Consul
Compliance Management Modules
Enabling corporate governance and regulatory compliance.
From the boardroom to information technology departments, rules and regulations are placing ever-increasing demands on companies of all sizes. In the middle are IT security managers and auditors who face the overwhelming task of understanding the regulations and implementing a wide array of compliance measures.
Regulations underscore the need to understand who’s touching your most crucial corporate data, and whether this behavior complies with your security policy. This is where Consul InSight comes in – enabling organisations to monitor all security events and audit them versus security policy.
Consul was the first event management vendor to introduce:
Each add-on module comes complete with a regulatory and/or standard specific:
- Compliance Dashboard
- Report Center
- Policy Template
- Classification Template
- Resource Center
Each Compliance Management Module (for Sarbanes-Oxley, ISO17799 and GLBA) is an optional plug-in to Consul InSight 5.0. Each module comes equipped with the following features customized for either Sarbanes-Oxley, ISO17799 or GLBA:
- A Compliance Dashboard: displays an easy-to-understand, color-coded matrix highlighting degrees and level of compliance based on user behavior and data access. The dashboard is customized for the specific regulation/standard of interest depending on the module you choose.
- A Report Center: provides dozens of relevant reports linked to the ISO17799 standard or FFIEC handbook (for GLBA), for monitoring compliance to the regulation or standard, and understanding who touched what across your network.
- A Policy Template: recommends a customizable policy for who should be allowed to access regulated information, and what they can do with it. Leveraging Consul’s patent-pending W7 Methodology, the Policy Template provides an easy, enforceable manner to establish and monitor file access versus policy.
- A Classification Template: enables quick classification of your enterprise to allow for role-based security auditing of your enterprise versus policy. Each classification template speaks the language of a regulation or standard to allow you to demonstrate compliance.
- A Resource Center: includes information on the Act and guidelines on how to use Consul InSight 5.0 for compliance, including specific advice on how to adjust the logging and audit settings in your enterprise to enable proper access monitoring.