|
|
|
|
Policy Enforcers
|
 |
|
May 29, 2003
By Mike Fratto
|
>> continued from previous page
PoliVec Security Policy Automation Suite (Builder 2.6, Scanner 3.5, Enforcer 1.1)
PoliVec offers three loosely integrated products--Scanner, Enforcer and Builder--that do the work of other vendors' single products. This approach does let you purchase only those components you need, but the integration is not seamless.
Scanner discovers the configuration of network hosts and is agentless for Windows targets. Enforcer allows configuration changes to be deployed to target systems, using agents. In the case of Unix systems, Enforcer can also discover configurations. Builder creates from templates security polices that can be distributed and read by end users. Policies can also be exported as XML documents and imported into Scanner and Enforcer.
Builder is a breeze to use--simply run through the wizard and select the policy statements to include in the final policy. Icons show which items are used in Scanner or Enforcer and often have configurable items. For example, we wanted a strict password policy, which we defined in Builder and exported to Scanner and Enforcer. Builder offers lots of explanatory text about policy statements, and each statement could be annotated and customized.
Scanner takes policies--predefined, imported from Builder or defined in Scanner--runs through the selected target, and reports back. Scanner is focused on comparing targets to configurations and lacks some of the robust ad hoc querying capabilities found in other products.
|
|
Enforcer is an automated monitoring tool that takes an implementation standard derived from Builder and checks for compliance. Alerts are generated on non-compliant items, and based on defined intervals, we escalated notifications on unhandled exceptions. Unfortunately, however, Enforcer kept collapsing due to corrupt keys, and PoliVec could neither replicate nor solve the problem. We, too, are stumped.
PoliVec Security Policy Automation Suite, PoliVec, (866) 765-4832. www.polivec.com
|
 |
 |
|
|
|
 |
|