Zur Startseite

Rule Type


The central rule type has all the limiting and threshold values stored in it for analyzing the security status of the computer systems on the Security Information Map.

The rules can be applied to all security areas, such as virus protection, updates/patches, vulnerabilities, or protection status.

The policies defined at the company are transformed into clear rules to this end. These rules define precisely when the network fulfills the requisite security level and is protected sufficiently. In doing so, the security management team define the requirements for a compliant network status from the very beginning.

One requirement could be that a system in the "Virus Protection" area only counts as being compliant if it receives the current pattern/signature available every 240 minutes. Hence, the condition for distributing virus signatures is as follows: an online computer system is not allowed to be behind target for a pattern/signature by more than 240 minutes.

The rule type already has standard rules defined within the scope of delivery for the product. User-defined rules can also be created that relate, for instance, to certain locations or protection classes.

The standard rule is defined as follows: if at least 80% of the computer systems fulfill the previously defined condition, the region is displayed in green. In this case, it means that at least 80% of the systems have received the current pattern/signature.
If 60% - 80% of the computers show that they have received the current pattern/signature, the region is displayed in yellow. If the number of systems is under 60%, the region is shown in red.

However, if individual locations or critical computer systems need to be equipped with individual rules, these can be added to the standard ones. For instance, when monitoring systems that have been assigned the protection category "Very High" via the policy, the additional rule defines that at least 96% of highly critical systems need to have the current pattern showing up in green on the Security Information Map.



Quality by AMPEG

Security Level

"Initially, it was more important for us to establish a uniform standard in the global environment at the locations from the outset, than work on maintaining specific limiting and threshold values. At the end of the day, a chain is only as strong as its weakest link. We now have a standard infrastructure in place across the group, which should make it possible to maintain security at a high level everywhere."

 

CSO of a company with 40,000 PCs at 70 locations worldwide.






© 2011 AMPEG GmbH. All rights reserved.