Home > Security News > Review: Elemental Compliance System 1.1 innovative, solid
Security News:
EMAIL THIS

Review: Elemental Compliance System 1.1 innovative, solid

By Brent Huston, Contributor
01 Aug 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Compliance is all the buzz, but the real challenge is leveraging tools that give organizations a firm grip on their enterprise security posture and do more than simply earn an auditor's signature. Elemental's Elemental Compliance System (ECS) unites enterprise-wide host configuration, policy management and network access control into one easy-to-use package.

ECS employs agent technology to monitor hosts and align them with policy, polling the server for current policies, assessing host status and reporting back to the server for correlation. If a host or group is out of compliance, network access may be restricted or stopped. Hosts that don't have an agent can be given restricted network access.

The server supports 4,000 managed clients, and multiple ECS servers can share a common master database. Policies can be created from a wide range of rules, including usage of most common antivirus software packages, up-to-date patches, password confirmations and unauthorized program detection. Hosts or groups of hosts are graded by their conformance with these policies.

Groups can be based on attributes such as OS, server role or specific processes running, and dynamically generated from details gathered on the hosts. Hosts can be automatically added to existing groups based on group attributes (e.g., Windows Server 2003). ECS includes policy templates for regulatory compliance (SOX) and best practices.

The server runs on Red Hat Enterprise with an Oracle back end. The Py-thon-based agent runs on Red Hat, Solaris and Win-dows 2000/XP/2003.

The installation of a prerelease of the 1.1 version server, aided by an Elemental engineer, was a little rough around the edges, and re-quired manual editing of configuration files and manual deployment of the Oracle server. Clients were installed and connected to the server. From this point on, the server and clients worked flawlessly.

Almost immediately, ECS began receiving information, starting with vital data points such as IP addresses, MAC addresses and the host OS. After several minutes, the host compliance was rated.

The SSL Web-based interface is clean and well-designed; our tests were a breeze thanks to the simplicity and effective, logical placement of controls.

Each user can have multiple report pages that are completely configurable. Users can view compliance at a high level or can drill down to individual hosts. Reports can be generated for overall compliance, trending over time, group membership, host attributes and packet filter data.

ECS is a very innovative system and a solid, albeit young product that can go a long way in helping any organization meet its policy guidelines.

Brent Huston is a technical editor for Information Security magazine, where this review first appeared in the August 2005 issue.

Tags: FISMAHIPAAData Privacy and ProtectionSarbanes-Oxley ActCompliance management systemsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
FISMA
GAO report cites government weaknesses, data leakage
DHS fills National Cybersecurity Center post
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
White House cybersecurity czar faces major hurdles
Feds should get private sector advice on cybersecurity
ICE Act would create White House cybersecurity post
Experts alarmed over U.S. electrical grid penetration
Group identifies top 20 security controls to thwart cyberattacks
FISMA compliance made easier with OpenFISMA
FISMA Research

HIPAA
Cost of security, IT management add up at healthcare facilities, study finds
Healthcare security spending remains sluggish, report shows
Creating a HIPAA employee training program
FTC extends breach notification to Web-based health repositories
Are there guidelines to create a HIPAA-compliant data center?
HHS HIPAA guidance on encryption requirements and data destruction
Writing a patient identifier policy to prevent common HIPAA violations
HIPAA compliance: New regulations change the game
HIPAA compliance manual: Training, audit and requirement checklist
Key elements of a HIPAA compliance checklist
HIPAA Research

Data Privacy and Protection
Quiz: Compliance-driven role management
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Researchers predict SSNs, crack algorithm putting identities at risk
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Data Privacy and Protection Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Federal Information Security Management Act  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts