrace platform provides continuous monitoring across hybrid and multi-cloud environments, delivering real-time observability into system behavior and access patterns. This transparency supports data residency, operational traceability, and audit readiness—key components of cloud sovereignty—while helping organizations align with regional compliance requirements.
  • Strengthened security and risk management. Early threat detection and rapid incident response mitigate risks associated with unauthorized access, data breaches, and sovereignty-related IT challenges.
  • Optimized cloud performance and resilience. AI-driven insights and automation help achieve operational continuity, reduce downtime, and identify resilience and dependency risks over critical workloads and data.
  • Greater autonomy from providers. A comprehensive observability strategy enables organizations to identify their level of reliance on cloud vendors, assess the impact of different deployment models, and embrace resilient strategies aligned with business objectives.

Achieving these crucial sovereignty benefits requires technology capable of providing complete, uninterrupted visibility across complex environments — precisely where core tracing capabilities from the Dynatrace platform excel.

The role of the Dynatrace observability platform in cloud sovereignty

The cutting-edge observability platform from Dynatrace, combined with Deloitte’s deep-industry and cloud-engineering expertise, supports organizations’ ability to meet their sovereignty requirements. PurePath® is at the heart of the Dynatrace platform’s DNA. The patented distributed tracing technology delivers continuous, end-to-end visibility into application transactions and data flows. With capabilities like automated topology mapping, distributed trace analysis, and real-time anomaly detection, observability solutions like the Dynatrace platform can help institutions maintain service continuity and detect operational issues that could impact compliance or service-level obligations in regulated markets. Check out the video below to learn how enterprises can address data sovereignty challenges using AI-powered observability.

Analyzing real-world applications of observability

With its comprehensive tracing capabilities that provide unparalleled visibility and control, the Dynatrace observability platform should be a cornerstone of data sovereignty.

The whitepaper delves into practical applications of observability in highly-regulated sectors, such as healthcare and financial institutions that may need to retain data in specific geographical locations.

These institutions must implement best practices to meet regulatory obligations, customer expectations, and reduce risks, safeguarding sensitive data and strengthening resilience against cyber threats. By delivering end-to-end visibility into application performance, infrastructure behavior, and user interactions, observability platforms like Dynatrace help financial institutions detect anomalies, trace root causes, and demonstrate operational traceability—key requirements for maintaining regulatory readiness in complex environments.

The evolution of sovereignty is increasingly shaped by regulatory, geopolitical, and technological forces. Organizations should adopt integrated, compliance-driven architectures to navigate this complex landscape.

Key takeaways include the following:

  • Consider observability as a key enabler. Sovereignty is about control, transparency, and strategic autonomy — not just regulatory box-checking.
  • Embrace sovereignty by design, powered by observability. Integrate sovereignty into the design phase to prevent compliance and security risks before they occur in production.
  • Scale sovereignty through a PoC with measurable outcomes. Dynatrace and Deloitte help organizations embed observability into their cloud strategy through scalable approaches with measurable benefits.

Achieving true cloud sovereignty requires more than just meeting regulatory mandates — it demands a comprehensive approach that enables organizations to reevaluate their cloud strategies. Industry-leading observability solutions from Dynatrace, combined with Deloitte’s expertise in cloud engineering and regulatory strategy, empower organizations to take ownership of their cloud environments with a seamless path to cloud sovereignty.

Read the whitepaper: Unlocking cloud sovereignty with Dynatrace and Deloitte to discover how observability can transform your approach to cloud sovereignty, ensuring compliance, security, and operational resilience.

___

© 2025 Dynatrace LLC

Dynatrace and the Dynatrace logo, are trademarks of the Dynatrace, Inc. group of companies. All other trademarks are the property of their respective owners.

The post Unlocking sovereignty with Dynatrace and Deloitte appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/unlocking-sovereignty-with-dynatrace-and-deloitte/feed/ 0
Efficiently manage sensitive data and privacy requirements at scale on the Dynatrace platform https://www.dynatrace.com/news/blog/manage-sensitive-data-and-privacy-requirements-at-scale/ https://www.dynatrace.com/news/blog/manage-sensitive-data-and-privacy-requirements-at-scale/#respond Fri, 30 May 2025 13:54:55 +0000 https://www.dynatrace.com/news/?p=69296 Database securtiy

Complex systems and IT environments generate increasingly more observability data and signals than ever before. Not only do observability platforms need to manage the scale of this data efficiently, they must also provide safeguards that allow their customers to control and protect their sensitive data in compliance with an evolving regulatory landscape while not reducing the value they provide to their users and customers, whether it’s personal data, payment data, health information, or any other sensitive data requiring protection.

The post Efficiently manage sensitive data and privacy requirements at scale on the Dynatrace platform appeared first on Dynatrace news.

]]>
Database securtiy

In this blog post, you’ll learn how Dynatrace allows you to manage observability data at scale by providing sensitive data handling capabilities across the entire data lifecycle on the Dynatrace platform. Preventing sensitive data from leaving the customers environment, using OpenPipeline™ to efficiently enrich, contextualize and ingest huge volumes of data, leveraging Grail™ data lakehouse for unified storage for all data types, with a wide range of regions to select from to meet your data residency needs, and leveraging other platform capabilities such as controlling access to data, or enabling to delete only the selected records permanently, helps significantly reduce the complexity of managing different data types typically stored in silos.

Why sensitive data management is important

Whether a bank, government, or airline, observability is no longer optional for any organization’s IT systems that must provide high-quality and secure services to its customers and end-users. These systems generate vast amounts of data, and sensitive data might be embedded in such large-scale volumes of data.

To maintain customer trust and comply with stringent regulatory requirements, such as GDPR or HIPAA, organizations need to manage sensitive data appropriately, not only in their own IT environment but also in their observability platform and other third-party services. Sensitive data isn’t required for the majority of observability use cases. Organizations should control which data is captured, how it’s processed, where it’s stored, and who can access it. Additionally, organizations must promptly address data subject and privacy rights requests and adhere to retention periods, all in line with their privacy policies and regulations.

Manage sensitive data at scale in complex IT environments

Big IT environments often use thousands of apps and digital services managed by different teams. Each app generates a significant amount of observability data, often with different structures and sensitive data types. In such complex environments, it’s essential to not only detect sensitive data and configure how the observability platform handles such data but also validate that the configuration works as intended and permanently remove selected sensitive data, if needed, without compromising the remaining data and the larger dataset.

End-to-end sensitive data handling in Dynatrace

The Dynatrace data lifecycle consists of five steps.

End-to-end sensitive data handling in five steps with DynatraceWhile all data sent to Dynatrace is encrypted in transit and storage, each step provides you with the capabilities and controls needed to manage your sensitive data. While this blog post focuses on privacy controls and managing sensitive data in Dynatrace, you might be interested in how Dynatrace protects your data overall. Check our Trust Center for an overview or Dynatrace Documentation for the complete list and description of security and privacy controls in Dynatrace.

1. Data capture

When using Dynatrace OneAgent® and Dynatrace Collector for OpenTelemetry data, sensitive data matching the masking rules is irreversibly redacted at its first contact with Dynatrace and doesn’t leave the monitored environment.

This is often a crucial requirement for organizations operating in highly regulated industries. Take, for example, a financial institution using Dynatrace Log Analytics to monitor and analyze SWIFT message logs across its global infrastructure. These logs and other user behavioral data are essential for tracking transaction flows, detecting anomalies, and ensuring regulatory compliance. However, given the sensitive nature of the data, such as account identifiers and payment instructions, they must enforce robust privacy controls to comply with regulations like GDPR and other industry standards. One of those rules is that sensitive data must not leave their environment.

To address this, the institution leverages Dynatrace’s multi-layered data masking capabilities. Before log data leaves the environment, Dynatrace OneAgent applies user-configured masking rules at capture to, for example, allow for the redacting of the account number, name, date of birth, and address of the account holder and beneficiaries.

2. Data processing

Data sent to Dynatrace is processed in OpenPipeline™, a powerful solution for ingesting and enriching huge volumes of data quickly and cost-effectively, while allowing configuration to allow secure and compliant collection and processing. With OpenPipeline, organizations can define processing rules that automatically mask or redact sensitive data such as credit card numbers, email addresses, or IP addresses, regardless of the source. This approach allows flexible, centralized masking, protecting sensitive data before it‘s stored or made available for analysis.

3. Data storage

Data localization and residency are becoming increasingly important for organizations to address various strategic, regulatory, and operational requirements. By keeping data within specific geographic regions, organizations can comply with local laws, regulations, and sector-specific requirements. For this purpose, Dynatrace can be deployed to AWS, Azure, and Google Cloud regions across the globe and thus support most of its customers in storing their data within their preferred region.

Data storage regions used by Dynatrace

Data ingested into Dynatrace is stored in the Grail™ data lakehouse, a unified data storage system for unifying and contextually analyzing observability, security, and business data at any scale.

In addition to the location where sensitive data is stored, it’s crucial not to store such data for longer than needed. Dynatrace allows configurable retention periods for custom Grail buckets, such as up to 10 years for logs and distributed traces.

Some customers also store logs for audit purposes. Depending on your country and industry, you might be required to store audit logs for five or even up to 10 years, a practice your Dynatrace tenant supports.

The logs stored in Grail are always accessible by any app and user who has permission to do so. This minimizes the time and cost in case historical data must be accessed by an auditor, as there is no such process of rehydration or concept of hot/cold-storage tiers.

