|
Security Lifecycle Map™
ScriptLogic solutions provide IT organizations with unsurpassed Windows security management by offering solutions that
cover every aspect of security, as shown in the Security Lifecycle Map. The Security Lifecycle
Map demonstrates our comprehensive coverage of security management as a continually repeating lifecycle.
From folder shares and printers, to NTFS, to Group memberships, to delegation of Active Directory, the process of
securing Windows environments remains the same. Take a look and see how the Security Lifecycle Map
applies to all aspects of Windows security.
Assess, Assign, Audit...Repeat
Security can be boiled down to three simple tasks that make up the continual process of making Windows network secure.
Organizations first assess the current state of their security, looking for blatant breaches in security, validating
the existing security configuration or perhaps utilizing some best practice document or standard as a comparison. Once
an assessment is complete, the faults in the current security and changes to be made will be evident. So, an organization
will need to assign new security settings to fill in the holes found during the assessment. Once a new set of security
parameters are in place, the new security needs to be put to the test – thus an audit of the security is required.
This process will repeat itself continually – during the audit, more security breaches may be found so an assessment
of how those violations occurred will be needed, followed by a new assignment of security, and so on.
The next three parts of the Security Lifecycle Map are underlying characteristics that add validity,
credibility, and confidence to your security implementation. While these characteristics generally apply to the security
lifecycle, in some cases, you may not find a direct application to a specific Windows technology.
Availability
It is of no use to implement security if you cannot be certain it is in place, ready to enforce your organizations
policies. Availability refers to the power of an organization to quickly restore security to its former state should
the security be inappropriately changed or even lost due to a failed system.
Accountability
In many organizations, security cannot and should not be left to a single individual. Accountability refers to an
organization putting a change management process in place to ensure the changes one individual wants to make are
appropriate, have been validated, and will not have adverse effects when implemented. It also means that one
individual is accountable to another before changes can be made.
Assurance
Security is useless if an outside force can infiltrate by unsuspecting means and gain administrative access, as
in the case of Spyware and viruses today. Assurance refers to protecting your organization from outside influence
by defending against known vulnerabilities via patch management, anti-spyware and anti-virus measures.
The Security Lifecycle Map demonstrates ScriptLogic's dedication to ensuring a secure Windows
environment utilizing a continual process of assessing, assigning and auditing the security controls in place, with
the appropriate characteristics providing validity, credibility, and confidence to the process. Look for the Security
Lifecycle Map when evaluating ScriptLogic solutions to see where each product fits into the lifecycle.
|