12.07.2015 Views

ArcSight Compliance Insight Package for IT

ArcSight Compliance Insight Package for IT

ArcSight Compliance Insight Package for IT

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Product Brief: <strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governance<strong>Compliance</strong>-Relevant LogReview <strong>for</strong> <strong>IT</strong> GovernanceHighlights:• Clarifies confusing compliance logreviews through a comprehensive,best practice approach• Alleviates time-consuming audittasks through automaticallygenerated compliance in<strong>for</strong>mation• Delivers all in<strong>for</strong>mation in thecurrent standards-basedISO-17799:2005 and NIST 800-53relevant <strong>for</strong>matThe <strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong>Governance quickly provides organizations thatare implementing an <strong>IT</strong> governance program witha comprehensive foundation <strong>for</strong> log review basedon best practices.Growing <strong>Compliance</strong> ComplexityThe increase in government regulation overthe confidentiality, integrity and availability ofsensitive in<strong>for</strong>mation has drastically affectedthe operating requirements of securitydepartments. These new requirementshave <strong>for</strong>ced security departments to spendan inordinate amount of time collecting,organizing, monitoring and reporting on eventlogs to detect and manage control-relatedactivity. It’s no surprise that companies acrossall industries are searching <strong>for</strong> technology toautomate this necessary but taxing process.Ease the <strong>Compliance</strong> Burden<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong><strong>for</strong> <strong>IT</strong> Governance is ideal <strong>for</strong> organizationsthat are implementing an <strong>IT</strong> governanceprogram, either independently or as thefoundation of their regulatory complianceinitiative. This easily customizable packagecontains a host of ready-to-use technicaland business-level checks in accordancewith the reporting structure <strong>for</strong> the ISO-17799:2005 and NIST 800-53 standards.<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong><strong>for</strong> <strong>IT</strong> Governance, combined with <strong>ArcSight</strong>ESM, provides companies and governmentorganizations with the ability to automaticallyidentify and assess the effectiveness ofinternal controls in an <strong>IT</strong> governance relevantcontext. Key to compliance adherence isensuring that controls <strong>for</strong> in<strong>for</strong>mation systemsare effectively implemented, monitored andmaintained. <strong>ArcSight</strong> ESM <strong>Compliance</strong><strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governance providesa comprehensive set of analytics, dashboardsand reports to provide an easily customizablelog review program based on the ISO-17799:2005 and NIST 800-53 frameworks.These two standards are recommendedby security experts as a firm basis <strong>for</strong>regulatory compliance initiatives and strong<strong>IT</strong> governance.


Product Brief: <strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong> GovernanceFormatsContentReportsDashboardsActive ListsReal-Time RulesFocusAssetRelevanceSarbanes-Oxley HIPAA GLBA FISMA PCI Basel IIAnalysisBusinessRelevanceISO-17799 Practices • Business Processes • Policy Monitoring • Risk ManagementTechnicalChecksNIST 800-53Standard• Logon/Logoff• Privilege Change• ConfigurationChanges• Attack Status• AdministrationActivity• TerminatedEmployees• Vulnerability• System ActivityData FeedsPrimaryControlsSecondaryControlsApplication Database OS IAM HIDS VAFirewall IDS/IPS Network Infrastructure<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governance MethodologyStrong Multi-Standards ApproachDesigned around best practices,<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong><strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governance leveragesthe NIST 800-53 (FIPS 200) standard toprovide a comprehensive system <strong>for</strong> theimplementation, assessment and monitoringof internal controls, including access controlchanges, administrative activity, log-inmonitoring, as well as change and riskmanagement. <strong>ArcSight</strong> ESM <strong>Compliance</strong><strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governanceautomatically maps these technical checksto the ISO-17799:2005 standard to placethem in policy and risk-relevant operationalcontext, allowing organizations to focus onkey services and business processes withinthe enterprise and address critical auditpoints. <strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong><strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governance brings thesetwo security standards together to deliverthe most relevant and comprehensive set ofcompliance content in the SIEM market today.Benefits of <strong>ArcSight</strong> ESM <strong>Compliance</strong><strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governance• Comprehensive Report Templates<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong><strong>for</strong> <strong>IT</strong> Governance provides over 85easily customizable reports, dashboards,correlation rules and data monitors tomeasure and report on the effectiveness ofcontrols through both technical checks andbusiness process activity review. Theseviews provide a real-time status of issuesagainst specific compliance requirements,as well as comprehensive reportingon historical data that can be used <strong>for</strong>benchmarking ef<strong>for</strong>ts.• Real-Time <strong>Compliance</strong> Oversight<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong><strong>Package</strong> <strong>for</strong> <strong>IT</strong> Governance offers realtimemonitoring, detection and reportingof compliance breaches, providing theability to proactively address complianceviolations be<strong>for</strong>e they are identifiedby auditors. Real-time reporting anddashboards provide application users andsecurity professional a means of assessingcompliance, as well as demonstrating tomanagement and auditors the organizationis effectively demonstrating complianceoversight.• Focused Tracking of AdministrativeActivity Effective Separation of DutiesA common audit point is the requirementto separately review administrativeactivity that relates to the access controls<strong>for</strong> regulated systems. <strong>ArcSight</strong> ESM<strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong>Governance automatically tracks alladministrative users and their activity viaunique active list functionality to easilyfulfill separation of duties requirements <strong>for</strong>security monitoring.• Real-Time Identification of<strong>Compliance</strong> Activity<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Package</strong><strong>for</strong> <strong>IT</strong> Governance is tuned to monitorcompliance activity in real-time and identifygaps in the compliance ef<strong>for</strong>t that presenta risk to the confidentiality, integrity andavailability of regulated in<strong>for</strong>mation, aswell as launch appropriate remediationactions to demonstrate full compliancemanagement.


