Product review: TraceSecurity Risk Manager - Information Security Magazine

Security Services: TraceSecurity Risk Manager

SecurityReview

TraceSecurity Risk Manager

TraceSecurity
Price: Starts at $9,500

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

for 2 years


Regulatory compliance requires companies to not only adopt stronger security controls, but demonstrate to auditors that those controls are implemented and maintained as part of ongoing business procedures and not just paper policies and neglected security tools.

That's a lot for any organization, especially those outside traditionally highly regulated industries and/or lack the resources and expertise to adequately monitor and enforce their policies and deliver auditable reports.

TraceSecurity takes on the heavy lifting of compliance for SMBs through its SaaS suite, Compliance Manager, and several related services. Risk Manager 1.0, its newest service, maintains an automated, continuous risk assessment process for customers, a significant step beyond one-time, third-party assessments conducted by TraceSecurity and many other consulting firms.

"In the past, we would do all the work, give our report and walk away," says CTO Jim Stickley. "It wasn't that functional after we left--just a snapshot of their life."

Risk Manager scans the network and delivers risk scores, profiles and reports based on potential threats and asset criticality as determined by the customer, guiding risk management and mitigation, and satisfying audit requirements.

It can be applied to nontechnical risks as well, to help form disaster recovery/business continuity plans.

TraceSecurity's flagship service, Compliance Manager, provides continual monitoring, measures current security progress and posture and produces vulnerability reports and remediation recommendations.

--Neil Roiter

This was first published in March 2008