Computer Associates eTrust Policy Compliance 7.4
CA's eTrust Policy Compliance (EPC) is loaded with useful features and, function by function, competes right on with our top contenders. It's a good tool for monitoring and remediation--if you can afford it. We simply can't recommend it, though, at the price of $470,000 for 1,000 hosts. The bulk of the cost comes down to tiered pricing, where bottom-tier servers start at $2,000 per agent; even desktop licenses are high, at $200 a pop.
EPC's reporting and remediation offered no surprises and are on par with bv-Control and SecurityExpressions. We did run into an issue where the silent agent installer failed to authenticate to the management server. CA sent us an update to fix the problem. Once the agents were installed, we were in business. Building and running queries was a simple matter of following some wizards. Same with fixing config issues. Unfortunately, however, fixes can be applied only one at a time, so don't expect to make large-scale changes quickly. The reports are decent but don't provide the level of detail we found in its rivals.
EPC does offer a useful comparison feature for change notification. Once a target computer was configured, we saved a baseline snapshot of it locally. We could then scan the target at a later time and view any changes from the baseline. Likewise, a template system could be used to compare other systems; this would be a useful capability in a centrally managed desktop/server environment.