Solution providers angling for a piece of the $29.9 billion that will be spent on compliance this year, by AMR Research's estimate, have no shortage of products to choose from. Forrester Research counts as many as 500 software vendors that offer compliance applications, covering the gamut from risk assessment to e-discovery. But there is no such thing as a complete compliance solution.
There is one common starting point for the many-legged compliance beast, though—an audit of a company's assets. As such, for this Solutions That Work, the CRN Test Center decided to pull together a flexible, easy-to-manage compliance audit solution.
While a sound asset management process is critical in its own right, it also is the backbone of any compliance engagement, solution providers say. Rather than wasting energy on ad hoc solutions for meeting specific regulations, companies are finding that implementing best IT practices for asset management will quite naturally resolve many compliance issues, or lay the groundwork for the resolution of specific issues.
Fortress Network Security, a Louisville, Ky., solution provider, always starts with an asset inventory before developing a security controls solution, said Mike Meyer, security project manager at Fortress. "A network auditing tool cuts down on the time required to gain an understanding of the customer's network," he said.
Asset protection covers myriad functions, from tracking equipment, to ensuring only authorized users have access to assets, to checking software licenses, to patching security vulnerabilities. There are a number of tools that do the job. While CA has its Unicenter family of products, IBM is organizing its Tivoli product family into a comprehensive Compliance Framework and Hewlett-Packard provides its OpenView Configuration Management Inventory Manager.
Besides the platform vendors, BigFix, PatchLink and Shavlik offer patch management suites. Altris has two products: Asset Management Suite and Security Expressions patch management software. Layton Technology's Audit Wizard also has automatic network discovery and can collect asset, user, hardware and software details as well as identify installed applications on Windows machines.
For this audit solution, we chose CA's Unicenter products: Unicenter Asset Management, Unicenter Patch Management and CA Configuration Management Database. A unified approach like CA's solution makes deployment easier and monitoring straightforward.
Next: Step 1: Create An Inventory