Dynatrace makes subject rights management easy with the Privacy Rights app. Authorized users can efficiently search for all personal data related to a specific individual, review the results, and approve export or deletion requests in a secure, auditable workflow meeting regulatory deadlines. This helps organizations fulfill data subject rights requests, such as those required under GDPR and CCPA.

4. Data access

Granular and configurable data access is essential for protecting sensitive data and ensuring only authorized users can view and interact with stored data. Grail access in Dynatrace is managed through a flexible, fine-grained permission system that allows administrators to control who can access data at multiple levels, from buckets to tables and records down to the field level.

A healthcare diagnostics provider partnered with us to enhance their observability while ensuring HIPAA compliance and protecting PHI/PII. In addition to masking and redacting PHI/PII fields at ingest, they configured granular field-level access controls, allowing their teams to view only the data relevant to their roles. This way, Dynatrace empowers providers with secure, compliant, actionable insights from their logs without compromising patient privacy.

Notebook of healthcare diagnostics in Dynatrace screenshot

5. Data deletion

Dynatrace allows organizations to meet strict privacy and compliance requirements by supporting hard deletion of individual records in Grail. This capability, available via Grail API and Privacy Rights, ensures that information can be securely and permanently removed at the record level, without impacting the integrity or availability of other valuable data. An audit trail is maintained for deletions directly executed through the API and those orchestrated by the Privacy Rights app. Unlike soft deletion, which might only hide data, hard deletion in Grail guarantees that deleted records are irreversibly erased, reducing the risk of unauthorized access and supporting full regulatory compliance.

Sensitive Data Center

Later this year, Dynatrace will start integrating its sensitive data handling capabilities into the new Sensitive Data Center* to help streamline the management of sensitive data. In the first step, we’ll combine the existing Privacy Rights with the planned, and currently in development, Sensitive Data Scanner*.

Sensitive Data Scanner adds another level of protection to Dynatrace’s existing sensitive data masking capabilities. It monitors Grail for unintentionally ingested sensitive data in logs, allowing customers to validate their masking configuration, quickly identify and respond to inconsistencies, and take precise and targeted corrective action for future data ingestion and sensitive data that has already been ingested, such as adjusting access permissions and retention periods, deleting sensitive data, and updating masking rules to prevent sensitive data types from being stored in the future.

Summary

You’ve learned about how Dynatrace helps you manage sensitive data securely and in compliance with regulations throughout its lifecycle. Dynatrace focuses on privacy from the moment data is captured, using advanced masking techniques to prevent sensitive information from leaving the environment, and through centralized data processing and unified data storage, including supporting data residency and retention controls. Dynatrace supports compliance for many global and industry-specific standards. Fine-grained access controls and hard-deletion capabilities further empower organizations to manage data governance and fulfill privacy obligations like GDPR and CCPA. Overall, Dynatrace offers a comprehensive, privacy-first approach to observability that aligns with operational needs and regulatory demands.


* This blog post contains forward-looking statements. These statements reflect current views and assumptions, but results might differ due to various risks or plan changes.

The post Efficiently manage sensitive data and privacy requirements at scale on the Dynatrace platform appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/manage-sensitive-data-and-privacy-requirements-at-scale/feed/ 0
Dynatrace on Microsoft Azure achieves PROTECTED status in Australian government IRAP assessment https://www.dynatrace.com/news/blog/dynatrace-on-microsoft-azure-achieves-protected-status-in-australian-government-irap-assessment/ https://www.dynatrace.com/news/blog/dynatrace-on-microsoft-azure-achieves-protected-status-in-australian-government-irap-assessment/#respond Mon, 07 Apr 2025 23:00:17 +0000 https://www.dynatrace.com/news/?p=68667 Dynatrace on Microsoft Azure achieves PROTECTED status in Australian government IRAP assessment

Dynatrace SaaS on Microsoft Azure received independent validation that it meets the PROTECTED level of the Australian government’s Information Security Manual (ISM) following an assessment conducted by an Information Security Registered Assessors Program (IRAP) certified assessor against the ISM.  

The post Dynatrace on Microsoft Azure achieves PROTECTED status in Australian government IRAP assessment appeared first on Dynatrace news.

]]>
Dynatrace on Microsoft Azure achieves PROTECTED status in Australian government IRAP assessment

The Australian Cyber Security Center (ACSC) created the ISM framework to provide practical guidance and principles to protect organizations’ IT and operational technology systems, applications, and data from cyber threats. The Australian Signals Directorate created the IRAP to create a pool of assessors capable of conducting high-quality assessment services. Endorsed IRAP Assessors independently assess organizations’ cybersecurity postures, identifying security risks and suggesting mitigation measures. All Australian Commonwealth entities must comply with the Protective Security Policy Framework. The ISM is the cybersecurity framework that facilitates compliance.

Dynatrace previously achieved PROTECTED status for deploying the Dynatrace platform on Amazon Web Services (AWS). The new assessment demonstrates that Australian government agencies and highly regulated enterprises, such as utilities, healthcare, and financial services providers, can deploy Dynatrace on Microsoft Azure. This empowers these organizations to deliver automation and intelligence at scale, unlocking deeper business insights and faster time to value, knowing that their data resides in a Microsoft Azure environment in Sydney that meets high standards.

Breaking down the advantages of a unified observability platform

With the Dynatrace unified observability platform, Australian government agencies can:

  • Gain real-time visibility into the performance and availability of infrastructure and applications.
  • Deliver high-quality, cloud-native applications to accelerate innovation.
  • Identify, prioritize, and resolve service-affecting issues to deliver seamless user experiences.
  • Automate repetitive and time-consuming manual tasks, freeing skilled IT resources to focus on strategic initiatives and automation that can be triggered anytime without manual interaction.
  • Adopt shift-left development practices to make applications more secure by automating vulnerability detection and resolution before they can be exploited.
  • Overcome the complexity of cloud-native environments and stay ahead of regulatory reporting rules by automating continuous discovery, proactive anomaly detection, and optimization across the software development lifecycle.
  • Create a single source of truth about the health of IT services to facilitate closer collaboration between development, operations, and security teams, as well as support the adoption of DevSecOps practices.

Data protection is a growing challenge

All organizations must implement adequate controls to ensure the integrity and security of their data. Government agencies are under added pressure, and as they continue to digitally transform, the complexity of their systems increases.

Data is distributed across multiple platforms and applications, making it more difficult to ensure adequate controls. Common challenges include the following:

  • Data residency. Government agencies need to maintain complete control and transparency of where their data is stored, especially when using cloud services. Highly sensitive data is subject to stringent residency requirements, meaning it can’t be stored outside the country of origin.
  • Securing data throughout the vendor ecosystem. The process of assessing a vendor’s security, privacy, and compliance posture and validating they meet the stringent requirements of the Australian government is often time-consuming and cumbersome.
  • Continuous compliance. It’s essential to remain compliant with security and privacy requirements on an ongoing basis rather than treat them as an annual check-box exercise. With rapidly evolving threats and regulatory requirements, it’s crucial for organizations to stay ahead of the curve and continuously improve their security posture.

Keep your data secure with Dynatrace

Dynatrace was purpose-built to process and query massive volumes of data. Therefore, it has comprehensive controls to protect customer data and is constantly investing in these capabilities to stay ahead of evolving market standards and regional and sector-specific needs.

Key Dynatrace capabilities that help Australian government agencies protect their data include the following:

  • Dynatrace operates its AI-powered unified observability and security platform as a SaaS solution in 20 worldwide regions. By allowing customers to choose where their data resides, Dynatrace assists them in meeting their country- and sector-specific regulations.
  • Dynatrace proactively engages with highly qualified and independent assessors to validate its security, privacy, and compliance posture against the ISM control framework. This simplifies and accelerates the due diligence process for Australian government agencies and other highly regulated enterprises.

Independent software vendors (ISVs) such as Dynatrace can demonstrate their security posture level according to the Australian government’s ISM. This process evaluates risk assessments, access controls, incident response strategies, and sensitive data handling to ensure the vendor maintains robust security practices.

Completing this additional assessment for Dynatrace on Azure is the latest validation of its rigorous security, privacy, and compliance posture. The Dynatrace Trust Center provides a complete overview of the certifications, laws, and standards with which the Dynatrace platform complies.

Get started with Dynatrace on Azure

Australian government agencies that want to learn more about how Dynatrace on Azure can improve their operations and accelerate innovation should contact us or check out our free trial via the marketplace.

Microsoft Azure is a registered trademark of the Microsoft group of companies.

Dynatrace and the Dynatrace logo are trademarks of the Dynatrace, Inc. group of companies. All other trademarks are the property of their respective owners.

The post Dynatrace on Microsoft Azure achieves PROTECTED status in Australian government IRAP assessment appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-on-microsoft-azure-achieves-protected-status-in-australian-government-irap-assessment/feed/ 0
How automation helps financial institutions efficiently achieve continuous compliance with DORA https://www.dynatrace.com/news/blog/financial-institutions-achieve-dora-compliance-with-automation/ https://www.dynatrace.com/news/blog/financial-institutions-achieve-dora-compliance-with-automation/#respond Tue, 28 Jan 2025 17:00:14 +0000 https://www.dynatrace.com/news/?p=67479 Digital Operational Resilience Act (DORA) graphic

The Digital Operational Resilience Act (DORA) is a pivotal regulation for financial institutions in the European Union (EU), designed to ensure operational resilience and safeguard against cyber threats. Complying with DORA is a strategic yet resource-intensive initiative for financial institutions operating in the EU. Dynatrace analysis suggests that by leveraging the unified observability and security capabilities in Dynatrace, organizations can automate up to 80% of the technical tasks necessary to manage DORA compliance, which reduces the time and personnel required. This reduction also helps enhance accuracy and efficiency, minimizing non-compliance risk. Dynatrace automated processes help with continuous monitoring, providing real-time insights and proactive management of compliance requirements.

The post How automation helps financial institutions efficiently achieve continuous compliance with DORA appeared first on Dynatrace news.

]]>
Digital Operational Resilience Act (DORA) graphic

Automation can help European banks save 50-70% of effort in DORA compliance

The journey to continuous DORA compliance can be summarized in three steps:

  1. Continuous monitoring of IT environments
  2. Proactive incident prevention and handling
  3. Ongoing management of compliance requirements

These efforts demand significant resources, time, and operational bandwidth. Manual processes are prone to human error and inefficiencies which can lead to compliance gaps, posing substantial risks to financial institutions. The strain on resources can divert attention from core business activities, negatively impacting overall productivity and growth.

“We estimate that with Dynatrace, organizations can automate up to 80% of the technical tasks necessary to be DORA compliant, helping reduce the overall required time and personnel by 50-70%. Unifying observability and security not only helps save significant time and effort, it also provides the necessary visibility into the organization’s IT environment and helps to achieve continuous compliance, said Bernd Greifeneder, Founder and Chief Technology Officer, Dynatrace.

Customers have shared that our platform has helped them save significant time and increase productivity by reducing mean time to discovery (MTTD) by 99%, time spent on root cause analysis by 80%, and mean time to resolution by 80%, among many other customer success stories with Dynatrace. Taking those into account and understanding how we use Dynatrace for self-monitoring, our analysis suggests that using unified observability and security from Dynatrace can lead to saving up to 50% – 70% of the effort required to manage DORA compliance.

Based on the above, we estimate the following effort needed for DORA compliance in a medium to large bank operating in multiple EU markets, with 5,000 to 20,000 employees.

Estimated effort for DORA compliance with minimum automation

  • Initial phase (12 – 24 months): 50 – 100 people
  • Ongoing management: 20 – 30 people

Estimated effort for DORA compliance with automation

  • Initial phase (6 – 12 months): 20 – 60 people
  • Ongoing management: 5 – 10 people

Continuous monitoring of IT environments

Because DORA requires continuous compliance, a snapshot of an institution’s compliance with DORA is often insufficient. In complex IT environments, new services, applications, and other components can be added or removed at any time. Manually monitoring those changes and updating the map of the entire IT environment each time a change occurs is quite labor intensive.

Dynatrace helps cross-functional teams (comprising IT managers, compliance officers, risk managers, and others) save significant amounts of time through real-time monitoring of the entire IT environment. Dynatrace provides up-to-date network maps, identifies critical services, and highlights gaps in coverage.

Proactive incident prevention and handling

Reacting quickly to incidents when they occur isn’t sufficient. Any incident can negatively impact service availability, and even a swift reaction might not prevent financial, reputational, or societal damage from happening. Proactive risk management and prevention are crucial and are reflected in DORA and other similar frameworks.

In a continuously monitored IT environment and leveraging Davis® AI, Dynatrace helps security and incident response teams detect abnormal behavior, identify root causes, and detect vulnerabilities and attacks on your IT environment—all in real time, with prioritization based on business impact. Remediation activities can be triggered automatically, supporting timely and efficient incident handling.

Ongoing management of compliance requirements

DORA comes with technical best practices and standards for IT environments. Tracking, validating, and remediating potential findings is a labor-intensive task necessary to keep the environment compliant and provide evidence for auditing.

Dynatrace helps IT and compliance teams continuously assess their IT environments against DORA standards, at scale, and relative to current and future growth. Dynatrace gathers all relevant findings on security posture with full context and creates a holistic and intuitive way to prioritize, remediate, and report on those findings.

Increase productivity beyond DORA compliance

Dynatrace helps simplify the compliance process and delivers substantial value to organizations. By automating compliance efforts, you can:

  • Reduce operational costs: Lower the personnel and time required for compliance.
  • Enhance accuracy and efficiency: Minimize human error and increase productivity in achieving continuous compliance.
  • Improve operational resilience: Proactively manage compliance and mitigate risks.
  • Focus on core business activities: Free up resources to drive growth and innovation.

Based on the above-mentioned use case for DORA compliance, we estimate that adopting Dynatrace can help organizations save significant time and resources needed to achieve and manage DORA, NIS2, PS21/3, CPS 230, and similar cybersecurity and resilience compliance frameworks, translating into substantial cost savings and operational efficiencies.

What next?

In the face of stringent regulatory requirements, automating DORA compliance with Dynatrace offers a strategic advantage for financial institutions. It assists with efforts to achieve continuous compliance and helps enhance operational resilience, reduce costs, and free up resources for core business activities. Integrating Dynatrace into organizations’ compliance strategy can be a valuable step for executives and senior management to help secure their organizations’ future.

Read the blog post, Dynatrace for executives: Security compliance from our CTO, to understand better how integrating Dynatrace into your compliance strategy helps your business be more resilient and compliant and provides a strategic advantage in today’s dynamic regulatory landscape.

Contact us to learn more about how Dynatrace can help transform your approach to DORA compliance and operational resilience.

Disclaimer: The estimated effort savings are based on analyzing how customers use Dynatrace and on internal research. They are intended for informational purposes only. Actual results may vary depending on individual organizational factors. Organizations should conduct their own assessments and planning to determine the most appropriate approach for achieving and managing DORA compliance. Dynatrace does not guarantee specific outcomes or savings.

The post How automation helps financial institutions efficiently achieve continuous compliance with DORA appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/financial-institutions-achieve-dora-compliance-with-automation/feed/ 0
Dynatrace platform receives TX-RAMP Level 2 certification https://www.dynatrace.com/news/blog/dynatrace-platform-receives-tx-ramp-level-2-certification/ https://www.dynatrace.com/news/blog/dynatrace-platform-receives-tx-ramp-level-2-certification/#respond Fri, 17 Jan 2025 17:02:51 +0000 https://www.dynatrace.com/news/?p=67341 Dynatrace platform receives TX-RAMP Level 2 certification

We're excited to announce that Dynatrace has successfully expanded its TX-RAMP Level 2 certification to the latest Dynatrace® platform. This certification demonstrates to Texas state agencies and educational institutions that the Dynatrace platform for observability and security meets the strict security and compliance standards required to enable secure and flawless digital interactions and drive digital transformation initiatives at scale.

The post Dynatrace platform receives TX-RAMP Level 2 certification appeared first on Dynatrace news.

]]>
Dynatrace platform receives TX-RAMP Level 2 certification

What is TX-RAMP?

The Texas Risk and Authorization Management Program (TX-RAMP) provides a standardized approach for security assessment, certification, and continuous monitoring of cloud computing services that process the data of Texas state agencies. TX-RAMP certification requires cloud service providers to meet the stringent security and privacy standards set by the Texas Department of Information Resources (DIR).

TX-RAMP Level 2 Certification is the required minimum certification level for a cloud computing service that processes, stores, or transmits agency data determined to be confidential and from a moderate or high-impact information resource.

Dynatrace partners with Texas state institutions

Dynatrace partners with public sector agencies in the US and globally to ensure that essential government and educational institutions deliver resilient, efficient, and secure services. Complex IT environments that house these services are often built on hybrid and multicloud architectures. Ensuring application security, resilience, and efficient operations with limited resources in the public sector requires a solution that provides precise answers and intelligent automation from enormous amounts of cloud data while meeting the strictest cybersecurity standards.

Receiving TX-RAMP Level 2 certification confirms that the Dynatrace platform meets these standards and allows Texas state institutions to ensure flawless and secure digital services for its residents.

Unified observability and security accelerate digital transformation initiatives

Satisfaction with services provided by state and local government agencies strongly influences trust in those agencies. The opportunities that digital and cloud-based technologies provide constantly increase expectations for providing these services digitally and without disruptions. To achieve this, state and local government agencies must undergo digital transformation so that their services are cost-efficient, secure, and resilient.

Whether in an enterprise or state agency, technology executives are aware that observability is the foundation for managing the health of cloud and IT services. The right observability platform with observability, security, and other data in context makes the difference in increasing IT productivity, reducing business risks, optimizing costs, and reducing carbon footprint.

Our commitment to enterprise-level security

As shown by our broad range of certifications and accreditations, security is a core value at Dynatrace. Adding TX-RAMP highlights our dedication to excellence. We’re focused on ongoing improvements to maintain the highest security standards and deliver exceptional service, providing our customers with a safe and governed environment.

What’s next

Contact Dynatrace to discuss how we can support your cloud transformation and provide cost-efficient, resilient and secure services for Texas residents.

The post Dynatrace platform receives TX-RAMP Level 2 certification appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-platform-receives-tx-ramp-level-2-certification/feed/ 0
Build resilient IT systems and manage regulatory requirements with compliance and resilience capabilities from Dynatrace https://www.dynatrace.com/news/blog/manage-compliance-and-resilience-at-scale-with-dynatrace/ https://www.dynatrace.com/news/blog/manage-compliance-and-resilience-at-scale-with-dynatrace/#respond Thu, 16 Jan 2025 01:00:01 +0000 https://www.dynatrace.com/news/?p=67183 Security compliance graphic

By leveraging Dynatrace unified observability and security, you can automate up to 80% of the technical tasks necessary for managing compliance and resilience at scale. This approach addresses the dynamic global regulatory requirements for operational resilience, emphasizing the growing reliance on secure, resilient, and dependable IT environments.

The post Build resilient IT systems and manage regulatory requirements with compliance and resilience capabilities from Dynatrace appeared first on Dynatrace news.

]]>
Security compliance graphic

The Importance of Resilience in a Complex Regulatory Landscape

In today’s digital age, operational resilience is paramount for businesses striving to maintain seamless operations and safeguard their reputation. The ability to quickly react to incidents is no longer sufficient; organizations must proactively prevent issues and manage risks to ensure continuous service delivery. This need is amplified by an increasingly complex regulatory and compliance landscape, where global standards demand stringent measures to protect data, ensure service continuity, and mitigate risks.

Navigating these regulations while maintaining high performance and security standards is challenging. Non-compliance can lead to operational disruptions, severe penalties, and reputational damage. Therefore, achieving operational resilience is not just about compliance; it’s about ensuring long-term sustainability and protecting the business against potential threats.

Dynatrace: Your Partner in Compliance and Resilience

Compliance and resilience capabilities leverage the industry-leading Dynatrace platform for unified observability and security, including the upcoming Compliance Assistant app for DORA compliance. They offer a comprehensive solution to these challenges, providing functionalities designed to enhance compliance and resilience in IT environments. Here’s how Dynatrace can help automate up to 80% of technical tasks required to manage compliance and resilience:

  • Understand the complexity of IT systems in real time
  • Proactively prevent, prioritize, and efficiently manage performance and security incidents
  • Automate manual and routine tasks to increase your productivity

Understand the complexity of IT systems in real time

Dynatrace helps you comprehensively map the entire IT environment in real time. It gives you visibility into which components are monitored and which are not and helps automate time-consuming compliance configuration checks.

Discovery & Coverage helps prevent unexpected outages by detecting and remediating monitoring coverage gaps across your entire enterprise.

Discovery & Coverage

Smartscape topology visualizes the relationships between applications, services, processes, hosts, and data centers, highlighting problems and vulnerabilities.

Smartscape

Security Posture Management helps detect, visualize, analyze, and remediate security posture and compliance findings, including misconfigurations and regulatory compliance assessments.

Security Posture Management

Compliance Assistant provides a dedicated view tailored for the European Union Digital Operational Resilience Act (DORA).

Compliance Assistant

Proactively prevent and prioritize performance and security incidents

Dynatrace helps you focus on preventing incidents before they occur, managing risks proactively, and prioritizing incidents for remediation when they occur.

Problems utilizes Davis® AI to automatically analyze your system and detect abnormal behavior, such as performance or stability issues. It also investigates an incident’s impact and root cause and reduces the mean time to repair.

Problems dashboard

Vulnerabilities is our Dynatrace Runtime Vulnerability Analytics platform experience for detecting, visualizing, analyzing, monitoring, and remediating vulnerabilities across your application stack.

Vulnerabilities dashboard

Attacks helps you get a real-time overview of all the attacks in your environment. Leveraging code-level insights and transaction analysis, Dynatrace Runtime Application Protection automatically detects attacks on applications in your environment.

Application Security attacks dashboard

Site Reliability Guardian provides an automated change impact analysis to validate service availability, performance, and capacity objectives across various systems. This enables DevOps platform engineers to make the right release decisions for new versions and empowers SREs to apply Service-Level Objectives (SLOs) for their critical services.

Site Reliability Guardian dashboard

Automate manual tasks to increase productivity

Automation in Dynatrace allows you to automate tasks in your IT landscape, remediate problems, and visualize processes to increase productivity and focus on strategic initiatives.

Workflows assembles a series of actions to build processes in graphical representations. Workflows can be triggered manually, on a schedule, or by events in Dynatrace, such as anomalies detected by Davis® AI.

Workflows in Dynatrace

What’s next

Read Dynatrace for executives: Security compliance, a blog post from our CTO, to learn more about staying ahead of the curve and helping your business be more resilient and compliant in today’s dynamic regulatory landscape. Contact us for a personalized demo to learn more about how Dynatrace can transform your approach to compliance and resilience.

Ready to try out compliance and resilience tools at scale?

The post Build resilient IT systems and manage regulatory requirements with compliance and resilience capabilities from Dynatrace appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/manage-compliance-and-resilience-at-scale-with-dynatrace/feed/ 0
Navigate end-to-end data compliance through effective log management https://www.dynatrace.com/news/blog/navigate-end-to-end-data-compliance-through-effective-log-management/ https://www.dynatrace.com/news/blog/navigate-end-to-end-data-compliance-through-effective-log-management/#respond Tue, 03 Dec 2024 06:08:35 +0000 https://www.dynatrace.com/news/?p=66927 Log management graphics

Log management with end-to-end compliance is imperative for your business's success. Dynatrace provides an end-to-end log management compliance guide that supports you in enhancing security, ensuring compliance, and building a foundation of trust with your customers. Investing in effective log management and ensuring that compliance requirements are met not only safeguards sensitive information but also drives operational excellence.

The post Navigate end-to-end data compliance through effective log management appeared first on Dynatrace news.

]]>
Log management graphics

Log management with adherence to industry-specific compliance requirements is more critical than ever. With an increasing number of regulations and standards governing how businesses handle data, an end-to-end compliance strategy is crucial. Administrators who work with developers and product managers responsible for instrumenting, managing, and achieving the business goals of applications benefit from Dynatrace log management. As the volume and complexity of data increase, understanding and managing logs effectively to reach compliance is essential.

The importance of compliance for end-to-end log data

End-to-end compliance refers to the ability to ensure that all aspects of an organization’s operations meet regulatory standards from start to finish. This holistic approach is particularly critical in industries handling sensitive data, such as the healthcare and financial sectors.

Figure 1. These logs contain sensitive healthcare data. Retention periods and access controls must be properly configured to protect such PII.
Figure 1. These logs contain sensitive healthcare data. Retention periods and access controls must be properly configured to protect such PII.

Holistic risk management: End-to-end compliance provides a comprehensive view of risk across the organization. By ensuring that all processes—from data collection to storage and usage—comply with regulatory requirements, organizations can better manage potential threats.

Build trust with your customers: Consumer trust is vital in sectors like e-commerce and healthcare. Demonstrating a commitment to protecting end-user data through compliant log management can enhance brand reputation and customer loyalty.

Streamlined audits: End-to-end compliance simplifies the audit process. With centralized log data, you can provide auditors with clear and comprehensive records, reducing the time and effort required for compliance checks.

Implement Dynatrace Log Management and Analytics with end-to-end compliance

Organizations should consider the following steps to effectively implement log management and ensure end-to-end compliance. Use our log management compliance guide to leverage the configuration options Dynatrace provides to address your regulatory and compliance requirements for log management.

  1. Outline your organization’s data compliance requirements: Create policies for log management and compliance requirements based on your log management use case, ensuring your employees understand their roles and responsibilities.
  2. Equip your compliance teams: Enrich your team’s knowledge of the Dynatrace capabilities that are required to ensure compliance with log data privacy and foster a culture of accountability.
  3. Continuous improvement: Regularly assess your log management processes and compliance measures to identify areas for improvement and adapt to changing regulations

Our log management compliance guide explores three compliance-relevant use cases. These use cases can help you identify which configuration options you should consider for your environment:

  • Optimize e-commerce conversion rates: Leverage Dynatrace log data to enhance user experience and increase conversion rates while maintaining compliance through data masking and controlled access.
  • Monitor healthcare service logs in patient portals: Dynatrace has provisions that safeguard sensitive patient data and ensure compliance with healthcare regulations by implementing robust monitoring practices and preventing unauthorized access to personal health information.
  • Fraud detection for payment services and aid: Ensure sensitive information is protected through stringent data masking techniques provided by Dynatrace during capture, ingestion, storage, and display in line with financial sector regulations.

Summary

To ensure your organization meets data compliance requirements based on industry regulations, it’s essential to identify each specific requirement and outline the steps to protect sensitive data. Additionally, understanding the configuration options provided by Dynatrace, particularly within its Log Management and Analytics masking capabilities, can help you effectively address these regulatory and compliance objectives.

Want to learn more? Read our documentation and explore how Dynatrace helps you address your regulatory and compliance requirements.

Explore our end-to-end log management compliance guide.

The post Navigate end-to-end data compliance through effective log management appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/navigate-end-to-end-data-compliance-through-effective-log-management/feed/ 0
Dynatrace elevates data security with separated storage and unique encryption keys for each tenant https://www.dynatrace.com/news/blog/separated-storage-and-unique-encryption-keys-for-each-tenant/ https://www.dynatrace.com/news/blog/separated-storage-and-unique-encryption-keys-for-each-tenant/#respond Fri, 29 Nov 2024 18:58:20 +0000 https://www.dynatrace.com/news/?p=66942 Data security graphic

Dynatrace continues to deliver on its commitment to keeping your data secure in the cloud. Enhancing data separation by partitioning each customer’s data on the storage level and encrypting it with a unique encryption key adds an additional layer of protection against unauthorized data access. Separate data storage fulfills the security compliance requirements of many […]

The post Dynatrace elevates data security with separated storage and unique encryption keys for each tenant appeared first on Dynatrace news.

]]>
Data security graphic

Dynatrace continues to deliver on its commitment to keeping your data secure in the cloud. Enhancing data separation by partitioning each customer’s data on the storage level and encrypting it with a unique encryption key adds an additional layer of protection against unauthorized data access. Separate data storage fulfills the security compliance requirements of many Dynatrace customers operating in highly regulated sectors, making it much easier for them to use Dynatrace SaaS and accelerate their digital business transformation.

Protect data in multi-tenant architectures

To bring you the most value by unifying observability and security in one analytics and automation platform powered by AI, Dynatrace SaaS leverages a multitenancy architecture, enabling efficient and scalable data ingestion, querying, and processing on shared infrastructure. Such infrastructures must implement additional controls to securely separate each customer’s data. Dynatrace ensures that each customer’s tenant data is separated from each other customer’s data throughout its lifecycle using multiple layers of data security controls, such as:

In addition to the data security controls, a rigorous secure development lifecycle (SDL) ensures that data security controls for data separation work as designed and that any potential issues are detected and prevented during development. The Dynatrace SDL includes penetration testing, red teaming, continuous threat modeling and risk assessments, a public bug bounty program, and vulnerability scans.

Dedicated storage and unique encryption keys for each tenant

Dynatrace introduces a fundamental improvement in how each customer’s tenant data is kept separate. By providing dedicated storage and a unique encryption key for each tenant, each Dynatrace tenant’s data is kept separate at rest on the storage level, significantly reducing the risk of unauthorized access to the data.

A unique encryption key is applied to each tenant’s storage and automatically rotated every 365 days. This guarantees that only one tenant is affected in the unlikely case of a compromised encryption key. For further security and convenience, you can easily revoke a key without impacting your data.

This level of data separation and encryption fulfills the security compliance requirements of many Dynatrace customers operating in highly regulated sectors.

Tenant data separation in Dynatrace

Currently, the enhanced tenant data separation and encryption feature is activated by default for all Dynatrace SaaS customers on AWS and Azure using the latest version of Dynatrace SaaS. There is no need to make any changes.

On AWS, each Dynatrace tenant now has a dedicated S3 bucket assigned to it. All new Dynatrace platform data at rest is stored in such a dedicated S3 bucket. S3 buckets are configured to be encrypted with a bucket key stored in the AWS key management system (KMS). Each S3 bucket is assigned its own unique bucket key. All bucket keys are managed by Dynatrace and are configured to rotate automatically after 365 days.

On Azure, each Dynatrace tenant now has a dedicated Azure storage account assigned to it. All new Dynatrace platform data at rest is stored in such a dedicated storage account. Storage accounts are configured to be encrypted with a key stored in the Azure Key Vault. Each storage account is assigned its own unique encryption key. All encryption keys are managed by Dynatrace and are configured to rotate automatically after 365 days. 

What’s next

Next, the enhanced data separation and encryption features are planned for release to all customers on Azure and then to all customers on Google Cloud.

With improved data separation and newly introduced encryption, Dynatrace helps you fulfill data security requirements for highly regulated sectors.

Contact your Dynatrace account manager to learn how Dynatrace meets your organization’s security, privacy, and compliance requirements and to accelerate your journey to Dynatrace SaaS.

The post Dynatrace elevates data security with separated storage and unique encryption keys for each tenant appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/separated-storage-and-unique-encryption-keys-for-each-tenant/feed/ 0
Dynatrace achieves CSA Star 2 certification https://www.dynatrace.com/news/blog/dynatrace-achieves-csa-star-2-certification/ https://www.dynatrace.com/news/blog/dynatrace-achieves-csa-star-2-certification/#respond Fri, 29 Nov 2024 18:23:27 +0000 https://www.dynatrace.com/news/?p=66936 Dynatrace achieves CSA Star 2 certification

We’re excited to announce that Dynatrace has successfully achieved CSA Star 2 certification with a Gold Maturity Score. This significant milestone underscores our ongoing commitment to maintaining the highest standards of security and compliance in the cloud and making it easier for our customers to use Dynatrace SaaS. What is CSA Star 2? The Cloud […]

The post Dynatrace achieves CSA Star 2 certification appeared first on Dynatrace news.

]]>
Dynatrace achieves CSA Star 2 certification

We’re excited to announce that Dynatrace has successfully achieved CSA Star 2 certification with a Gold Maturity Score. This significant milestone underscores our ongoing commitment to maintaining the highest standards of security and compliance in the cloud and making it easier for our customers to use Dynatrace SaaS.

What is CSA Star 2?

The Cloud Security Alliance (CSA) Security, Trust & Assurance Registry (STAR) is a comprehensive framework for cloud security assurance. The Level 2 certification involves a rigorous third-party assessment based on the CSA’s Cloud Controls Matrix (CCM). This certification is specifically designed for Cloud Service Providers (CSPs) and builds upon the more generic approaches of ISO 27001 and SOC 2 Type II.

CSA Star 2 strengthens Dynatrace cloud security posture

CSA Star 2 certification provides a trusted benchmark for cloud security and thus strengthens the overall Dynatrace security posture. It signifies that a cloud provider has undergone a thorough evaluation by an independent auditor, confirming that their security measures meet or exceed industry standards.

Benefits to Dynatrace customers

The Dynatrace® platform for observability and security with Davis® hypermodal AI provides answers and intelligent automation from data at an enormous scale. This enables innovators to modernize and automate cloud operations, deliver software faster and more securely, and ensure flawless digital experiences. That’s why the world’s largest organizations trust Dynatrace to accelerate digital transformation.

Achieving CSA Star 2 certification is not just a badge of honor for Dynatrace; it’s a testament to our dedication to safeguarding your data. This certification means:

  • Enhanced trust: Customers can be assured that Dynatrace adheres to the highest security standards, as validated by CSA Star 2 certification through a third-party audit.
  • Risk reduction: The certification process ensures that we have strong controls in place to mitigate security risks significantly, reducing the likelihood of breaches.
  • Regulatory compliance: Our certification helps customers meet their own regulatory requirements, simplifying their compliance processes because our certification aligns with international standards and ensures data is handled in compliance with relevant laws and regulations.
  • Streamlined audits: Customers can leverage our certification during their own audits, making the process more efficient and providing evidence of our commitment to security.

Our commitment

As shown by our broad range of certifications and accreditations, security is a core value at Dynatrace. Adding CSA Star 2 certification highlights our dedication to excellence. We’re focused on ongoing improvements to maintain the highest security standards and deliver exceptional service, providing a safe and governed environment for our customers.

What’s next

To learn more about Dynatrace data security and privacy, visit our Trust Center.

If you’re an existing Dynatrace Managed customer looking to upgrade to Dynatrace SaaS, see How to start your journey to Dynatrace SaaS.

Visit Dynatrace for Executives to learn how Dynatrace helps drive innovation, mitigate risk, and optimize cost.

The post Dynatrace achieves CSA Star 2 certification appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-achieves-csa-star-2-certification/feed/ 0
Dynatrace achieves SOC 1 Type II certification https://www.dynatrace.com/news/blog/dynatrace-achieves-soc-1-type-ii-certification/ https://www.dynatrace.com/news/blog/dynatrace-achieves-soc-1-type-ii-certification/#respond Tue, 29 Oct 2024 17:15:04 +0000 https://www.dynatrace.com/news/?p=66381 Dynatrace achieves SOC 1 Type II certification

We’re thrilled to announce that Dynatrace has successfully obtained SOC 1 Type II certification. This achievement reflects our commitment to maintaining the highest standards of security and compliance.

The post Dynatrace achieves SOC 1 Type II certification appeared first on Dynatrace news.

]]>
Dynatrace achieves SOC 1 Type II certification

What is SOC 1 Type II?

SOC 1 (Service Organization Control 1) is a widely recognized auditing standard developed by the American Institute of Certified Public Accountants (AICPA). It focuses on controls related to financial reporting. The “Type II” designation means that an independent auditor evaluated our controls over a period of time (typically six months) and confirmed the controls’ effectiveness.

Strengthening the Dynatrace security posture

Having SOC 1 Type II certification demonstrates Dynatrace’s robust security practices. Our internal controls have been rigorously assessed, ensuring we meet or exceed industry standards. This certification provides peace of mind to our customers, partners, and stakeholders, who can be confident that their data is safe.

Benefits to Dynatrace customers

Our customers directly benefit from our SOC 1 Type II certification:

  1. Increased trust: With this certification, you can trust that Dynatrace adheres to stringent security protocols. We prioritize the confidentiality, integrity, and availability of all customer data.
  2. Risk mitigation: By adhering to SOC 1 Type II standards, we minimize the risk of financial misstatements or security breaches. You can confidently rely on Dynatrace for critical operations.
  3. Streamlined audits: You can leverage Dynatrace certification during your own internal audits; it simplifies the audit process and provides evidence of our commitment to security.

Our commitment

At Dynatrace, security is at the core of everything we do. Achieving SOC 1 Type II certification reinforces our dedication to excellence. We remain focused on continuous improvement, maintaining the highest security standards while ensuring you receive exceptional service.

What’s next

Visit Dynatrace for Executives to learn how Dynatrace helps drive innovation, mitigate risk, and optimize cost.

The post Dynatrace achieves SOC 1 Type II certification appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dynatrace-achieves-soc-1-type-ii-certification/feed/ 0
Tailored access management, Part 3: Simplified setup for enterprise-scale access management https://www.dynatrace.com/news/blog/tailored-access-management-enterprise-scale-access-management/ https://www.dynatrace.com/news/blog/tailored-access-management-enterprise-scale-access-management/#respond Mon, 14 Oct 2024 17:42:08 +0000 https://www.dynatrace.com/news/?p=66182 Access management graphic

We recently introduced several new Identity and Access Management (IAM) capabilities to simplify the setup and assignment of user permissions while providing unmatched enterprise-scale flexibility. Combined with new policy boundaries, rethought default policies make it easier to manage which records and resources users can access.

The post Tailored access management, Part 3: Simplified setup for enterprise-scale access management appeared first on Dynatrace news.

]]>
Access management graphic

Manage the complexity of authorization systems

Most modern authorization systems provide access management using Attribute-Based Access Control (ABAC). ABAC has several advantages:

  • Enhanced security, providing granular control over access permissions, significantly reducing the risk of data breaches and unauthorized activities.
  • High flexibility, adapting to dynamic environments and diverse user needs. It also supports scalability, making it suitable for organizations of all sizes.
  • Meeting regulatory requirements by providing detailed access control policies.
  • High granularity by segmenting resource and record-level data, ensuring that access decisions are precise and context-aware.
  • Up-to-date security through dynamic authorization; access can be granted or revoked in real time based on changing attributes.

This level of flexibility does, however, bring increased complexity, meaning that implementing and managing ABAC can be time-consuming and resource-intensive. The system demands significant effort to design, manage, and maintain, especially as an organization’s needs evolve. Authorization must be continuously managed and adapted to the changing requirements of applications and enterprises.

To counteract this, Dynatrace introduced features to make it easy for admins to adopt and apply our security policies while enjoying the benefits of a highly customizable ABAC system.

Dynatrace introduces new default policies for reduced complexity

With the introduction of security policies, we provided the capability of default policies, which are managed by Dynatrace and work out of the box.

Default policies eliminate much of the hassle of configuring permissions and can easily be deployed. Default policies also ensure a consistent security baseline across all your users, minimizing the chance of security gaps.

Our original concept of default policies, which was launched back in 2022, was focused on service level. While this concept gave admins much control, it also required knowledge of our service model. Striving for greater simplicity, we took another approach to default policies, focusing only on the two most important access control use cases:

  • Dynatrace platform access (Dynatrace access): Managing access to Dynatrace features
  • Data monitoring access (Data access): Managing access to monitored data stored in Dynatrace

Dynatrace access policies cover classic and new features, providing a single entry point to manage access to the entire feature set of the Dynatrace platform. With the new release, there are three default access policies available:

  • Standard User policy: Provides baseline access to Dynatrace (corresponds to the former, “AppEngine – User”)
  • Pro User policy: Provides access to advanced features
  • Admin User policy: Grants admin privileges and provides access to all features (corresponds to the former, “AppEngine – Admin”)

Data access policies manage access to the monitored data stored in your environment. Access policies for Dynatrace Grail™ data lakehouse are still available as service-related policies; they allow you to control access to the monitoring data on a per-data-source level, for example, logs and metrics.

All other default policies on the service level, for example, “AutomationEngine – User” access, are now marked as Legacy. This means that existing assignments for these policies remain valid, but they can’t be changed except for deletion. Also, no new policy assignments with Legacy policies are allowed.

Simple partition management through policy boundaries

In addition to security policies, admins can now apply policy boundaries, simplifying the management of partitions on the data level and enabling further re-usability. While policies define which features and data users can access, policy boundaries define where users can access those features and data.

Policy boundaries allow you to manage your business-specific access control conditions separately from your policies and apply your policies selectively to one or many policy-to-group mappings.

Figure 1. Create a new policy boundary in the new user group management web UI
Figure 1. Create a new policy boundary in the new user group management web UI.

For more information, go to our IAM policy boundaries documentation.

Get started with our new security policies

  1. Utilize the default groups: If you’re a new Dynatrace customer, we recommend that you utilize the default groups provisioned during account creation. This significantly reduces the effort required to manage user groups and permissions.
  2. Utilize the default policies for new user groups: When creating new groups, utilize the Dynatrace default policies for baselining.
    • Dynatrace access policies: Decide which functionality your users require and apply the right Dynatrace access policy. Regular users can work with the Standard or Pro User policy; the Admin User policy should be reserved for admins only.
    • Data access policies: To manage data access, select the data sources your users should be able to see, such as logs, spans, metrics, and so on. Use the respective data access policies for these assignments.
  3. Assign policy boundaries: When you need to restrict monitoring data access on a per-record basis or if you need to restrict the resources offered by Dynatrace platform services, define these conditions in your boundaries and apply them as part of your policy configuration. You can assign multiple boundaries to a single policy. The boundaries are automatically matched to the respective policy statements and restricted further.
  4. Refine assigned policies with boundaries reflecting your record/resource partitions.
  5. Create custom policies for advanced access scenarios not covered by the Dynatrace defaults. Be aware that creating custom policies requires additional maintenance effort to keep them current.Here is a list of use cases where custom policies can help you fulfill advanced access scenarios:
    • Extend or restrict access defined by default policies by creating custom policies with ALLOW/DENY statements that tailor user access.
    • Template reusable policies to assign privileges at scale.
    • Create custom policies and assign them to the All-users group to establish a baseline of permissions for all users in your account.

Adopt the new Dynatrace security policies today

Go to Dynatrace Documentation for complete information about these enhancements to Dynatrace access management and how you can benefit from them. If you’re an existing customer and want to upgrade to the attribute-based access control system, check out our new guide, which will walk you through the process.

This blog post is part of our series on Tailored access management. If you’re interested in learning more about the Dynatrace approach to IAM, have a look at Part 1 and Part 2 of this blog series.

The post Tailored access management, Part 3: Simplified setup for enterprise-scale access management appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/tailored-access-management-enterprise-scale-access-management/feed/ 0
Dynatrace commitment to safe OneAgent releases: Protecting production environment resilience https://www.dynatrace.com/news/blog/commitment-to-safe-oneagent-releases-protects-your-production-environment/ https://www.dynatrace.com/news/blog/commitment-to-safe-oneagent-releases-protects-your-production-environment/#respond Tue, 13 Aug 2024 17:21:57 +0000 https://www.dynatrace.com/news/?p=65166 OneAgent for production environment resilience

Securing production environment resilience is top of mind for many organizations in the wake of widespread outages caused by a routine software update in July, 2024. Here's how Dynatrace ensures our OneAgent releases protect our customer IT environments at every stage of the software development lifecycle.

The post Dynatrace commitment to safe OneAgent releases: Protecting production environment resilience appeared first on Dynatrace news.

]]>
OneAgent for production environment resilience

Modern observability and security require comprehensive access to your hosts, processes, services, and applications to monitor system performance, conduct live debugging, and ensure application security protection. This level of access enables advanced capabilities such as runtime instrumentation and detailed diagnostics. While these techniques are powerful, they can pose risks to production environment resilience if not managed properly, as demonstrated by the widespread software outages in July.

At Dynatrace, we’ve implemented a thorough and industry-proven approach to developing OneAgent® that minimizes such risks. Our approach encompasses all stages of the software development lifecycle, focusing on safeguarding OneAgent integration with your systems. Through rigorous testing, dependency management, continuous monitoring, and phased rollouts, we’ve prioritized the development of OneAgent with the highest possible reliability and security standards.

By adhering to these stringent processes, OneAgent is designed to operate smoothly and securely, minimizing the likelihood of disruptions and providing you with greater confidence in your system’s security.

Dynatrace OneAgent: Quick overview

Dynatrace OneAgent is a unified monitoring solution deployed across customers’ IT environments. It automatically discovers and monitors each host’s applications, services, processes, and infrastructure components. Injecting monitoring code into your applications without manual configuration ensures continuous and comprehensive monitoring and security. OneAgent provides end-to-end visibility, capturing real-time performance data and detailed metrics on CPU, memory, disk, network, and processes.

Safety measures across the entire software lifecycle

From development to rollout and production, we’ve developed safeguards to ensure production environment resilience at each phase of the software development lifecycle, preventing problems in your systems during updates. Let’s dive into the details.

Safeguards are implemented for each phase of the software development lifecycle
Figure 1. Safeguards are implemented for each phase of the software development lifecycle

End-to-end safety measures in the software development process

  • Separation of concerns: Each OneAgent component is designed to perform only one specific function. Critical and impactful components are minimized and undergo regular detailed reviews. Changes are introduced on a controlled schedule, typically once a week, to reduce the risk of affecting customer systems.
  • Dependency reduction: OneAgent development teams minimize the use of third-party or open source dependencies. Any required dependencies are thoroughly tested and fixed to specific versions, minimizing the risk of introducing untested code.
  • Rigorous testing: Engineers conduct extensive unit and integration tests on all code changes, covering individual functions and OneAgent performance with real-world applications. These tests are run on all supported operating systems and versions to enhance reliability.
  • Hardening phase: Before release, OneAgent undergoes a month-long hardening phase, during which repeated tests are conducted to uncover hidden issues. Our developers double-check these tests daily. The software is also deployed to internal test applications for real-world validation.
  • Artifact signing: OneAgent binaries are signed to prevent unauthorized changes. The deployment steps guide you through verifying the signature during installation, and from this point on, any OneAgent updates are verified automatically to ensure the integrity of the OneAgent.

