Extend. Manage. Secure. More than 30 years in the business. Over 65,000 customers.
Home » Resources » Customer Stories » NorthgateArinso
Contact Attachmate
1.800.872.2829

NGA Solves Compliance, Security, and Integration Problems for Key Client
Verastream Delivers 3-in-1 Solution

QUICK VIEW

Problems

  • Inability to achieve regulatory compliance.
  • Insufficient security for data transfers.
  • Incompatiblity of software platforms.

Solution

Used Verastream to integrate disparate applications so business processes could be unified.

Results

One solution solved 3 problems for NGA’s client:

  • Automated processes for enhanced auditability.
  • Ensured data security with improved transaction tracking.
  • Integrated CICS and other business
    apps across the enterprise.

NorthgateArinso (NGA) provides human-resources software and services to employers of all sizes, including Global Fortune® 500 companies and many public-sector organisations. One of NGA’s key clients is a leading pharmaceutical and health care company with offices in more than 100 countries and major research centres in the UK, USA, Belgium, and China.

Due to a series of mergers and acquisitions common to many health care organisations, NGA faced a difficult requirement in supporting a complex mix of the client’s incompatible software platforms. Specifically, the client was facing IT challenges around compliance, data security, and application integration. Let’s look at them individually.

Challenge #1: Compliance Regulations

A large portion of the client’s computing transactions used a front-end process that clearly would not be able to address significant upcoming compliance rules (both inter-company and regulatory). All aspects of an ideal process would inherently support the compliance requirements, but the client’s existing store-and-forward approach was not well suited to handle the new mandated functions.

Challenge #2: Data Transfer Security

UniConnect, a key application for the client, included a mainframe and web reporting component that used Internet protocols. Therefore, they required a separate, self-contained security solution tailored to their own purposes. For NGA’s client, the accommodation of security mandates was paramount. Now, with the physical border between internal and external data having blurred, they needed to ensure data in transit be encrypted for the whole journey, from the mainframe to the end user.
In the world of IT, compliance and security issues are subject to constant change, so the first two challenges would call for an architecture adaptable enough to continually respond to new demands. NGA would have to deliver a middleware environment that could use technology to address compliance rules. It would also have to support additional security with SSL Telnet and HTTPS.

Challenge #3: Application Integration

The client’s payroll system, running on a mainframe-based CICS server, now needed to be integrated with the HR system. The resulting solution needed the ability to verify and synchronise data sent from HR with data received in the payroll system, before integration took place.

Compounding this challenge was a rapidly diversifying audience. Experienced staff appreciated the speed and efficiency of the existing payroll system; they were accomplished in its navigation and actually preferred the native legacy workflow. However, less experienced users needed access too; they were not comfortable with the green-screen presentation or the complex workflow of the application, which was not built for ease of use.

Unifying the Goals

The goals for NGA: Introduce a middleware component that would enable business rules for existing and future compliance, raise the security of the environment outside the mainframe, and provide a high level of integration between similar and disparate systems.

It was important for the client to have direct access to the mainframe application data, for several reasons. They wanted the ability to remove latency potential, use existing mainframe-based business rules, and complement the architecture with new routines required for compliance. NGA hoped to find one solution that could meet all of their client’s challenges.

Finding a Solution

Direct communication with EDI through CICS-TS was discounted because it had no way to fulfill the security requirements over the Internet. To explore other options, NGA turned to Attachmate® Corporation. As satisfied users of Attachmate® Reflection® terminal emulation software, NGA had confidence that Attachmate could help them find a solution to meet their client’s needs. NGA had been particularly impressed with the proprietary protocols and inherent security of Reflection 2011.

“Our long history with Attachmate, going all the way back to coaxially connected computers – and the fact that we use their software internally – gave us the confidence to commence the project with Attachmate® Verastream®,” said Simon Davis, senior technical operations consultant at NGA. Verastream solutions help organisations remove host-system barriers and unlock legacy information for reuse.

How NGA Used Verastream

Because Verastream supports SSL out of the box, getting the secure tokens in place was one of the first elements of the project. This enabled the internal UniConnect client to safely interact with the host and conduct correctly authenticated, encrypted conversations. The Verastream use of a secure Telnet protocol provided a key component for meeting compliance rules.

Using Verastream as a middleware tool, Davis and his team were able to build complementary business models that worked in conjunction with the existing processes on the mainframe. The resulting solution provided a familiar view of the application for experienced staff by letting them interact natively with the payroll system, via the business rules that were already in place. At the same time, it provided a corresponding web interface for less-experienced employees who were not used to green screens.

The Verastream Advantage

With the Verastream solution, communications between users, middleware, and host are locked down; information is never allowed to reside anywhere but the mainframe – a big security improvement over the store-and-forward system it replaced. Any data not needed by the end user is not transferred to client devices. Furthermore, information that needs the host data stream is not sent to the end user’s work station, but retained on the server, where filters control access to it.

An unexpected benefit in this implementation was the ability of Verastream to act as a web services hub. That gave the client a level of flexibility that was previously unobtainable. And the Verastream services architecture provided a platform for both NGA and their client to meet unforeseen demands going forward.

Three Challenges, One Solution

With Verastream, NGA was able to meet their client’s challenges for compliance, security, and application integration. In fact, they were able to automate their processes in a way that let them control costs and provide enhanced auditability for better regulatory compliance. The new middleware solution also enabled a deep degree of granularity for improved reporting, and complete transaction tracking gave the client the data security they needed. 

Although the business models are bespoke for the client, reusability is ensured because the standards-based Verastream middleware environment supports native integration with the mainframe applications. It also enables continuous development of further business rules. For NGA, these capabilities meant they could deliver their client’s solution quickly, within budget, and with exceptional flexibility.

The timeframe of the project was 18 months, and could have been shorter; this span included periods when the project was put on hold for the client’s global quarterly reporting. Attachmate monitored the project at arm’s length, with NGA working independently and relying on their in-house IT staff. “It was critical to deliver a supportable solution to our client,” said Davis.“Moreover, it was critical to know we were in turn supported at the other end, and Attachmate was always there for us.”

About Verastream

Attachmate Verastream Host Integrator can service enable legacy applications by exposing business processes as web services, XML, Java, or .NET components. You get rapid results because you can use existing development skills, familiar IT tools, and proven mainframe investments. Whether your environment is IBM System z (S/390), IBM System i (AS/400), UNIX, OpenVMS, or HP e3000, Verastream can modernize the full range of enterprise host applications—without disturbing daily business operations.

Solution Overview

Solution Type
Legacy Modernization
Products and Services
Verastream
Verastream Bridge Integrator
Verastream Host Integrator
Verastream Process Designer
Industry
Services
Technology

It was critical to deliver a supportable solution to our client, and to know we were in turn supported at the other end. Attachmate was always there for us.

Simon Davis 
Senior Technical Operations Consultant
NorthgateArinso