Find White Papers
Home
About Us
List Your Papers
    
> Ecora Software > Automating Change Management for Security, Compliance, Stability and Sanity!

Automating Change Management for Security, Compliance, Stability and Sanity!

White Paper Published By: Ecora Software

Learn the importance of change management in today's complex IT infrastructures.



Tags : 
change management, configuration management, it management, project management, compliance, compliant, audit, auditing

Ecora Software
Published:  Aug 15, 2007
Type:  White Paper
Length:  4 pages

WHITEPAPER
Automating Change Management for Security,
Compliance, Stability, and Sanity
Alex BakmanFounder and Chairman Ecora SoftwareThis whitepaper will review all aspects of change management and present concrete steps you can use to take control of change in yourenvironment.
The Implications of ChangeAll IT systems are in a constant state of flux, with changes taking place minute by minute. Right now, for example, it is likely that, on your ownIT system, someone is installing an application or patch, changing a configuration setting, adding a new user, rolling out a new desktop, ormaking some other type of change. And even a simple change can greatly impact systems, servers, and applications. When any change occurs, the infrastructure moves from a "known" state-where systems are secure and operating effectively-to an"unknown" state where it is impossible to be confident that everything is as intended. In fact, any change can have a number of implications,which can impact on everything from operational efficiency, risk management, and business continuity to security, systems integrity, andregulatory compliance. This occurs because each component and setting in the IT environment is dependent on other components or settings, and every new device orapplication adds additional settings and new dependencies. This level of complexity makes controlling change more and more challenging. Let me give you a simple example. An Ecora Software customer had a problem with their Exchange server, so their email wasn't operating.They tried one thing after another to get the server up and running without any success. In the end, the administrator re-installed everything sothat the Exchange server-and email-was working again. Everybody was happy, until a security breach was identified several weeks later.You see, when the administrator did the install, he forgot about re-installing the service packs, which had patched some major securityproblems. According to Gartner, eight of every ten incidents of unscheduled downtime can be traced to change, and in this case, as in so many others,the problem can be traced to a change.
The Evolution of IT Compliance and Best PracticesAlmost every organization deals with regulatory compliance requirements on some level, and it is no longer acceptable to be compliant just foran audit alone. With requirements increasing, expectations for continuous compliance are growing. Financial institutions, for example, may be audited severaltimes each quarter by different regulatory agencies, which necessitates a state of constant readiness-and makes it essential that IT staffmembers are not tied up in "fire drill mode." These organizations have made compliance a standard procedure so there is no need to "getready" for an audit. Best business practices are being integrated into daily IT service delivery, controls are in place, and solid reports areavailable so that these organizations are always ready for an audit. Change management is at the heart of every regulatory standard. If an organization is not controlling what's changing in the IT infrastructure,the risk of security exposure is great. Unfortunately, many organizations don't consider the relationship between change management andsecurity, and, particularly, the threat that can come from uncontrolled changes made by employees within the organization itself. How can this type of security issue be discoveredand controlled? There are literally thousands ofconfiguration settings-including access control lists,credentials, permissions, password aging, patches,etc.-that control security. All applications haveaccess controls, for example, and if an organizationis not monitoring changes to access controls, it can'tbe completely secure. Similarly, if an organizationdoesn't control credentials, there is no way to knowwhich unauthorized personnel (or former personnel)may still have access to critical systems. Best practicesin configuration and change management lead to amore secure enterprise computing environment. Regardless of how change management processesare created or which tools are deployed for changemanagement, an organization must control the "what"or "what's changing," the "how" or "how will it bedone," the "who" or "who is making the change" forany changes to content, settings, and applications.This is particularly true for those organizations wherecompliance is a concern.
2WHITEPAPER
Preparing for-... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search