eGestalt intros SecureGRC

author-image
DQChannels Bureau
New Update

href="http://www.ciol.com/SMB/SMB/News-Reports/eGestalt-offers-GRC-on-cloud-for-US-SMBs/137446/0/">SecureGRC
is a cloud-based integrated
IT security and GRC solution. It is a SaaS-based model and is not
directly given to customers. The vendor works through managed SPs who
implement the application. This is especially important for smaller
companies that do not necessarily have GRC expertise in-house. It is
priced at Rs 65,961. It reduces the time for deployment.

Advertisment

Recently, Government and industry
regulations have put pressure on organizations to increase governance
over their IT systems, and in particular over data security and
privacy. These regulations include the Basel II Accord, the Health
Insurance Portability and Accountability Act (HIPAA), the
Sarbanes-Oxley Act of 2002 (SOX), the Gramm-Leach-Bliley Act (GLBA)
and California Senate Bill 1386. Non-compliance with an applicable
regulation can lead to serious penalties for a business, regardless
of its size. Even a small retail store faces stiff fines if it's
found to be non-compliant with the Payment Card Industry (PCI) data
security guidelines.

Noticing an opportunity, many SPs have
responded with applications that are designed to automate the complex
process of discovering, monitoring and reporting on a company's GRC
posture. Most of these solutions have been aimed at medium-to-large
enterprises that have extensive IT environments controlling complex
business processes. Implementations and ongoing usage of GRC
automation tools is time-consuming and expensive. This discourages
smaller, resource-strapped companies for GRC automation.

eGestalt's SaaS model is unique among
GRC vendors. Robert Klotz, Akibia's VP, Technology, said “We have
chosen href="http://dqchannels.ciol.com/content/reselleralert/110030206.asp">eGestalt
SecureGRC because of the product's functionality,
ease of use and low cost. SecureGRC's timely collection of data helps
us to demonstrate to our clients their current compliance profile and
compliance issues in a manner that allows them to better understand
what controls need to be implemented to assure compliance with their
specific policy and regulatory requirements.” Klotz further adds,
“SecureGRC is a full featured, cost friendly solution that is
adaptive, flexible and easy to use. He says it's a particularly good
fit for the companies that Akibia serves.”

Advertisment

SecureGRC automates the point solutions
of policy management, control assessment, data discovery, security
monitoring, net-forensics and threat assessments and integrates them
with a work flow engine for timely alerting/reporting of an
organization's current compliance state.

The major functions of eGestalt are:

Asset and Vulnerability Management

It is an integrated functionality to
manage the processes, data and tasks associated with assets and their
related vulnerabilities. Asset management involves discovering,
identifying and classifying assets such as servers, desktops,
laptops, firewalls. Vulnerability management consists of the ability
to discover the vulnerabilities associated with assets and providing
the data and insight that is necessary to manage them through the use
of direct fixes or the application of compensating controls.

Data Discovery

It is a comprehensive scanner that
searches for credit card data and other confidential data formats
specified by the customer. The scanner works on in-house data stores,
commercial and open source databases.

Advertisment
  • Compliance Scanning: Allows
    auditors, consultants and the internal security/compliance teams to
    streamline and automate the process of evaluating PCI compliance during
    their engagements. The compliance scanner accepts results from leading
    vulnerability and application scanning tools. It has built-in
    cardholder data search features (data discovery) for processing.

  • Compliance Logging: Gather system
    logs for integration and analysis in the overall compliance framework.

Manager

It provides an integrated solution for
managing the functions, documents and tasks that are associated with
audits of an organization.