Configuration Management, Design, and Remediation PRACTICE CONSULTANTS EXPERTS PROFESSIONALS

IT security and IT operations meet at Security Configuration Management (SCM) because this foundational control blends together key practices, such as vulnerability assessment, automated remediation and configuration assessment. Organizations can, therefore, leverage a software-based SCM solution to reduce their attack surfaces by proactively and continuously monitoring and hardening the security configurations of their environment’s operating systems, applications and network devices.

Our approach begins with a discussion emphasizing how network security begins with asset discovery. This foundational control advises organizations to develop an inventory of all authorized and unauthorized devices and software. Using that information, IT security personnel can track and correct all authorized devices and software. They can also deny access to unauthorized and unmanaged products, as well as prevent unapproved software from installing or executing on network devices. Once enterprises have discovered all their assets, they can move on to security configuration management (SCM).

Configuration Management, Design, and Remediation services we offer include:

SCM and Compliance

Compliance auditors can also use security configuration management to monitor an organization’s compliance with mandated policies. These standards range from the Health Insurance Portability and Accountability Act of 1996 (HIPAA) for organizations that collect medical information to the Payment Card Industry Data Security Standard (PCI DSS) for just about anyone who handles branded credit cards.

Security configuration management consists of four steps. The first step is asset discovery. Next, organizations should define acceptable secure configurations as baselines for each managed device type. They can do so using guidance published by the Center for Internet Security (CIST) or the National Institute of Standards and Technology (NIST).

Type of SCM Audits

In the case of Software Configuration Management (SCM) audits, three types of audits are typically performed:

  1. Functional Configuration Audit (FCA), which is an evaluation of the completed software products to determine their conformance, in terms of completeness, performance and functional characteristics, to their requirements specification(s).
  2. Physical Configuration Audit (PCA), which is an evaluation of each configuration item to determine its conformance to the technical documentation that defines it.
  3. In-Process SCM Audits, which are ongoing evaluations conducted throughout the life cycle to provide management with information about compliance to SCM policies, plans, processes and systems, and about the conformance of software product to their requirements and workmanship standards.

All SCM Audits we conduct are considered as planned and independent evaluations of one or more products or processes to determine conformance or compliance to a set of agreed to requirements. We take on the view that,

  • Auditing is an “objective assurance and consulting activity designed to add value and improve an organization’s operations.” Our SCM Audits provide assurance by validating that the products and/or processes are implemented in accordance with their requirements and objectives.
  • Audits are consulting activities because they provide on-going analysis of the degree to which those implementations are effective and efficient and they identify opportunities for continuous improvement.
  • Audits also visibly demonstrate management’s support for the quality program.
ADVANCED ICT » Consultants and Auditors LLP.