Security, compliance and management converge

Opinion
Aug 31, 20053 mins

* What the convergence of security, compliance and management means

The convergence of security, compliance, and management has become a significant area of focus for Enterprise Management Associates.

On Sept. 8, I’ll be hosting an EMA Webcast that takes a look at some of the ways this convergence is shaping the managed enterprise (more information about that below). Until then, let me whet your appetite for this event by giving you some examples of why this trend is something the enterprise should know more about.

Beyond the core benefits of centralization and automation are even more significant ways in which security, compliance, and enterprise management combine to provide maximum value. Using tools such as vulnerability management to inform and define software management priorities, for example, has revolutionized many approaches to systems management.

More recently, we’ve seen security management tools increasingly integrate remediation functionality themselves. This represents the logical next step in their evolution, since closing gaps completes a lifecycle approach to security and compliance management.

However, when this task touches on business-critical functionality, it is not something undertaken lightly. Patch management is perhaps the best-known example of this – but that raises the thorny issue of automating systems reconfiguration in response to a security event. No one wants to be responsible for deploying the “Mother of All Denial-of-Service Vehicles”!

Because of these and other factors, we are seeing three primary ways in which security and compliance are converging with management.

First, when security and compliance issues are central, or when security and compliance products have a more mature concept of the relevant issues, they are best positioned to directly manage critical functionality themselves. Identity-based access management fits into this category – but increasingly, so do emerging tools like policy management systems that address a wide range of policy-dependent issues.

Second, when there is compatibility between security and compliance tools and enterprise management, remediation may best be negotiated between their respective strengths. This is the meeting ground of evolving integrated products such as endpoint compliance enforcement systems, and next-generation security event management systems.

Third, when an enterprise management product has principal responsibility for critical functionality, extending its capabilities in security and compliance management may make the most sense, particularly when it adds to the return on investment of the management product and reduces the need for other security- or compliance-specific expenditures. Configuration and change management software is an example of this group, which can be further enhanced with greater integration of identity-based controls.

We’ll go into a lot more detail on these topics and even more examples on Sept. 8 at 4 p.m. Eastern/1 p.m. Pacific. I invite you to join us for this event by registering here.

Next week in this space I’ll talk about some of the gaps in this trend, which will give you an idea of what to look for in the new and emerging ways in which security and compliance are converging with enterprise management.