Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Closing gaps between security, compliance and management

Behind the convergence of security, compliance and management software
Network/Systems Management Alert Network World , 09/07/2005
Sign up for this newsletter now!

Senior Editor Denise Dubie guides you through the latest developments in management tools and services.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Last week, we looked at how the convergence of management with security and compliance software is increasing reliability and availability, and reducing operational risks. It has often been the gaps between security, compliance and management that have driven the convergence of all three.

This is what gave rise to the technology of network behavior anomaly detection, for example. Vendors such as Arbor Networks, Lancope, Mazu Networks and Q1Labs essentially leverage network flow analytics (a management technology) to provide an effective weapon against worms and many other security threats.

One of the most significant gaps apparent today is in policy management. We see policy management emerging in various areas, but there is still a need for products that embrace comprehensive policy across multiple domains. The one-size-fits-all approach is rarely appropriate for IT assets that may have a number of different attributes depending on use case, users, and applicable security or regulatory policy. Enforcement must go beyond the notion that “you must be at least this tall to ride this network” to assure policy compliance throughout the life of an asset’s presence.

One company that has seen the opportunity this gap presents is Elemental Security, which debuted earlier this year. Elemental’s agent-server approach embraces a wide range of host attributes. These can be grouped as needed, or according to defined measures such as compliance with a specific policy or regulatory mandate. This allows high flexibility in visualizing the current posture. This also enables the identification of non-compliant or unmanaged hosts on the network, which can be reconfigured or contained according to applicable policy, whenever they appear.

Since the approach cuts across so many different domains, I asked Elemental customer Doug Torre, director of networking and technical services with Catholic Health Systems in Buffalo, N.Y., about the alternatives he had considered, and why he had settled on Elemental. Doug said he had not found any one product that met so many of his policy management requirements in so many flexible ways. It met his requirements for policing the compliance of hosts on his network on an ongoing basis. It’s a classic case of a converged management, security and compliance product arising to help define an emerging market by meeting needs across all three domains.

Denise Dubie is senior editor with Network World.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Partner Content

NetScout and analyst Jim Metzler have teamed to deliver a series of IT Briefs on Network and Application Performance Management leveraging research from NetScout's nGenius & Sniffer users.

www.netscout.com

Metzler on Service Delivery Management

Delivering IT business value by evolving our thinking from managing application performance to focusing on services.

Learn More

2009 Handbook of Application Delivery

Successful IT organizations must know how to make the right application delivery decisions in these tough economic times.

Download the Handbook

Metzler on the Modern IP Network

Discusses the growing emphasis on network management and the need to implement a holistic view of the end-to-end experience of the user.

Read the Brief

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed