ConsoleWorks is an extremely powerful framework for building a Sarbanes-Oxley (SOX) compliant business. ConsoleWorks' pro-active event monitoring and management solution not only provides alerts in real-time, but also supplies root-cause analysis of the events, which is critical to maintaining a reliable infrastructure. ConsoleWorks monitors all servers in an enterprise deployment including system disks, memories, storage, networks, internal and external interfaces and even applications.
TDI has put together an informative white paper on this subject entitled Using ConsoleWorks to Simplify Compliance with the Sarbanes-Oxley Act. Click here to request this document .
Many companies are in the process of their first annual audit with a SOX 404 attestation process. Due to its very nature, ConsoleWorks simplifies the monitoring and management of the control points needed for Section 404 compliance, assisting companies with managing the control points, and reporting on activities for these control points, and even automatically responding if it detects “unacceptable” activities happening on these control points.
ConsoleWorks offers all of these benefits providing the framework on which companies build an adaptable, sustainable solution necessary for long term SOX compliance:
- Security activity is logged. Everything ConsoleWorks sees coming from or going to managed systems and applications are logged. This includes activities involved done through it as would be the case when investigating a security incident.
- ConsoleWorks has thousands of events already defined and ready to use. Customers can easily define their own events, and any event that occurs is logged along with the activity surrounding each event.
- ConsoleWorks monitors and responds to events in real-time, so a security violation is reported immediately. It notifies appropriate support personnel or security personnel by any means that its host operating system allows. Such capabilities go a long ways towards satisfying Section 409 compliance.
- ConsoleWorks offers automated response to problems. It can initiate actions to remediate an event. Support personnel can do this independently or in conjunction with automatic actions.
- Users only have program access, not direct access, to the security logs.
- The ConsoleWorks administrator sets the retention duration for each console's logs.
- ConsoleWorks provides whatever notification actions a business deems necessary. Such actions can be the same for all events or can vary by individual event.
ConsoleWorks offers a significant first step towards compliance with new and evolving federal securities laws and related regulations. Manually watching all the control points and monitoring the associated activities in these areas is difficult at best. The work is monotonous and prone to human error, which makes ConsoleWorks the ideal solution.
Contact TDi to find out more about how ConsoleWorks can help simplify compliance with the Sarbanes-Oxley Act.
|