Product Brief: <strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong> <strong>for</strong> <strong>IT</strong> GovernanceDesigned to Leverage <strong>ArcSight</strong> ESM<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Package</strong> <strong>for</strong><strong>IT</strong> Governance seamlessly installs andimmediately leverages <strong>ArcSight</strong> ESM – themarket-leading SIEM solution <strong>for</strong> enterprisethreat and risk management. The packagedelivers a strategic compliance solution thatallows organizations to implement compliancewhile vastly improving their overall securityprogram. <strong>ArcSight</strong> ESM provides thestrongest feature set to ensure that data isaccurately collected and efficiently stored, aswell as the strongest analytics capabilities toprovide immediate context to both securityevents and user activity. Customers canleverage the incredible flexibility of <strong>ArcSight</strong>ESM to easily focus compliance log reviewson their unique policies, procedures,infrastructure and audit points.<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong><strong>Package</strong> Family<strong>ArcSight</strong> ESM <strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong><strong>for</strong> <strong>IT</strong> Governance is part of the <strong>ArcSight</strong><strong>Compliance</strong> <strong>Insight</strong> <strong>Package</strong> family. Thissuite of content offerings delivers log reviewand security monitoring based on securityand audit best practices to help organizationsmeet regulatory compliance requirementsand institute a strong <strong>IT</strong> governance program.About <strong>ArcSight</strong>:<strong>ArcSight</strong>, an HP company, is a leading global provider of cybersecurity and compliancesolutions that protect organizations from enterprise threats and risks. Based on the marketleadingSIEM offering, the <strong>ArcSight</strong> Enterprise Threat and Risk Management (ETRM)plat<strong>for</strong>m enables businesses and government agencies to proactively safeguard digitalassets, comply with corporate and regulatory policy and control the internal and externalrisks associated with cybertheft, cyberfraud, cyberwarfare and cyberespionage. For morein<strong>for</strong>mation, visit www.arcsight.com.<strong>ArcSight</strong>, Inc.5 Results Way, Cupertino, CA 95014, USAwww.arcsight.com info@arcsight.comCorporate Headquarters: 1-888-415-ARSTEMEA Headquarters: +44 (0)844 745 2068Asia Pac Headquarters: +65 6248 4795© 2010 <strong>ArcSight</strong>, Inc. All rights reserved.<strong>ArcSight</strong> and the <strong>ArcSight</strong> logo are trademarksof <strong>ArcSight</strong>, Inc. All other product and companynames may be trademarks or registeredtrademarks of their respective owners.ARST-PB011-05212010-03

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!