Compliance Automation
Tuesday, May 29th, 2007At the recent European ID conference Tim Cole from Kuppinger Cole gave a presentation detailing a consultative checklist to be used when procuring an automated compliance tool. Tim suggested a tool must meet the following criteria:
- Policy Based
- Process Driven
- Comprehensive
- Localised
- Dashboard View
- Ex-post Analysis (logs etc)
- Real Time
- Highly Reactive
- Actionable
- Tamper-proof
All really logical, the one checkpoint I do have an issue with is “comprehensive”. Can any tool be comprehensive when we look at compliance documents such as CoBIT or ISO 27001. I guess not, better wording may have been “fit for purpose”. At a vendor panel after Tim’s presentation we discussed Compliance Automation, as you would expect all the vendors agreed that no one solution would meet all compliance requirements, unfortunately there is not a black box that plugs into the network and makes it compliant (I doubt there are any combination of 5 tools that could do this). When we look at comprehensive in Tim’s checklist we need to bring it back a step and address controls or sets of controls, rather than the issue of compliancy as a whole.