Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 2006

Examining Security-Policy Management

It all comes down to what’s important to your environment
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!

Companies create security policies for many reasons—perhaps you need to comply with corporate security standards, or you want to adhere to certain recommended best practices, or you need to abide by regulatory compliance. Your computing environment is unique, and therefore your security policies need to be tailored to your specific infrastructure. The biggest security-policy management challenge you probably face is accomplishing it all without increasing head count and costs.

You're probably on the lookout for an easy-to-use solution that provides visibility into your organization's current state, as well as automated remediation. You'll find a wealth of solutions on the market that seek to protect specific aspects of your organization— whether it's Active Directory (AD), file servers, workstations, or a combination of these or other areas. Where do you start looking for that perfect solution that targets your specific needs? Let's examine the various factors that might comprise a security-policy management solution, from AD integration to regulatory compliance to endpoint security.

Pillar Protection
AD is the central pillar of many organizations, and changes made to it can affect users company-wide. Administrators can use AD to push security policies across the entire enterprise, so it's vital that you know who is making changes, what the changes are, when the changes are being made, where the changes are being made, and why the changes are being made. NetPro considers this "5 Ws" list the centerpiece of its ChangeAuditor for Active Directory product. ChangeAuditor identifies these "5 Ws" for all changes to group and user configuration in the AD environment. NetPro offers similarly functioning modules for file servers and Microsoft Exchange Server.

Configuresoft's Enterprise Configuration Manager (ECM)—although not tied solely to AD—also plays a big role in the Windows security-policy management space, offering support for Exchange, Systems Management Server (SMS), and so on. Recognizing the uniqueness of individual environments, Configuresoft has fashioned a solution that collects thousands of asset, security, and configuration settings from throughout your enterprise and stores them in its Configuration Management Database (CMDB). You can then use this assembled information to determine which policies are appropriate for your infrastructure.

You should also consider NetIQ in this arena. Its Change Guardian for Active Directory is similar to NetPro's solutions, in that it ensures that all changes to AD are authorized, monitored, and audited.

Targeted Systems
Most vendors in the security-policy management market provide policy templates from popular industry experts or leading IT security organizations to help you secure your organization. Most of these templates are customizable, or if you feel up to the job, you can create your own template from scratch. New Boundary Technologies, like many other vendors, offers policy templates but sets itself apart from the competition in other ways. Its policy-management solution, Policy Commander, automatically implements, monitors, and enforces computer-security policies across your network, whether internal or remote. The unique aspect of Policy Commander is its specialized targeting of security policies. Targeting—based on each computer's configuration and role, security level, organization group, and location—lets organizations push a particular policy out to only the appropriate computers or servers that need it.

Altiris offers similar functionality but separates itself from the pack with its cross-platform support and agent/agentless structure. Altiris's SecurityExpressions automatically audits, deploys, and enforces security policies across all Windows, UNIX, and Linux desktops, notebooks, and servers. Such cross-platform support is becoming more and more important, as many IT shops are becoming increasingly heterogeneous.

Regulatory Compliance
Generally speaking, security is a never-ending battle that administrators fight across all aspects of the organization. Lately, security has played a key role in the midst of increasing regulatory-compliance pressures in the wake of Health Insurance Portability and Accountability Act (HIPAA) and Sarbanes-Oxley (SOX) Act. Auditors now require that customers provide evidence of compliance policies, so it's important that you know where you're compliant and where you aren't.

Security-policy management solutions help you identify your compliance levels, but more important, such solutions help you—and your auditors—address any security gaps and learn how to bridge them. With its Directory Experts Conference Survey, NetPro polled users about their organizational priorities. Whereas 67 percent of respondents answered that improving Windows security was the top organizational priority, 73 percent of respondents marked compliance as the top priority.

   Previous  [1]  2  Next 


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Learning Path For information about least privilege:
"Least Privilege User Accounts On Windows XP"

"Dealing with the Least Privilege Security Principle"


For information about NAC and NAP:
"Market Watch: Network Quarantine"

"Hey Microsoft!: QUARANTINE!"


For information about regulatory compliance:
"Is Your IT Infrastructure Compliance-Ready?"

"Sarbanes-Oxley Checklist"


Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

WinInfo Short Takes: Week of July 21, 2008

An often irreverent look at some of the week's other news, including an iPhone 3G defeat, 180 million copies of Windows Vista in the wild, Microsoft earnings some more Yahoo silliness, Wii vs. Xbox 360, EU vs. Intel, AMD ousts its CEO, and so much more ...

What service packs and fixes are available?

...


Active Directory (AD) Whitepapers An Introduction to Windows Server 2008 Server Manager

Get More from Active Directory—Easily Audit Changes, and Secure and Restore Objects

User Provisioning: Get the Most Bang for your IT Buck

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Shortcut Guide to SQL Server Infrastructure Optimization
With right tools and techniques, you can have a top-performing SQL Server infrastructure without having to cram your data centers so that they're overflowing. Download this eBook to learn how.

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Continuous Data Protection and Recovery for Exchange
Read this white paper to learn about Continuous Data Protection (CDP), Exchange 2007's local continuous replication and cluster continuous replication features.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Tips to Managing Messaging
Discover three fundamental mail and messaging management services - security, availability and control services - and how you can implement them in a Microsoft-centric mail and messaging environment.

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Drag & Drop Data Mapping Tool
Try this award-winning data mapping, & transformation tool that supports multiple databases, flat files, Web services, EDI, Excel 2007, & more! Free trial for 30 days!

Overcome bloated Windows file systems
Crossroads FMA delivers powerful yet inexpensive data migration

Bandwidth Monitoring Tool from SolarWinds
Identify largest bandwidth users in seconds. Get the free download now.

Speed Deployment of Vista and Microsoft Office
Read this white paper to learn how you can maximize your Vista and Office investments while lowering costs and increasing efficiency.

Integrated Virtualization Done Right
Download this white paper on server virtualization to begin improving resource utilization and lowering operating costs.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

KVM over IP Solutions
Learn about a KVM over IP solution that is specifically designed to meet the needs of the distributed IT environment.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing