Gain the upper hand on governance and compliance with SaaS-based SecureGRC

Opinion
Jul 16, 20105 mins

Most of the governance, risk and compliance automation tools on the market are aimed at large enterprises with complex environments and deep resources. But smaller companies need governance and must meet compliance mandates, too. Now these companies have the option of a SaaS-based GRC solution that comes with a low subscription rate rather than a high purchase price.

In recent years, government and industry regulations have put pressure on organizations of every ilk and size to increase governance over their IT systems, and in particular over data security and privacy. These regulations include the Basel II Accord, the Health Insurance Portability and Accountability Act (HIPAA), the Sarbanes-Oxley Act of 2002 (SOX), the Gramm-Leach-Bliley Act (GLBA) and California Senate Bill 1386, just to name a few. Non-compliance with an applicable regulation can lead to serious penalties for a business, regardless of its size. Even a small mom-and-pop retail store faces stiff fines if it’s found to be non-compliant with the Payment Card Industry (PCI) data security guidelines.

Seeing an opportunity, many solution vendors have responded with applications designed to automate the complex process of discovering, monitoring and reporting on a company’s governance, risk and compliance (GRC) posture. Most of these solutions have been aimed at medium-to-large enterprises that have extensive IT environments controlling complex business processes. Because of the overarching and pervasive nature of these GRC automation tools, their implementations and ongoing usage can be time-consuming and expensive. This has left smaller, resource-strapped companies out in the cold for GRC automation. Until now, that is.

In early June, eGestalt Technologies announced SecureGRC, a cloud-based integrated IT security and GRC solution. With subscription pricing starting as low as $1,400 per month, even small-to-midsize companies can afford to automate the process of aligning security management practices with organizational governance. SecureGRC scales to serve large enterprises as well.

At this writing, eGestalt’s SaaS model is unique among GRC vendors. But eGestalt doesn’t sell its subscriptions direct to customers; rather, the vendor works through managed service providers that implement the application and help the customer interpret the GRC gap reports. This is especially important for smaller companies that don’t necessarily have GRC expertise in-house.

Akibia is an eGestalt channel partner. Akibia provides services to help companies manage their data center, network and security infrastructure. Akibia uses SecureGRC to offer its customers an Assured Compliance service, which provides visibility into multiple compliance requirements via a single, integrated framework.

Robert Klotz, Akibia’s vice president of technology, says they chose eGestalt SecureGRC because of the product’s functionality, ease of use and low cost. “SecureGRC’s timely collection of data helps us demonstrate to our clients their current compliance profile and compliance issues in a manner that allows them to better understand what controls need to be implemented to assure compliance with their specific policy and regulatory requirements.” Klotz adds that SecureGRC is a full featured, cost friendly solution that is adaptive, flexible and easy to use. He says it’s a particularly good fit for the companies that Akibia serves.

SecureGRC provides the aggregation of compliance, governance and security information in a unified risk dashboard so that a company can see, in near real-time, what its overall risk profile is. This helps break down the separate information silos of security and IT-GRC that are common today. With a single unified view, the company can focus its efforts on mitigating risks to the organization by addressing all of its needs around security, compliance, and risk management through automation, integration of policy controls, and governance frameworks.

Since compliance with policies and regulations is no longer a “point in time” project, organizations must demonstrate that they are actively monitoring and managing compliance as a continual business process. SecureGRC provides companies the ability to demonstrate their proactive management of the security and controls necessary in today’s complex compliance environment where organizations have multiple compliance mandates to manage against.

To provide the proactive and holistic processes needed today, SecureGRC automates the point solutions of policy management, control assessment, data discovery, security monitoring, net-forensics, and threat assessments and integrates them with a workflow engine for timely alerting/reporting of an organization’s current compliance state.

Among the major functions of eGestalt are:

* Policy Manager allows an organization to consolidate and store all its security and control policies in a central repository, measure the company’s current compliance with these policies and view various statistics from a central dashboard.

* Asset and Vulnerability Management is integrated functionality to manage the processes, data and tasks associated with assets and their related vulnerabilities. Asset management involves discovering, identifying and classifying assets such as servers, desktops, laptops, firewallls and so on that are part of any organization. Vulnerability management consists of the ability to discover the vulnerabilities associated with assets and provide the data and insight necessary to manage the vulnerabilities through the use of direct fixes or the application of compensating controls.

* Data Discovery is a comprehensive scanner that searches for credit card data and other confidential data formats specified by the customer. The scanner works on in-house data stores, as well as most commercial and open source databases.

* Compliance Scanning allows auditors, consultants and the internal security/compliance teams to streamline and automate the process of evaluating PCI compliance during their engagements. The compliance scanner accepts results from leading vulnerability and application scanning tools. It has built-in cardholder data search features (Data Discovery) for processing and pre-population of approximately half the controls associated with PCI DSS.

* Compliance Logging gathers system logs for integration and analysis in the overall compliance framework.

* Manager provides an integrated solution to managing the functions, documents and tasks associated with audits of an organization.

If your company is looking for a way to ease into GRC automation, maybe the eGestalt SaaS model is right for you. Contact eGestalt to find a managed service provider that can help you with your implementation.