|
|
|
|
Policy Enforcers
|
 |
|
May 29, 2003
By Mike Fratto
|
>> continued from previous page
Symantec Enterprise Security Manager 5.5
Enterprise Security Manager (ESM) excels on reporting--the level of detail is certainly on par with that of Configuresoft ECM. In fact, the reports are so well designed that we needed to do very little customization. Roll-ups down to technical details are available within a few clicks. Unfortunately, ESM subjected us to some deployment difficulties, and its pricing places it at the high end of the spectrum.
ESM uses agents to gather data from remote hosts, and the agents can be centrally deployed--in theory, anyway. The process is somewhat convoluted, however, requiring that you build a temporary share on your management station and install a remote update agent on the targets. The manager should then instruct the remote update services to connect to the share on the management station to install the software and register with the manager; once successful, the remote update service will be removed from the target, and the share is also removed. We say should because we couldn't get any of our targets to connect back to the installation share on the manager, and Symantec couldn't figure out a fix. There is a silent installer, however, that we used with success.
We used predefined reports to get a view of our network. For the roll-ups, ESM scores and totals misconfigurations for a measure of risk or vulnerability. While good for making generalizations about population status, the scoring is somewhat arbitrary. In this case it's in the details, where the devil resides, that ESM shines. The detail reports provided easy-to-understand information about each issue, how it was resolved, and sometimes even potential difficulties that may result.
|
|
Building custom reports and ad hoc queries, while possible, isn't as straightforward as we would have liked. Again, with familiarity and experience, customization became easier, but getting to that point took time.
Finally, many fixes can be applied, but ESM doesn't support remote patch deployment.
Symantec Enterprise Security Manager 5.5, Symantec Corp., (800) 441-7234. www.symantec.com
|
 |
 |
|
|
|
 |
|