Welcome to TDI
overview
features
requirements
purchasing
support
 
it security alerts
white papers
news & resources
events
support services
contact us


Problem:

Organizations today, whether public, private or governmental, are charged with complying with a myriad of regulations, standards and laws. Failure to comply can result in something as simple as a virus infecting a single PC or something as serious as large fines from the SEC, FERC or some other regulatory body. These failures may even halt or destroy your business. No one product can deal with all the compliance requirements and no one department in an organization has responsibility for implementing solutions for all the compliance pieces. In addition, when regulatory events occur, the traditional compliance solutions do not specify the violated regulations, thus making it difficult to evaluate risk and provide meaningful compliance audit reporting.

Effects of Problem:

Auditors, compliance officers, IT departments, CIO’s, CFO’s, CEO’s and many others each have different requirements with relation to compliance. They all try to implement that one sentence or one paragraph out of that one regulation that matters to them, rather than taking a holistic approach. The result is multiple overlapping and duplicative solutions that often don’t really satisfy the needs of the auditors and don’t offer sufficient flexibility to allow for integration with other solutions. Monitoring data is often easy to modify after it is collected, making it an unreliable source of compliance information. Integration with other solutions or moving data to a common data repository is difficult.

Compliance reports are often generated by hand using various potentially unreliable sources, resulting in reports which are inconsistent from event to event or report to report. Automated reporting that easily relates a monitored item to a specific regulation, standard or law is seldom available. As the data center experiences compliance issues, personnel are seldom in a position to understand the impact on compliance, even if such impact is high risk in nature.

The Ideal Solution:

In an ideal world, monitoring solutions would automatically relate events to compliance issues. Tampering with monitoring data would be difficult and easy to detect. If there is a central repository of compliance data, it would be simple to move that data to the repository making integration with other compliance tools easy. Reporting would provide both the event and the appropriate section(s) of the law, standard or regulation.

TDI Solution:

ConsoleWorks provides a real time view of compliance risk. It can instantly associate a specific sentence or paragraph from a law, regulation or standard with an event. ConsoleWorks integrates with other compliance solutions quickly and easily. Reporting on compliance events is equally easy with the additional capability of reporting by paragraph number rather than just by event. Digitally signed log files insure the detection of monitoring data modification, making auditors happy.

ConsoleWorks provides the following:

Event Monitoring Event Management Compliance
  • Monitoring 24X7
  • Aggregated event monitoring from the entire enterprise
  • Real-time notification of events
  • Real -time logging of events
  • Goes a step beyond SNMP monitoring tools like HP OpenView, Tivoli, BMC Patrol to event management
  • (CIP 002-009, Sarbanes-Oxley, SAS 70, GLB, HIPAA and others)
  • Monitor and manage critical compliance events in addition to operations events
  • Real-time business intelligence surrounding compliance events
  • Understand the business intelligence of when an event occurred, where it occurred, who managed the event, and how the event was managed