Preventsys security dashboard shows where you are at risk

Opinion
Jul 11, 20054 mins

* Preventsys Enterprise Security Management

A few weeks ago we wrote about various software tools that help you meet the regulatory requirements of the Sarbanes-Oxley Act of 2002. While there are many niche products that help with one aspect or another of compliance, there is one product that gives you the broadest possible real-time view of your enterprise network, as well as provide steps for remediation when something is out of bounds. We’re talking about the Enterprise Security Management System from Preventsys.

Now before you start thinking this is a tool that is only for Sarbanes-Oxley compliance, shake that notion from your head. In fact, “Sox” compliance enablement is only one small part of what ESM does. More broadly, this product is a consolidator of all kinds of security information. The bottom line health of your network is presented in a dashboard format so that you can easily see if or where you have a problem, and how critical it is.

True enterprise security requires an ongoing commitment to managing the entire security lifecycle. You must be willing and able to discover, assess, prioritize, mitigate, eliminate the root cause of, and monitor and measure vulnerabilities and threats at all times. Most companies today manage at least parts of the process, perhaps with discrete tools on portions of the network.  ESM ties all these pieces together and unifies the data so you get one holistic view of your network. And there’s no need to rip and replace anything that you’ve already got in place as far as vulnerability scanners, configuration managers, audit applications, and the like; instead, ESM uses the output of those tools to feed the dashboard and give you the big picture.

In the Preventsys realm of security management, Linux-based appliances called asset management servers reside on various segments of the network. They collect information about assets by using their own discovery tools and by accepting input from other sources monitoring the “six degrees of assessment”: operating system and software flaws, host configurations, application configurations and settings, database access, wireless networks, and network architecture. The information collected covers every security and configuration aspect of your assets.

The asset management servers pass the consolidated information to the centralized Enterprise Security Manager application. At this point, the data is correlated and simplified. The ESM checks the condition of your data against vulnerability lists such as those from the National Security Agency (NSA), National Institute of Standards and Technology (NIST) and The SANS Institute.  The data is also compared to the required conditions of internal policies and external regulations such as Sox, the Health Insurance Portability and Accountability Act (HIPAA), and the Graham-Leach-Blilely Act (GLBA). 

The results of these comparisons are projected into a dashboard – a quick view of your risks and vulnerabilities. Perhaps most importantly, the ESM lets you see the priorities for remediation of your vulnerabilities. A server with out-of-date operating system software, for example, would require a higher level of attention than a PC with obsolete anti-virus signatures. And if you use a help desk tool such as Remedy, you can automatically generate trouble tickets to initiate action to install an operating system patch and update the PC anti-virus files. 

As for the audit compliance – or any other policy, for that matter – Preventsys ESM is able to read your policies in Word format, translate them to XML, and then perform a control check on your network. This automates a process that is typically manual and very time consuming.

Network World has twice honored Preventsys in 2005 with awards for “best” products in the security management and security auditing tools categories. If you’re looking for one overarching tool to help summarize and prioritize your security vulnerabilities, give Preventsys a look.

Linda Musthaler is vice president of Currid & Company.  You can write to her at mailto:Linda.Musthaler@currid.com