Advantages of UpdateEXPERT Premium

Threats to systems have been evolving sometimes faster than our ability to defend against them. Initially, anti-virus software was adequate to protect systems against malicious attack. Subsequently, anti-virus software had to became a service because of the continual addition of virus signatures - sofware releases simply couldn't keep up. Eventually, vendors started to release security patches to deal with vulnerabilities in their own programs. Now, there is much focus on combating spyware with new anti-spyware solutions cropping up everywhere.
The next stage in this continuing effort to provide more and more defenses to protect and harden your systems is security settings management. Insufficient security settings have been recognized by SANS as one of their top ten OS vulnerabilities. When security settings are insufficient, they create holes in your network that patching alone can't close. Security settings, for example, include making changes to systems to restrict/control; allowing or disallowing remote access to a desktop; changing permissions to different directories to enable/disable access;
modifying service settings (such as turning or turning off ftp, remote login, etc.); and closing or opening different communication ports.
"Security policies are an absolute must for any organization. They provide the virtual glue to hold it all together.
Imagine a small city that did not have any rules? What would life be like? The same applies to your organization - policies lay the groundwork."
Michele D. Guel, A Short Primer For Developing Security Policies |
With the recent release of UpdateEXPERT Premium patch management security software, St. Bernard Software has added security settings management to patch management to create a powerful tool aimed at helping system administrators harden systems. The solution we developed enables you to manage these settings in a similar way you manage patching with UpdateEXPERT service pack / patch management security software. To facilitate the design of security policies, UpdateEXPERT Premium incorporated the recommendations of leading experts such as SANS, NIST, CIS, CSE and Microsoft and created easy to use templates. If you were to try and configure your security settings through research, you would find yourself searching through reams of documentation - some of them 400 pages in length. To avoid that scenario, our engineers have summarized these documents into concise security points and compiled a variety of templates that you can save and apply to your own systems. These templates target the most widely used OS applications such as Enterprise Client Desktop, Enterprise Client Laptop, etc. Servers by their very nature are unique and need specific targeted settings.
The usage model is simple -
- Create a policy,
- Assign the policy to a group of computers,
- Deploy the settings,
- Run reports to verify that the computers are in compliance with the designated policy.
Of all these tasks, coming up with a relevant and effective security policy is the most difficult. UpdateEXPERT Premium service pack / patch management security software provides invaluable tools allowing you to form policies, for both patching and settings management, and then enforce compliance to your policies.
There are a couple of ways you can establish policies; in one, you choose a single expert's recommendations, such as NIST, and make that your policy; or, you can choose recommendations from multiple experts and UpdateEXPERT Premium will show you their differences You can then
resolve the differences by choosing a recommendation that suits your environment.
I have been speaking to various analysts about security trends in the market. Consistently, they have brought up the issue of security settings management. They told me that in the initial phase, larger organizations are implementing solutions to deal with insufficient security settings. In the next phase, they believe small and medium-sized enterprises will recognize the importance of security settings on their own, or will be required to do so by their larger business partners. We added this functionality to UpdateEXPERT Premium service pack / patch management security software because we believe it provides critical protection for our customers. So far, it has been well received by analysts and customers alike.
|
 |




|