Reduced likelihood of failures in the OneAgent rollout process

  • Pre-rollout check: After the hardening phase, we thoroughly review each new OneAgent version with all teams to identify any known issues or concerns. We only proceed with a phased rollout when confident in a release.
  • Phased and controlled rollout: Each rollout is carefully staged, starting with internal environments, then moving to proofs-of-concept (POCs), trials, new customer environments, and finally to the broader customer base. We monitor correct OneAgent behavior and functionality at each stage to ensure it behaves as expected.
  • Customer control: You can manually update OneAgent versions, prioritizing updates for critical applications or host groups while enabling auto-updates for less critical areas. You can also schedule updates during maintenance windows to minimize disruption.

Stay ahead of potential failures with production self-monitoring

  • 24/7 fully automated monitoring: We continuously monitor critical statistics, such as the number of connected OneAgents per technology, to swiftly address any significant issues. We also collect and analyze warning and severe log events to proactively address potential problems before they escalate into incidents.
  • Real-time health insights: Dynatrace provides immediate insights into your environment, helping you quickly identify the root cause of any issues. This enables you to clearly understand the health of your OneAgent deployment across your entire environment.
Stay ahead of OneAgent deployment issues with self-monitoring during production.
Figure 2. Stay ahead of OneAgent deployment issues with self-monitoring during production.
  • Automated issue collection: Details of potential issues are automatically collected and can be sent to Dynatrace for further analysis. Additionally, manual diagnostics can be performed to gather more specific information if needed.
Manual diagnostics reveal a critical error in an outdated version of OneAgent.
Figure 3. Manual diagnostics reveal a critical error in an outdated version of OneAgent.
  • Proactive analysis and auto-remediation: When a problem is reported, regardless of its severity, we assess its potential impact on our customers’ environments and take appropriate action as needed. This might include adding safety checks or rolling out an updated version to address the issue.

Ensure system stability with our zero-impact policy

Dynatrace OneAgent is built with a focus on reliability and security, aiming to keep your systems stable and protected. We proactively approach potential risks, implementing rigorous standards across the entire software development lifecycle and maintaining continuous, real-time monitoring. This comprehensive strategy is designed to reduce the likelihood of disruptions, offering you greater confidence in the safety and resilience of your IT environment.

While no system is entirely free from potential risks, our approach minimizes such risks and provides robust protection for your systems, helping to ensure smoother and more reliable operation.

For complete details about Dynatrace OneAgent, go to Dynatrace Documentation.

Interested in innovating along with us? Explore the OneAgent careers page.

Gain insights into how Dynatrace developers develop observability code, continuously test across all supported environments, and avoid situations like the CrowdStrike software outages in July.

The post Dynatrace commitment to safe OneAgent releases: Protecting production environment resilience appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/commitment-to-safe-oneagent-releases-protects-your-production-environment/feed/ 0
Beyond DORA compliance: How Dynatrace helps the financial sector stay resilient https://www.dynatrace.com/news/blog/dora-how-dynatrace-helps-the-financial-sector-stay-resilient/ https://www.dynatrace.com/news/blog/dora-how-dynatrace-helps-the-financial-sector-stay-resilient/#respond Tue, 30 Jul 2024 16:17:14 +0000 https://www.dynatrace.com/news/?p=65039 DORA compliance

As financial institutions navigate the Digital Operational Resilience Act (DORA), the journey towards compliance presents significant challenges. This blog post explains how Dynatrace helps banks, insurance companies, investment firms, and others comply with the DORA requirements using analytics and automation based on observability and security data.

The post Beyond DORA compliance: How Dynatrace helps the financial sector stay resilient appeared first on Dynatrace news.

]]>
DORA compliance

The Digital Operational Resilience Act (DORA) ensures that the European financial sector remains resilient during severe operational disruptions. DORA compliance is required of all organizations that fall under its jurisdiction by January 17, 2025.

Financial institutions have an increased compliance burden with DORA. We estimate that Dynatrace can automate 80% repetitive tasks introduced by DORA technical requirements using analytics and automation, based on observability and security data.*

* Estimated from our analysis of the technical needs and recognition of the issues that our platform can potentially resolve.

The DORA 5 pillars

DORA consists of the following five pillars.

  • ICT Risk Management: Financial entities must effectively manage risks related to their information and communication technology (ICT) systems. This includes identifying, assessing, and mitigating risks to maintain operational resilience.
  • ICT Incident Reporting: Organizations must promptly report major ICT-related incidents to competent authorities. Transparency is crucial for addressing disruptions and preventing widespread impact.
  • Digital Operational Resilience Testing: Regular testing ensures systems can withstand cyber threats and operational disruptions. Robust testing practices enhance overall resilience.
  • ICT Third-Party Risk Management: Financial institutions must assess and manage risks associated with third-party service providers. Outsourcing ICT services requires diligent oversight to maintain resilience.
  • Information and Intelligence Sharing: Collaboration and information exchange among financial entities and ICT providers help combat cyber threats collectively. Sharing insights strengthens the sector’s defenses.

Why Dynatrace for DORA compliance

The Dynatrace® platform offers a comprehensive solution for DORA compliance that helps you identify and address various pain points and requirements described in the DORA pillars. Observability and application security, driven by hypermodal Davis® AI, help enhance the security of your systems, increase operational resiliency, effectively manage your risks, and reduce costs.

Compliance Assistant for DORA compliance 

Addressing DORA’s technical requirements is very labor-intensive without proper tooling and automation. Examples include complex mapping to technical requirements, analyzing and quickly acting on ICT incidents, and ensuring compliance across the whole critical ecosystem. Inefficient workarounds and custom tooling are often needed to achieve and maintain DORA compliance.  

Dynatrace addresses this need with the introduction of Compliance Assistant, a tailored app that supports you in your efforts towards achieving DORA compliance by:  

  • Automating repetitive and time-consuming tasks so your team can focus on creating value and innovation. 
  • Providing a tailored view of the important metrics and events so you can confidently navigate compliance requirements impacting your organization. 
  • Leveraging observability, security, and other capabilities of the Dynatrace platform with hypermodal Davis® AI. 

How Dynatrace solves key pain points in DORA compliance

We analyzed the DORA pillars to understand the requirements they bring to our customers. Having end-to-end visibility across the entire IT environment and validating our findings with customers and partners, we identified four key pain points DORA surfaces and how we think Dynatrace helps turn them into opportunities to innovate while increasing security, resiliency, and efficiency.

Complexity of digital ecosystems

Pain point: Financial services operate in complex environments with numerous applications, hybrid cloud infrastructures, and third-party vendors. This complexity increases cybersecurity risks and complicates governance.

Addressed DORA pillars: ICT Risk Management, Digital Operational Resilience Testing, Managing ICT-Third Party Risk

The Dynatrace solution

  • Full-stack observability: To assist with DORA compliance, Dynatrace offers end-to-end visibility across the entire IT environment, including applications, cloud infrastructure, and third-party integrations. This holistic view simplifies the management of complex ecosystems, reducing cybersecurity risks and ensuring seamless governance.
  • Dynatrace Runtime Vulnerability Analytics: This feature provides AI-powered risk assessment and continuous real-time exposure management throughout the entire application stack. It promptly alerts security teams about identified exposures and visualizes any affected dependencies using the platform’s topology map.

Third-party risk management

Pain point: Limited control over third-party ICT service providers requires robust risk assessment and continuous monitoring.

Addressed DORA pillars: Managing ICT-Third Party Risk

The Dynatrace solution

  • Runtime Vulnerability Analytics: Dynatrace continuously monitors third-party software for vulnerabilities, providing real-time detection and prioritization of exposures. This proactive approach ensures third-party risks are managed effectively, maintaining a strong security posture for DORA compliance.
  • Better Understanding of Third-Party ICT Risk: Dynatrace can detect and prioritize exposures in any monitored application, including third-party software like COTS and open source, eliminating the dependency on vendor-provided SBOMs.

Resource constraints

Pain point: DORA compliance demands skilled personnel, advanced technologies, and significant investment, often diverting resources from innovation and customer experience improvements.

Addressed DORA pillars: ICT Risk Management, ICT Incident Management

The Dynatrace solution

  • Automated Compliance Monitoring: Dynatrace automates compliance checks and reporting, reducing the need for extensive manual effort. This automation frees up valuable resources, allowing teams to focus on innovation and enhancing customer experiences.
  • Dynatrace Security Posture Management (SPM): SPM can digitally and automatically verify technical requirements across different DORA requirements, assisting you in achieving compliance with minimal manual intervention.

Integration with existing processes

Pain point: DORA compliance must integrate seamlessly with existing risk management, incident response, and business continuity processes, which can be challenging and resource-intensive.

Addressed DORA pillars: ICT Incident Management, Information Sharing Arrangements

The Dynatrace solution

  • Seamless Integration: Dynatrace integrates with existing IT workflows and processes, ensuring compliance measures are part of daily operations. This seamless integration enhances efficiency and reduces the complexity of maintaining DORA compliance.
  • Continuous Digital Operational Resilience Testing: Dynatrace automates change impact analysis with Site Reliability Guardian, validating service-level objectives and security vulnerabilities before and after deployments to improve release quality.

What’s next

Learn more about how Dynatrace assists with addressing DORA requirements and how Dynatrace complies with DORA in our DORA blog series, and contact your Dynatrace account representative to find the best solution for your organization.

Visit Dynatrace for Executives to learn how Dynatrace helps drive innovation, mitigate risk, and optimize cost.

The post Beyond DORA compliance: How Dynatrace helps the financial sector stay resilient appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/dora-how-dynatrace-helps-the-financial-sector-stay-resilient/feed/ 0
Privacy spotlight: Ensure compliance by hard deleting individual records in Grail https://www.dynatrace.com/news/blog/hard-deleting-individual-records-in-grail/ https://www.dynatrace.com/news/blog/hard-deleting-individual-records-in-grail/#respond Thu, 11 Jul 2024 16:52:33 +0000 https://www.dynatrace.com/news/?p=64686

Dynatrace introduces record-level hard deletion to more effectively comply with end-user deletion requests in line with privacy laws. By ensuring only relevant data is efficiently and permanently removed, deletion requests help drive innovation and don’t negatively impact your data quality.

The post Privacy spotlight: Ensure compliance by hard deleting individual records in Grail appeared first on Dynatrace news.

]]>

Data deletion might seem simple, but it’s critical in data management and privacy laws. It’s not just about hitting the Delete button; it’s about securely meeting compliance requirements while ensuring data integrity. Dynatrace Grail™ is a data lakehouse optimized for high performance, automated data collection and processing, and queries of petabytes of data in real time. A data lakehouse is schema-on-read and indexless, making deletion operations complex. Adding to the technical challenges, effective deletion involves a combination of policies, procedures, and technologies to ensure data is appropriately managed throughout its lifecycle.

Strategically handle end-to-end data deletion

Two key elements form the backbone of an effective deletion strategy in Dynatrace SaaS data management: retention-based and on-demand deletion. Retention-based deletion is governed by a policy outlining the duration for which data is stored in the database before it’s deleted automatically. The retention period can vary based on the nature of the data, regulatory requirements, and the business’s specific needs. With Dynatrace Grail™, you can customize data retention periods with day-level granularity for up to 10 years.

On-demand deletions are initiated in response to specific events or requests. For instance, if data is mistakenly ingested into the database, it may need to be deleted to prevent inaccuracies or sensitive data from being stored. Another consideration is compliance with end-user privacy rights to delete personal data processed about them in line with data protection laws like GDPR and CCPA.

Hard deletion on the record level is the gold standard

On-demand data deletion in a Dynatrace SaaS environment relies on two core characteristics: granularity and hard deletion. Granularity, specifically at the record level, allows for precise control over what data is deleted. This means that individual records can be targeted for deletion without affecting the rest of the dataset. Hard deletion refers to the permanent and secure erasure of data. These characteristics are crucial in ensuring data deletion is effective, secure, and compliant with data privacy regulations.

Many other SaaS vendors mistakenly assume that a soft delete—merely hiding or marking data as deleted while retaining it elsewhere—is sufficient. However, this approach leaves room for accidental exposure, unauthorized access, or data breaches, jeopardizing compliance and customer trust. Industry standards refer to hard deletion by overwriting data as the appropriate data sanitization method.[1]

In addition, as with some other solutions, data deletion is often limited to a timeframe or requires removing all data in an index. This approach lacks flexibility and results in losing large volumes of important business data.

[1] NIST Special Publication 800-88 Revision 1, Guidelines for Media Sanitization

Keep valuable data in Grail with targeted deletion

With record-level hard deletion, Dynatrace gives you control and transparency over your data. It enables you to effectively identify and promptly delete targeted data in a thorough and irreversible manner. So, while the relevant data is completely erased, all other valuable data remains intact. This ensures that your business operations continue smoothly, and you can focus on extracting value from Dynatrace.

In addition to the possibility of deleting data in buckets in Grail, record deletion in Grail now enables you to identify and select the records to be removed by leveraging DQL. You can use the Grail Storage Record Deletion API to trigger a deletion request.

Here are some tips to consider when deleting records in Grail:

  • Leverage Notebooks: Use Notebooks to create a DQL query to filter all the records you intend to delete. With Notebooks, you can easily query data from Grail and visualize the results. This step also helps you determine the timeframe within which the relevant records are stored. To delete the records, use the Storage Record Deletion API. You might need to invoke the API multiple times if your data spans multiple days. Be aware that only one deletion process can be executed at a time.
  • Verify your permissions: Before proceeding with any data deletion tasks, ensure that you have the necessary permissions, specifically storage:records:delete.
  • Pause data ingestion: To avoid mistakenly deleting any recent data, stop ingesting new data that contains information you plan to delete. Only data older than 4 hours can be deleted.
  • Keep track of deletion: Use the status command to gain insights into the status of the current deletion process. If necessary, use the cancel command to cancel a running process.

An audit trail is maintained to provide a clear and transparent record of what data was deleted, when, and by whom. By following these best practices, you can ensure efficient and safe data management, allowing you to focus on extracting value from Dynatrace while maintaining smooth and compliant business operations.

Cleanup data in Grail with Privacy Rights

You can also hard delete on the record level in Grail using the out-of-the-box deletion functionalities in Privacy Rights. With an interface designed for your compliance needs, you can efficiently manage data deletion requests and cleanup tasks. A dashboard provides you with a summary of key details, including the request reference, status, and due date alignment. This streamlined process—from request creation to record deletion—is logged and auditable within the app, ensuring transparency and accountability.

The cleanup workflow in Privacy Rights allows you to refine your query to locate all relevant data points, guaranteeing a comprehensive and precise deletion process. In addition, a multi-user approval process with an assignee and a reviewer minimizes deletion risks and ensures accuracy. With Privacy Rights, what once seemed like a daunting compliance task has transformed into a simple and transparent workflow.

Get started

What’s next

As we continue to innovate and enhance our privacy features, we remain committed to providing you with the industry’s most robust and transparent data protection solutions. We’re working on making data deletion even easier by onboarding log deletion in Grail to the Privacy Rights app. Check our Privacy Rights documentation to stay tuned to our continuous improvements.

See documentation for Record deletion in Grail via API.

The post Privacy spotlight: Ensure compliance by hard deleting individual records in Grail appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/hard-deleting-individual-records-in-grail/feed/ 0
HIPAA compliance and Dynatrace’s commitment to support digital transformation in healthcare https://www.dynatrace.com/news/blog/hipaa-compliance-and-dynatrace-commitment-to-support-digital-transformation-in-healthcare/ https://www.dynatrace.com/news/blog/hipaa-compliance-and-dynatrace-commitment-to-support-digital-transformation-in-healthcare/#respond Sun, 30 Jun 2024 18:06:25 +0000 https://www.dynatrace.com/news/?p=64500 Dynatrace is HIPAA compliant

Dynatrace continues its commitment to delivering its unified observability and security platform to support healthcare organizations in the United States by addressing HIPAA compliance requirements and giving its customers the option to enter a Business Associate Agreement (BAA) with Dynatrace. Healthcare providers, other healthcare organizations, and their patients and partners can be confident that their data resides in a highly secure environment.

The post HIPAA compliance and Dynatrace’s commitment to support digital transformation in healthcare appeared first on Dynatrace news.

]]>
Dynatrace is HIPAA compliant

Observability and security are key components of successful digital transformation, a critical priority for healthcare organizations to stay competitive, deliver enhanced patient care, and improve operational efficiencies. As more and more patient data is collected and stored, healthcare organizations must protect collected data following strict standards governed by the Healthcare Insurance Portability and Accountability Act (HIPAA).

HIPAA compliance is more than a legal requirement for healthcare organizations. It’s key to nurturing patient trust, protecting sensitive health information, avoiding financial and criminal penalties, and promoting ethical practices.

With its ability to significantly improve customer experiences, performance, and security of IT systems, Dynatrace extends its commitment to healthcare organizations by entering into a BAA so that healthcare companies can use the Dynatrace platform to digitally transform and deliver the best patient care, improve operational efficiencies, and provide additional safeguards of patient privacy and the security of their digital ecosystems.

Dynatrace for healthcare

Healthcare organizations increasingly turn to technology solutions to boost patient outcomes, reduce patient wait times, lower costs, and drive innovation.

Technology-driven solutions help healthcare organizations address evolving customer preferences and delivery models—from telemedicine and patient portals to AI-assisted diagnoses. These solutions demand IT infrastructure, often delivered from the cloud, to enable them quickly, cost-effectively, and securely.

These modern cloud environments are dynamic and complex. The dynamic nature and the explosion of data they produce make them too complex to manage with dashboards, alerts, and manual troubleshooting.

Healthcare technology teams need a mature approach to monitoring, managing, and maximizing the value of their investments in cloud ecosystems. To tame the complexity, they need a modern observability and security solution that delivers predictable, trustworthy, and precise real-time insights.

Dynatrace combines broad and deep observability and runtime application security with hypermodal AI that combines predictive, causal, and generative techniques to deliver answers and intelligent automation from data.

HIPAA compliance

The Health Insurance Portability and Accountability Act, passed by the US Congress in 1996, is a set of rules and regulations to protect health information (PHI). PHI refers to  information concerning a person’s health, healthcare, or payment for their healthcare.

The HIPAA Privacy Rule addresses patients’ rights to access and control their health information, while the HIPAA Security Rule protects health data created, received, maintained, or transmitted.

When a Business Associate, such as Dynatrace, enters a BAA with its customers, it commits that the products and services in the scope of such BAA comply with the requirements defined by HIPAA. Dynatrace’s BAA covers the whole Dynatrace platform and extends to the related Business Insights services.

What’s next

Visit Dynatrace for Executives to learn how Dynatrace helps drive innovation, mitigate risk, and optimize cost.

The post HIPAA compliance and Dynatrace’s commitment to support digital transformation in healthcare appeared first on Dynatrace news.

]]>
https://www.dynatrace.com/news/blog/hipaa-compliance-and-dynatrace-commitment-to-support-digital-transformation-in-healthcare/feed/ 0