Denise Dubie
Senior Editor

Building IT governance into your management regime

Opinion
Feb 26, 20074 mins

* Governance, risk and compliance management tools

First I must address an error I included in one of last week’s newsletters, “Management and open source software, together at last.” I had said the fledgling industry organization, the Open Management Forum, seemed to be defunct, but I was mistaken. A DNS error had made their Web site inaccessible from the address I had and from the links provided in a Google search. I am happy to report the OMC is alive and thriving with more than 30 members working toward open source and commercial management application interoperability. More on that group in future newsletters.

Now onto today’s topic. Aspects of IT governance have come to the forefront of IT executives priorities in light of compliance deadlines for industry regulations such as Sarbanes-Oxley and Health Insurance Portability and Accountability Act (HIPAA). While there are commercial products that promise to help IT managers track compliance, IT governance in and of itself is not just about technology. It is about how IT delivers services — either in a centralized or decentralized manner — and the controls and documentation put in place to maintain accurate configurations and enforce processes. For instance, IT governance would monitor changes and access made to systems and assess if those acts comply with security or regulatory policies.

Forrester Research categorizes such products as governance, risk and compliance (GRC) management tools. The products comprise many functions once handled by disparate department across an enterprise organization.

“Increased risk and regulatory pressures in a distributed enterprise are propelling organizations to craft consistent game plans for centralizing GRC oversight,” reads a recent Forrester report. “Organizations are to establish a platform that maintains a system of record for GRC. This enables disparate compliance and governance technologies to combine into a coherent regime for managing GRC across the enterprise.”

With the size of todays IT environments and the constant rate of change to systems, many vendors have emerged with products that would automate the monitoring and assessment of these myriad changes. One problem area is monitoring changes to determine if they comply with preset policies and that those making changes are authorized. In the past month alone, Active Reasoning and Tripwire updated their governance platforms to provide enterprise IT managers with more ways to ensure policies are followed and compliance demands are met.

To start, Tripwire updated its flagship software with more system support and enhanced capabilities that the company says help IT handle changes based on the systems to which they are made.

Tripwire Enterprise 6.0 comprises the company’s previous products Tripwire for Networks Devices and Tripwire for Servers into one enterprise offering. Tripwire Enterprise 6.0 now can also determine if a change was made by authorized personal.

“A large number of organizations don’t have to the tools in place to monitor change. Are changes made at the right time, made in the right way and is the person making them authorized to do so?” says Rob Warmack, Tripwire vice president of marketing and communications. “In this release, we can automatically detect change and analyze it to ensure that the change is OK.”

Also in this release, Tripwire added SQL support and expanded directory support to the software.

Separately, Active Reasoning updated its flagship software as well. The company uses its product to track and log all the actions taken by IT staff. The software can be linked to event management systems from BMC’s Remedy or HP’s Peregrine tools to see if a change made by a systems administrator on, say, an NT server, caused poor application performance.

Active Reasoning System 5 now includes a policy mapping database, which gives IT managers a map of policies and control frameworks and the end users, applications, systems, network devices, files and databases related to them. The view would quickly show IT managers which elements need to be monitoring to properly enforce the policies, the company says. The software also includes continuous change detection, SNMP event monitoring and an enterprise risk dashboard to show how well an organization’s operational activity is following defined policies and controls.

“We take the approach of making monitoring continuous, taking care of the bits and pieces that need to be monitored in relation to an organizations policies and controls,” says Andrew Lochart, Active Reasoning’s vice president of marketing. “The number of changes that need to be monitored and measured for risk are too great to do it manually. We reconcile the changes and activities reported against the control systems to give customers a broader view of what is going on across their network.

Denise Dubie

Denise Dubie is a senior editor at Network World with nearly 30 years of experience writing about the tech industry. Her coverage areas include AIOps, cybersecurity, networking careers, network management, observability, SASE, SD-WAN, and how AI transforms enterprise IT. A seasoned journalist and content creator, Denise writes breaking news and in-depth features, and she delivers practical advice for IT professionals while making complex technology accessible to all. Before returning to journalism, she held senior content marketing roles at CA Technologies, Berkshire Grey, and Cisco. Denise is a trusted voice in the world of enterprise IT and networking.

More from this author