by Mandy Andress

Altiris takes unique approach to client system connectivity

Reviews
Jun 12, 20063 mins

SecurityExpressions is the only product tested that provides full policy-check functionality whether the client connection is agent-based or agentless.

Altiris has a unique approach to client system connectivity. Altiris’s SecurityExpressions is the only product tested that provides full policy-check functionality regardless of whether the client connection is agent-based or agentless.

Altiris (formerly Pedestal Software) has a unique approach to client system connectivity. Altiris’s SecurityExpressions is the only product tested that provides full policy-check functionality regardless of whether the client connection is agent-based or agentless. Administrators don’t even know which type of connection the system is using when running a check once the host is configured in the system.

Users also can run a distributed proxy, which has one Altiris agent serving as the communication point to the primary server for a number of other servers. This can help cut down on the amount of network traffic or number of firewall ports that need to be open.

The standard regulatory and guideline policies are offered out of the box, as with the other products tested.

Altiris provides the most flexibility in developing policy checks and remediation options: If you can script it, you can check it. During our testing, we created scripts to run on the system, making it out of compliance. The outcome of the script was inconsequential to compliance, but the ability to execute the action was simple and flexible.

Access control is limited and does not provide much detail. Some level of access control is available on a page-by-page basis, but this is difficult to administer and not easy to implement in most organizations based on standard support structures.

The user interface is easy to use once the user understands how it works. The one necessary improvement would be the ability to understand what scan was run at what time. Right now, the user sees just a date/time stamp with no indication of which policy check was run or what systems were analyzed.

Policies comprise rules, which are then bundled into rule groups, which are further combined to form compliance templates. Creation of both of our test policies was ultimately successful, but the process was not very intuitive.

Policy files can be encrypted to prevent unauthorized modification. Policy files are updated by downloading new files from the Altiris support Web site. Running policy scans against target systems is very quick, taking just a few minutes and resulting in a list of OK/Not OK machines, from which issues can be identified quickly. Users can view results to date while a scan is in progress, which also is unique.

Specific delta reports are not available, but the Altiris trend report provides not only trend graphs, but specific details of what changed. This satisfies the requirements of the delta test here. Most of the other products contained trend reports, but they just showed a high-level increase or decrease in compliance and did not include any specifics on the changes that occurred to change the compliance level.

With Altiris, remediation and policy checks are similar because you can script them all. Autoremediation is available, and remediation options are virtually unlimited with the scripting flexibility.

Previous: Elemental Security | Next: New Boundary >