YOUR FEEDBACK
3rd International Virtualization Conference & Expo: Themes & Topics
queZZtion wrote: Who is the current leader in the market for backup and di...
SOA World Conference
Virtualization Conference
$50 Savings Expire May 23, 2008... – Register Today!

SYS-CON.TV
TODAY'S TOP SOA & WEBSERVICES LINKS


Weathering the Storm of IT Security Compliance
It's 90% process and 10% technology

Digg This!

Page 2 of 2   « previous page

Following a more administrative approach to addressing potential risks, systems administrators should consider a configuration management database or CMDB-driven data repository as the starting point. Administrators could actually prevent most of the risks to their IT infrastructures by gaining a complete understanding of details associated with system settings and configuration controls at all points throughout the enterprise. Defining the policy on which an organization builds a "gold standard" of operation without this critical step results in an ineffective reactionary-based trend in enterprise IT security.

 Over the Rainbow
Once administrators have collected that mission-critical data, they can begin to shape an appropriate policy for what should be considered the "gold standard" of operational expectation. Blending the strong integrity of a CMDB-based approach to policy management further capitalizes on the administrator's ability to address the need for pre-emptive control rather than post-event recovery. In a sense, you can't fix what you don't know is broken, but you CAN plan for risks when you know what you have and how it's working before those risks are exploited.

The old axiom that "knowing is half the battle" certainly rings true where your organization's risk management plans are concerned. Organizations can no longer afford to claim "The hole is on your side of the boat."


Page 2 of 2   « previous page

About Drew Williams
Drew Williams, a long-time information management and security strategist, pioneered the vendor security research team model with the industry's first such group, AXENT Technologies' "Information Security SWAT Team." Drew was also a founding member of the President's Partnership for Critical Infrastructure Security, a member of the Internet Engineering Task Force on Internet Security, and an initial member of the independently supported CVE development team. He has served as a security policy advisor to major financial institutions, health care manufacturers and state governments.

SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
SUBSCRIBE TO OUR RSS FEEDS & GET YOUR SYS-CON NEWS LIVE!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON FEATURED WHITEPAPERS


ADS BY GOOGLE