Agentless and Agent-Based Vulnerability Management
This document describes the benefits of both agent-based and agentless auditing techniques and highlights the associated implementation
and ongoing implications of each solution. The document is intended to help customers determine which SecurityExpressions
configuration – agent-based, agentless, or a combination of both – to use to solve their system security auditing and compliance need
for their specific environment.
Advanced Audit Tasks
This document details the components necessary to achieve comprehensive system security. Specifically, it illustrates many types of audit checks/actions that are critical to maintaining good system security, but are above and beyond implementing an industry best practices system security policy, patch management solution, and unauthorized hardware/software identification protocol.
Key Considerations for System Security Policy Management
This document outlines the factors that should be considered when looking for a powerful system security policy management solution. An outline of the necessary functionality and their benefits is also included in this white paper.
Sarbanes-Oxley: A System Security Perspective
When system audits fail, CEOs and CFOs must create instant security projects to secure their systems before they can legally sign Sarbanes-Oxley documents. The combination of a failed audit and the potential penalties associated with Sarbanes-Oxley infractions (i.e. personal fines, personal jail-time) currently drives the creation of system security policy management projects at the majority of publicly traded companies.
System Vulnerability Management Definitions
The category of System Vulnerability Management is a broad category that contains both proactive and
reactive system security components - each of which solves a different problem. These components
include: patching, vulnerability scanning, vulnerability remediation, system security audit and compliance,
and network access control. This document contains definitions for each component.
System Security Policy Management
This document outlines how to efficiently perform audits and to apply policy across all desktops, workstations, and servers.
This paper also introduces the concept of a security policy management and its impact on auditing and adhering to corporate system
security policy.