* More than one way to skin security management
Both agent-based and agentless approaches have been developed to help IT managers deal with security.
Security is unique among management domains in its ability to “make lemons out of lemonade,” turning lessons learned from the gaps in security management into valuable assets that close those gaps.
Vulnerability management, for example, arose directly out of legitimate penetration testing, using the tools used by attackers for finding the chinks in IT’s armor.
Vulnerability management has come a long way from those early days. Today’s vulnerability management systems perform a number of highly sophisticated functions, enabling the enterprise to see a lot more than an attacker can, and even identifying likely attack paths. Increasingly, they also integrate directly with other management systems to help the enterprise to discover, prioritize, and remediate its exposures more effectively.
Security scanning techniques continue to form one of the cornerstones of agentless security management.
Other agentless scanning techniques include those used in endpoint compliance enforcement. This type of scan assesses the health of a network endpoint before a connection is established. An endpoint found not to be in compliance after a scan may be redirected to a remediation or containment site, or a safe network zone isolated from the trusted production network.
Endpoint security measures are perhaps more often associated with agent-based techniques, and in IT security, few agent-based approaches are more well-known than anti-virus applications, which have become ubiquitous in the face of many years of endpoint-focused attacks. These attacks have also precipitated the widespread use of so-called “personal” firewalls and host intrusion prevention systems. More recently, host-based anti-malware has expanded to include so-called anti-spyware systems which detect and block software that can exploit information gleaned from the host and its users.
The coordination of these techniques in comprehensive endpoint compliance enforcement has, in turn, produced agents that can assure the coordination of an entire range of protections. The major vendors have already begun to consolidate the functionalities of their endpoint security agents, which heralds a trend we can expect to continue.
Still another highly significant aspect of security is software and configuration management, where agent-based and agentless approaches are often combined. Even in a regime in which agents are deployed, agentless detection can determine by a target’s response to specific probes if an update or reconfiguration is required. Configuration management in particular is becoming a central aspect not just of security, but of IT management generally, reflected by initiatives such as the increased interest in ITIL compliance.
We at Enterprise Management Associates are conducting a survey on the use of agent-based versus agentless management techniques. In fact, if you can take about 5 minutes to complete our survey you will be provided with the final paper when complete. We look forward to your participation.




