Home > Midmarket CIO Tips > Security for the midmarket > Security configuration management: Advanced patching
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Security configuration management: Advanced patching


Mike Rothman, Contributor
05.31.2007
Rating: -2.50- (out of 5)


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


For many small and medium-sized businesses (SMBs), security means putting a firewall in place and doing the requisite patching required every month after Microsoft's "Patch Tuesday." There are many tools that can automate and manage the patching process, but the tools are not enough.

Keeping an endpoint secure involves more than making sure it is adequately patched. IT professionals at SMBs also need to make sure the data on the device is protected and adheres to the organization's policies relative to authorized applications. For instance, you may want to turn off Skype or not allow users to use Web mail at work or during certain times.

More on patching
Firm eases pain of patch management for mobile workers

Seven steps for a patch management process: Check IT List
First-generation patching products didn't give the level of granularity needed to enforce these policies. They were all about scanning a machine, making sure the latest patches were applied and moving on. A new offering called security configuration management (SCM) is maturing quickly and can address many of these issues.

SCM products manage the lifecycle of the desktop and integrate a lot of traditional desktop management functions, like software distribution, patching and asset management.

There will be more functionality making it into the SCM agent. Antivirus and antispyware functions are obvious additions to provide more leverage and ease the burden of managing all of the disparate agents running on the typical device.

Ultimately, you are trying to both increase the security of your environment and streamline the management. Sounds like having your cake and eating it too? It is, and for that privilege you will pay -- probably through the nose. But as the markets mature, prices will come down, as they always do.

So who are some of the players in this market? Per usual, you have the specialists and the aggregators, who have bought their way into the market. The specialists include BigFix Inc., Configuresoft Inc., Shavlik Technologies LLC and PatchLink Corp. Some started with patching and have grown capabilities, while others started from the standpoint of systems management and sort of ended up doing security. No matter, these companies will be rolled up sooner, rather than later, as Big IT (Microsoft, Hewlett-Packard Co., IBM, CA) realizes it's sick of giving money to Big Security (Symantec Corp. and McAfee Inc.).

Speaking of Big Security, both of the antivirus leaders have bought companies to get exposure to security configuration management. Symantec has had a number of products that solved a portion of problems (Enterprise Security Manager and BindView) and recently bought Altiris Inc. to get a broader, more robust endpoint management capability. McAfee bought Citadel Security Systems Inc. and Preventsys to integrate their capabilities into its Total Protection suite.

Of course, you know what they say about acquired technology. Unless it's actually integrated, it's not really that useful. So we are going to continue to see a lot of evolution and integration relative to endpoint security. It's ridiculous that you need eight to 10 agents to get the job done, so consolidating these capabilities is a must, and it's happening -- slowly, but surely. To net things out, security configuration management is yet another feature of a strong endpoint security platform.

Mike Rothman is president and principal analyst of Security Incite, an industry analyst firm in Atlanta, and the author of The Pragmatic CSO: 12 Steps to Being a Security Master. Get more information about The Pragmatic CSO at http://www.pragmaticcso.com, read his blog at http://blog.securityincite.com, or reach him via email at mike.rothman (at) securityincite (dot) com.


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Information security management for the midmarket
Droid does, but will IT support it?
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
Information technology management e-book downloads for midmarket CIOs
10 must-have steps for an effective SMB information security program
Your IT security budget: How to get more bang for the buck
Using key risk indicators to sell your information security program
IT security spending a bright spot in '09, with more growth predicted

Risk management for the midmarket
Information security program revamp adds outsourcer oversight and more
From data breaches to risk management frameworks: Test your knowledge
Adopting a beta tool: Risks vs. rewards for a midsized enterprise
The challenge of managing risk when IT budgets tighten
Why cybersecurity awareness is everyone's responsibility
How to decide if changing technology vendors is worth the time, risk
A guide to managing the risk assessment process
Free risk management tools and resources for the enterprise
CIOs taking risk of cutting vendor maintenance contracts to save money
10 must-have steps for an effective SMB information security program

Security tools for the midmarket
Why CIOs need to get real about identity and access management in 2010
Free risk management tools and resources for the enterprise
IT security spending a bright spot in '09, with more growth predicted
Security and risk management in the midmarket
Identity and access management planning guide for the midmarket
A CIO's advice for implementing single sign-on solutions
Options for outsourcing security grow, offer IT budget savings
Network access control: Pointers for getting the knack of NAC
Unified communications: Securing access to OCS
Unified communications security: How safe is it?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts