Compliance

Securing IT starts by managing IT

Challenges

Defining systems configuration policies allows having a methodical and systematic approach to guarantee homogeneous security.

Repository of security standards exists. They allow building a rational framework, which takes into account the human, organizational, legal and technical aspects (ISO27001, ISO17799 SOX). Nevertheless, enforcing these policies and technically assessing non-compliant devices is a complex and time consuming challenge.

- Standardise systems configuration
- Evaluate and guarantee security and configuration policies enforcement
- Target the non-compliant systems and act quickly to remedy
- Manage systems configuration to secure them better

Compliance

Criston Solutions

For compliance rules, standards, best practices (ISO27001, NIST, etc.) or even customised policies, the Precision Agent can assess the compliance level of each system towards numerous criteria (hardware, software, system, security configuration etc.).

Criston Precision offers the possibility of defining a set of rules (template or custom) and estimate the state of each device through executive reports.

Non-compliant devices can easily be targeted and remediation actions deployed.

Compliance Rules Samples:

- Administrator Accounts <= 1
- Password length> 6 characters
- Antivirus = up to date
- XP Firewall = Enabled with 1610 port open
- No instant messaging software installed
- Enterprise Application version x.x installed

Compliance Templates

Assess all systems against out-of-box security and configuration rules and policies based on recommended best practices or standards

Customised Compliance Policies

Define customised policy rules and assess all systems. Automatic creation of non-compliant group of devices for immediate remediation.

- Compliance level assessment
- Schedulable assessment of groups of devices against several policy rules.
- Non-Compliant device targeting and remediation
- After a compliance assessment, it is possible to create a group of device including all non-compliant systems, and automatically execute an action on all devices of this group (deploying a patch, setting a configuration parameter…)
- Dashboard and Reporting
- Executive and technical reports template or customisable reports are available.