Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Security
R E V I E W  
Policy Enforcers

  May 29, 2003
  By Mike Fratto


>> continued from previous page

NetIQ VigilEnt Security Manager 4.0
TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
BindView Development Corp. bv-Control 7.2 and Policy Operations Center 4.2
arrow
Configuresoft Enterprise Configuration Manager 4.0 with Security Update Manager 2.0
arrow
Pedestal Software SecurityExpressions 3.0
arrow
Symantec Enterprise Security Manager 5.5
arrow
PoliVec Security Policy Automation Suite (Builder 2.6, Scanner 3.5, Enforcer 1.1)
arrow
NetIQ VigilEnt Security Manager 4.0
arrow
Computer Associates eTrust Policy Compliance 7.4
arrow
How We Tested
arrow
Report Card

VigilEnt Security Manager (VSM) is a mixed bag of good and lame features at an expensive price. As with CA's product, the cost bump is in the server space. VigilEnt Policy Manager (VPM) is similar to PoliVec Builder in that policies can be developed and used as templates against target computers. Although VSM requires agents on target systems, proxy agents can scan up to a recommended maximum of 50 targets. Each target still uses a license, but you save the problem of deploying agents everywhere. Agents can be installed remotely; however, we ran into weird problems--the agents would install and run and then the service would shut down and issue a Dr Watson. Neither we nor NetIQ could determine the cause.

Reports are detailed, and we found customizing existing reports and creating new ones no more or less difficult than with other products we tested. We did, however, have difficulties limiting the data that was returned. For example, we wanted a report that listed only accounts that could act as part of the OS, but no dice. Could we do this with the products from Computer Associates and Configuresoft? Why, yes, we could. Applying a filter to a report isn't the same as generating the desired report automatically.

We build ad hoc queries, and VSM made interactive queries easy to make by letting us define a variable name for a parameter. The value is requested at run time. For example, we created a query that showed all the owners of files within a file system. Then we specified the directory that should be used as the search root. As for remediation, VSM was one of the weakest products we tested--it could manipulate only user objects.


NetIQ VigilEnt Security Manager 4.0, NetIQ Corp., (888) 323-6768, (408) 856-3000. www.netiq.com


start top  PoliVec Security Policy Automation Suite (Builder 2.6, Scanner 3.5, Enforcer 1.1) Computer Associates eTrust Policy Compliance 7.4  

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers