Tripwire predicts end to onerous audits

Change management software specialist claims new suite offers "continuous compliance"

Written by James Murray

Tripwire has predicted that compliance audits could become less onerous and even less frequent following today’s unveiling of the latest version of its change management software suite.

The company said that the new Enterprise 7 suite will be available from next month. It features enhanced functionality capable of providing firms with real-time data on the configuration and compliance status of their IT systems that will allow them to attain " continuous compliance" with internal and external policies and regulations.

Advertisement

Paul Gostick, marketing manager for Europe at the company, said that the integration of Tripwire's existing change management capabilities with new configuration assessment functionality – capable of monitoring a firm's IT systems against a compliant "baseline" state – means the suite can inform managers in real-time if their systems are compliant and whether or not an IT change would lead to a policy breach.

"What this functionality gives you is information that allows you to achieve continuous compliance," Gostick said. "The problem with the current audit-based approach to compliance with regulations such as PCI [payment card industry security standard] and SOX [Sarbanes-Oxley] is that it is matter of fact and after the event. Continuous compliance information helps you to prevent compliance breaches in the first place and avoid what has become known as the ‘TK Maxx incident’."

As well as reducing the risk of compliance and data breaches, Gostick argued that automated compliance management suites, such as Tripwire's, can also reduce the cost and frequency of both external and internal IT audits.

"In reality, governance practices mean that third-party audits will have to continue," Gostick admitted. "But what these systems do mean is that audits be co me far simpler because you have an automated audit trail, which means the cost will go down. Over time, as this technology is more widely deployed, we could see fewer audits being required."

Industry experts agreed that automated change and IT management systems are becoming an essential element of large firms' compliance strategies. Kosten Metreweli, vice-president of marketing and alliances at datacentre management software specialist Tideway Systems, agreed that compliance audits could soon be impossible without automated system monitoring and management capabilities. "We are approaching a point where compliance is so complicated it cannot be attained without a degree of automation," he said. "The manual cost of audits is getting prohibitive and, indeed, the scale of IT infrastructures means it is starting to become impossible to undertake accurate audits manually."

Blair Kantolinna, business development manager for Europe at IT management software vendor BMC, added that management software solutions had now matured to a stage where such automation was relatively easy to deploy.

"It used to be possible [to automate much of your IT compliance], but it required a massive integration effort between the component level management systems and the high-end process management systems," he explained. "What has changed in the last three years is that there is a far greater level of integration between the different parts of the management stack, which enables automation out the box."

However, Struan Robertson of law firm Pinsent Masons argued that although automated change management systems have a useful role to play in enhancing firms' compliance processes – reducing the risk of legal breaches and speeding up compliance audits – it is wrong for firms to see them as a "silver bullet", and argued that they are unlikely to limit the frequency of audits.

"Compliance isn't always a binary test, and software will struggle with leg al nuances," Robertson said. "For example, software can aid compliance by stopping someone installing software on an office computer, or it can determine whether a financial report has been filed on time. But it's less effective at determining whether a company complies with data protection rules on the collection and transfer of personal information, or FSA rules on anti-money laundering procedures."

Gostick admitted that while Tripwire's suite would help firms monitor whether or not they are compliant, it could not make them compliant and, as a result, firms deploying the system may also have to undertake process changes to attain regulatory compliance.

In addition to the new compliance monitoring capabilities, Tripwire Enterprise 7 also features enhanced network management functionality that can automatically "roll back" unauthorised changes at the network device level.

Gostick added that integration with IT management software from vendors including BMC, IBM and HP means that users can also use the new suite to help reverse unauthorised changes to applications and systems higher up the IT stack.

The vendor also announced plans to extend its support for configuration management databases (CMDBs), including tighter integration, due in a few months, between Tripwire's technology and BMC Atrium 2.0 CMDB, HP Universal CMDB and CA CMDB.

"The current prediction from Gartner is that 70 percent of CMDB deployments will fail because of problems with the integrity of the data kept in the repository, " said Gostick. "Integrating the CMDB with our ability to monitor system changes against a compliance baseline means firms will be able to ensure the integrity of the information."

Tags:

Related articles

Related whitepapers

Related jobs

Do you agree?

IT white papers

Search vnunet IThound

Top categories

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Watch

Shaun Nichols and Iain Thomson

10 Oct 2008

7.33 MBPodcast Special: Views from the Valley More...

Podcast image

09 Oct 2008

12.99 MBComputing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security More...

Shaun Nichols and Iain Thomson

03 Oct 2008

6.49 MBPodcast Special: Views from the Valley More...

Poll

Google Android

Google Android

Are you intending to try out a Google Android mobile phone?

Previous poll results

Spotlight

MoD building

Latest data breach leads MPs to demand culture change

MoD admits to losing a hard drive containing up to...  More...

Online shopping

E-retailers urged to prepare for Christmas

Credit crunch sending shoppers online for cheaper presents   More...

Mobile phone

Emerging markets drive mobile growth

Mobile penetration rates expected to reach 95 per cent by...  More...

Digital information

Poor data classification costing companies dear

Millions wasted on searching through clutter, says analyst   More...

Primary Navigation