Blog|Login|Chinese German Japanese|Follow @imperva
September 25, 2009
 SecureSphere's Approach to Audit & Compliance - Enter COBIT

SecureSphere report

Following a question from a prospect, I thought that it would be useful to provide some insight into  our approach for audit and compliance. 


"SecureSphere addresses different business requirements based on its ability to secure and monitor transactions from the end user through the Web application to the database. SecureSphere offers complete data security and visibility: SecureSphere can identify the unique application users that performed database queries—even in multi-tier environments. This Universal User Tracking capability provides user accountability to database audit trails and compliance reports".


Different compliance regulations require monitoring of users and/or privileged users and administrators: understanding how they behave, what they do, what kind of data they were accessing and what actually was reviewed.  

In order to address the many compliance requirements, SecureSphere is using the COBIT framework for reporting:

The Control Objectives for Information and related Technology (COBIT) is a set of best practices (framework) for information technology (IT) management created by the Information Systems Audit and Control Association (ISACA), and the IT Governance Institute (ITGI) in 1996. COBIT provides managers, auditors, and IT users with a set of generally accepted measures, indicators, processes and best practices to assist them in maximizing the benefits derived through the use of information technology and developing appropriate IT governance and control in a company. (source: wiki)


Using a single, well-known industry standard as a framework provide multiple benefits:
  1. Organizations can easily integrate SecureSphere into their existing audit and compliance projects using consistent reporting.
  2. SecureSphere administrator can add additional reports based on business requirements (even though SecureSphere ships with a library of several hundred reports...).   
  3. Adding out-of-the-box support for additional compliance mandates is  straightforward.  
And above all, ISACA is doing an excellent job in training so ensuring that SecureSphere is using a well defined and well known framework is also essential for establishing it as a standard tool for data activity monitoring, data security and compliance. 

Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« Insider Threat White Paper: The Anatomy of an Insider - Bad Guys Don't Always Wear Black | Main | Data Security for Critical Infrastructure »