Upcoming Events

Cloud Connect
Santa Clara
Feb 13-16, 2012

Cloud Connect brings together the entire cloud eco-system to better understand the transformation we're experiencing and promises to be the defining event of the cloud computing industry. Learn about the latest cloud technologies and platforms from thought leaders in Cloud Connect’s comprehensive conference.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up
Security
R E V I E W  
Policy Enforcers

  May 29, 2003
  By Mike Fratto


>> continued from previous page

Computer Associates eTrust Policy Compliance 7.4
TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
Discuss Discuss this article
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
BindView Development Corp. bv-Control 7.2 and Policy Operations Center 4.2
arrow
Configuresoft Enterprise Configuration Manager 4.0 with Security Update Manager 2.0
arrow
Pedestal Software SecurityExpressions 3.0
arrow
Symantec Enterprise Security Manager 5.5
arrow
PoliVec Security Policy Automation Suite (Builder 2.6, Scanner 3.5, Enforcer 1.1)
arrow
NetIQ VigilEnt Security Manager 4.0
arrow
Computer Associates eTrust Policy Compliance 7.4
arrow
How We Tested
arrow
Report Card

CA's eTrust Policy Compliance (EPC) is loaded with useful features and, function by function, competes right on with our top contenders. It's a good tool for monitoring and remediation--if you can afford it. We simply can't recommend it, though, at the price of $470,000 for 1,000 hosts. The bulk of the cost comes down to tiered pricing, where bottom-tier servers start at $2,000 per agent; even desktop licenses are high, at $200 a pop.

EPC's reporting and remediation offered no surprises and are on par with bv-Control and SecurityExpressions. We did run into an issue where the silent agent installer failed to authenticate to the management server. CA sent us an update to fix the problem. Once the agents were installed, we were in business. Building and running queries was a simple matter of following some wizards. Same with fixing config issues. Unfortunately, however, fixes can be applied only one at a time, so don't expect to make large-scale changes quickly. The reports are decent but don't provide the level of detail we found in its rivals.

EPC does offer a useful comparison feature for change notification. Once a target computer was configured, we saved a baseline snapshot of it locally. We could then scan the target at a later time and view any changes from the baseline. Likewise, a template system could be used to compare other systems; this would be a useful capability in a centrally managed desktop/server environment.


eTrust Policy Compliance 7.4, Computer Associates International, (800) 225-5224. www.ca.com

Mike Fratto is a senior technology editor based in Network Computing's Syracuse University Real-World Labs®; he covers all security-related topics. Prior to joining this magazine, Mike worked as an independent consultant in central New York. Write to him at mfratto@nwc.com.

Post a comment or question on this story.


start top  NetIQ VigilEnt Security Manager 4.0 How We Tested 

Research and Reports

Hypervisor Derby
August 2011

Network Computing: August 2011

TechWeb Careers