Home > Security All-in-One Guides > Compliance > Technology > Policy management > SecurityEXPERT eases device configuration but requires the UpdateEXPERT patching tool
All-in-One Guides: Compliance:
EMAIL THIS
 START   SOX SCHOOL   INFOSEC-RELATED REGS   STANDARDS   PROCESS IMPROVEMENT   PEOPLE & POLICY   TECHNOLOGY   AUDITS   
Technology


Policy management
<< PREVIOUS | NEXT >>: Review: Configuresoft's enterprise manager even...

SecurityEXPERT eases device configuration but requires the UpdateEXPERT patching tool

08 Mar 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

SecurityEXPERT 1.0
St. Bernard Software
Price: $1,680 for a one-year, 50-devices license

By Greg Balaze

St. Bernard Software's security configuration management tool, SecurityEXPERT, is a logical complement to its flagship automated patching tool, UpdateEXPERT. This solid first release enables organizations to implement secure configurations across Windows and Unix devices based on policy and/or best practice templates.

SecurityEXPERT is an agent-based OS-hardening tool that automates configurations; for example, it can restrict Windows services and rights to users and files via registry settings. Enterprises can enforce custom policies or draw on templates built on best practices from Microsoft, SANS, NIST, CERT and NSA.

Installing SecurityEXPERT's server (which includes the management console, IIS, Microsoft Data Engine, and setting and scanning Snap-ins) and applying Windows patches was a long process, though St. Bernard says even a large enterprise would require only one master and perhaps three or four additional servers. (SecurityEXPERT includes UpdateEXPERT, which is required and has to be installed separately. UpdateEXPERT is available as a stand-alone product.)

Setting up policies was simple. We placed our two workstations in a group with separate policies for each, using default SANS and Microsoft templates, though we could have easily customized them by selecting and enabling or disabling each policy procedure.

SecurityEXPERT can have multiple security policies active at once, combining the strength of each. If there's a conflict between policies, SecurityEXPERT allows you to view all the changes to be made by the policies line by line, and shows which ones are in conflict. You can then decide what action to take simply by clicking on the policy. This saves a security manager from having to sort through hundreds of potential conflicts. SecurityEXPERT can be set to issue alerts if policies have been changed on a server or workstation, and can automatically push out policies on defined schedules. We had no issues when we ran it overnight.

We tested SecurityEXPERT's effectiveness by reassigning the user account rights on our XP workstation. We selected the SANS template and ran reports to see how far they deviated from the policy template. We pushed the correct policy template to each workstation; after the remediation, we ran new reports, which showed the stations in compliance.

Although thorough and easy to read, the reports were somewhat lacking in customization and flexibility. For example, you can't run a report based on specific policy settings or time. Reports can be exported to a word processor or spreadsheet for further review and analysis.

Impressive for a first release, SecurityEXPERT is on a par with similar tools, such as NetIQ's Vulnerability Manager or Symantec's Client Security. It may be a particularly attractive option for existing UpdateEXPERT users, or for shops looking for patch and configuration management in one package.


MORE INFORMATION:

About the author
Greg Balaze is a technical editor for Information Security magazine.

This article originally appeared in our sister publication Information Security magazine.

BROWSE BY TAG
Network Security: Tools, Products, Software,   Network Device Management,   Enterprise Network Security,   Application and Platform Security,   Enterprise Vulnerability Management,   Configuration Management Planning,   Technology,   Policy management,   Compliance,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Review: Configuresoft's enterprise manager even...
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Network Device Management
Researchers find thousands of flawed embedded devices
Is there a way to block iPhone widgets that bypass Web filters?
Will an application usage policy best control network bandwidth?
What is the difference between static and dynamic network validation?
How to manage network bandwidth with distributed ISP bandwidth
DNSSEC deployments gain momentum since Kaminsky DNS bug
Firewall rule management best practices
What are best practices for fiber optic cable security?
The requirements for being a PCI DSS-compliant service provider
Enterprise UTM security: The best threat management solution?

Configuration Management Planning
Integrated change management reduces security risks
EMC adds configuration management with Configuresoft acquisition
McAfee to acquire Solidcore Systems for whitelisting
Product Review: Shavlik's NetChk Compliance
Security services: Fiberlink's MaaS360 Mobility Platform
CISSP Essentials training: Domain 10, Operations Security
5 Steps for Developing Strong Change Management Program Best Practices
Misconfiguration issues could have contributed to Hannaford breach
Misconfigured networks create huge security risks
Private sector should learn from government insecurity
Configuration Management Planning Research

Policy management
Policy management: Manual vs. automated tools
FullArmor lives up to its name
Review: Configuresoft's enterprise manager even better now

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
OCSP  (SearchSecurity.com)
trusted computing base  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts