Navigation - HOME
Navigation - PRODUCTS
Navigation - SOLUTIONS
Navigation - CUSTOMERS
Navigation - STRATEGIC ALLIANCES
Navigation - SUPPORT
Navigation - NEWS & EVENTS
Navigation - COMPANY

Microsoft and Brabeion

Microsoft Configuration Manager with Brabeion's IT Governance, Risk and Compliance Solutions
IT Governance, Risk and Compliance Program Management and Analysis

Microsoft and Brabeion Software, leader in IT GRC solutions, have partnered to provide Microsoft customers the ability to pinpoint both where and how they are in or out of compliance with major regulations and IT control frameworks.

Brabeion's rich risk and compliance content, includes recommended baseline technical controls for the most popular Microsoft enterprise products, leveraged within Microsoft System Center Configuration Manager 2007 to provide continuous controls monitoring for key regulatory requirements, including Section 404 of the Sarbanes-Oxley Act using COBIT 4.0, European Union Data Protection Directive (EUDPD), Gramm Leach Bliley Act (GLBA), the Federal Information Security Management Act (FISMA) and Health Insurance Portability and Accountability Act (HIPAA).

The Governance, Risk and Compliance Challenge for IT

What is IT Governance, Risk and Compliance?
IT organizations are called upon nearly every day to demonstrate to auditors, partners, executives, customers and employees that their IT governance, risk, compliance and security programs are protecting brand, reputation and shareholder value from theft disruption and violations.

IT Governance programs focus on ensuring that risks are managed appropriately and resources managed responsibly, while aligned with strategic and tactical imperatives of the organization.

Compliance programs focus on the effectiveness and relevance of IT controls put in place to meet legislative imperatives and company policies, and the risk associated with their failure.

Risk and Security Management programs focus on the reduction of risk and protection of critical assets from threats that could create breaches in confidentiality, integrity or availability.

However all of these programs can be compromised by insufficient controls, inefficient process, and inadequate metrics exposing companies to damage and loss of critical assets - whether they be people, processes, digital or physical assets.

Microsoft's Configuration Manager, powered by Brabeion's rich risk and compliance content, eliminate these exposures ensuring governance, risk, compliance and security programs meet the requirements of business managers, auditors, partners and regulators.

For the first time it's easy to know answers to questions such as:
  • Are my Exchange and Windows Domain Controllers in compliance with SOX and FISMA regulations?
  • Which Exchange servers are not SOX compliant?
  • What SQL servers need to be remediated?
  • Who changed the configuration on the server?
  • When was the server configuration changed?
  • How do we meet the challenge together?
    There are three ways for Microsoft customers to leverage Brabeion's IT GRC solutions. Use Microsoft's Configuration Manager, out of the box, to get reports on actual baseline results, and know where and how configurations are mapped to primary regulations.

    Microsoft's Configuration Manager reporting dashboard demonstrates the servers which do not meet the regulation requirements.


    Use Microsoft Configuration Manager with Brabeion's Polaris Pathfinder to collaboratively design, review, publish and track all IT policies, procedures and controls — mapped to regulations and frameworks.

    Adding Brabeion's Polaris Pathfinder provides customers with closed loop policy, procedure and controls life cycle management, supported by a web-based awareness portal for policy enforcement and tracking.

    Use Microsoft Configuration Manager with Brabeion's Polaris Navigator to eliminate critical exposures in governance, compliance and security programs with role-based dashboards, continuous risk and compliance assessments, risk scores on assets, and comprehensive reporting.

    Adding Brabeion's Polaris Navigator allows customers to compare stated policies and controls from Brabeion Polaris Pathfinder with the current status of your IT environment, including all Microsoft configurations, in order to identify and prioritize remediation requirements to ensure regulatory compliance.


    Key Features Customer Value

    Configuration Manager 2007

    • Configuration Manager Asset Intelligence provides enhanced infrastructure insight and control of IT systems
    • Utilize Configuration Manager and third party Configuration Packs to define best practices, help avoid common configuration errors, and help manage systems in the context of regulatory requirements such as Sarbanes-Oxley and HIPPA
    Utilize Microsoft and Brabeion best practice configuration knowledge to
    • Improve configuration definition and maintenance
    • Help ensure systems comply with a defined desired state
    • Enhance availability, security features and performance while streamlining your systems compliance efforts.

    Configuration Manager 2007 with Brabeion's Polaris Pathfinder

    • Complete closed-loop policy, procedure, standard and control lifecycle management
    • Authoritative Knowledgebase of over 6000 IT controls linking 600 policy standards to regulations such as SOX, HIPAA, FISMA, GLBA, PCI, and frameworks such as COBIT, ISO17799 and NIST 800-53.
    • Quarterly content updates by experts including PwC and the IT Governance Institute.
    • Implementation Guidance & Audit Work Program
    • Dramatically raise risk and compliance visibility
    • Quantify and qualify the state of compliance
    • Decrease risk, improve analysis, remediation and decision-making
    • Increase efficiency of root cause analysis
    • Customize risk and control calculations with a flexible framework

    Configuration Manager 2007 with Brabeion's Polaris Pathfinder, Polaris Navigator and Polaris Surveyor

    • IT GRC Dashboard and Reporting with risk and compliance scores, viewed by regulation, policy and framework, by role based on your actual polices and configuration data
    • Automated, Continuous Risk and Compliance Audits and Assessments
    • Automated testing through adaptors that integrates with Microsoft, Symantec, NetiQ and other IT configuration monitoring and management systems covering over 90 technologies
    • Role-based workflow for work assignment, with review, escalation and status
    • Multi-tiered People Process and Asset Repositories
    • Customizable multi-tiered hierarchy by such classifications as geography, organization unit, business process, application, technology, criticality, legislation, framework
    • Reduce cycle time and redundancy
    • Improve efficiencies and access
    • Facilitate reuse of test results across multiple audits
    • Facilitate views from multiple perspectives
    • Analyze data by any element
    • Demonstrate value and return on investment in days, not years
    • Enhance and formalize audit, risk and compliance programs
    • Strengthen relevance of control design and adherence to policies


    Implements Quickly and Easily
    • Built on common System Center standards such as Service Manager Language (SML) that enable standardization and reuse of your operational knowledge.
    • Configuration Items, settings/objects, and rules all include user-friendly names and descriptions, providing meaningful context to the administrator along with information to help them bring a system back into compliance
    • Import data assets and controls, LDAP, CMDB data automatically
    • Intuitive user interface, customizable for corporate branding and intranet integration, promotes productivity
    • SQL database support eases implementation
    • Adapters to leading assessment, configuration and change management technologies facilitate automation
    • Web-based design requires no client software
    • Microsoft technology: .Net, supports leading enterprise standards
    What Microsoft technologies are covered?
    • Windows Client Operating Systems
      • Windows XP
      • Windows 2000
      • Windows Vista
    • Windows Server Operating Systems
      • Windows Server 2000 Member Server
      • Windows Server 2000 Domain Controllers
      • Windows Server 2003 Member Server
      • Windows Server 2003 Domain Controllers
    • SQL Server 2000 with the most recent Service Pack
    • SQL Server 2005 with the most recent Service Pack
    • IIS 6.0 with the most recent Service Pack
    • Exchange 2003 with the most recent Service Pack
       
    Sidebar: Webcasts

    Brabeion and PricewaterhouseCoopers:
    Overcoming PCI Challenges

    Is your organization struggling to meet PCI requirements and deadlines? Is the fear of potential fines making it difficult to run and maintain a successful program?

    View Recorded Webcast »


    Brabeion and Forrester Research:
    Critical Steps to Automating your IT GRC Programs

    The crucial need to effectively manage and mitigate increasing IT risks - coupled with the rise in government-mandated and industry-specific regulations, demand that organizations unify their governance, security, risk and compliance silos to provide a holistic view of the IT environment.

    View Recorded Webcast »


    OCEG and Brabeion Webinar:
    Controls Based Risk Management:
    From Auditable Policy to Understanding Risk

    A unique approach for risk calculation utilizing a "component-based" method leveraging three pieces of information - Requirement, Standard and Control. Get a new understanding of risks from a compliance and controls perspective, enabling fuller visibility into business impacts and decision making.

    View Recorded Webcast »


    Rolling with the Changes:
    Managing Compliance in a Continuously Evolving Industry

    Financial Services companies face many obstacles due to the regulations and requirements they have to face. Learn how leading commercial and consumer finance company, CIT, has evolved their compliance programs.

    View Recorded Webcast »


    Brabeion in Enterprise:

    Featuring: Chevron-Texaco, Brabeion, and Forrester Research analyst Michael Rasmussen. Learn how to efficiently and effectively identify controls to achieve compliance with GLBA, PCI, FFIEC, SOX and HIPAA.

    View Recorded Webcast »