Home > Pitching patch: Configuresoft
Information Security magazine:
EMAIL THIS

Pitching patch: Configuresoft

27 May 2005 | By Neil Roiter

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Configuresoft's response emphasized the Enterprise Configuration Manager (ECM) and Security Update Manager (SUM) suite's strength as a configuration management and automated patch management product, turning the issue, correctly, into one of overall vulnerability management. While the company's proposal for patch management wasn't the strongest for our requirements, Configuresoft's overall approach was on point.

Configuresoft crafted its own version of what it deduced was our requirements (in addition to addressing our specific requirements). To some extent, we found this helped focus on big picture issues, but our overall sense was that this enabled Configuresoft to define the problem in its terms and tailor the solution to its strengths.

Following this line, Configuresoft -- like most respondents -- provided no real plan for our company, leaving us to "imagine, if you will" how its deployment would look and work. Configuresoft's agents give it tremendous flexibility for security policy setting and automated remediation through the central database. ECM allows the creation of custom templates to assess and remediate any app—a plus. It also allows for highly granular grouping of devices for remediation, though this is probably of more value to larger, more complex organizations.

Configuresoft uses a DCOM-based agent, using RPC, known for its vulnerabilities, to communicate, but it encrypts all communications with AES over HTTPS.

The company's response on the issue of mobile users and satellite offices was a mixed bag. Configuresoft mentioned distribution points that sounded like local caches to reduce WAN bandwidth, but what they are and how they work was unclear. A plan tailored to our company and a good diagram would have helped.

<<Return to Pitching patch

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts