Find White Papers
Home
About Us
List Your Papers
    
> Solidcore > Identifying Critical Change Control Failure Points

Identifying Critical Change Control Failure Points

White Paper Published By: Solidcore

Identifying critical change control failure points in your infrastructure can help reduce the threat of costly downtime, potential security breaches, and compliance weaknesses. Read this paper for guidelines on how to identify and categorize systems that have characteristics which heighten risk.



Tags : 
audit, auditing, security audit, vulnerabilities, vulnerability, vulnerability management, security management, change management

Solidcore
Published:  Jan 07, 2008
Type:  White Paper
Length:  3 pages

IIIIIdddddeeeeennnnntttttiiiiifffffyyyyyiiiiinnnnnggggg CCCCCrrrrriiiiitttttiiiiicccccaaaaalllll
CCCCChhhhhaaaaannnnngggggeeeee CCCCCooooonnnnntttttrrrrrooooolllll
FFFFFaaaaaiiiiillllluuuuurrrrreeeee PPPPPoooooiiiiinnnnntttttsssss
There are key systems in every infrastructure where un- created an audit weakness, which could result in restatementapproved change poses significant business risk. The of financials. Ericsson identified their ERP systems running onbusiness risk can be outage, integrity of operations, security Windows NT as critical because of the fragile nature and highand audit weaknesses. risk of outage. In summary, each of these companies haddifferent business risks, all of which are related toWhat are examples of such systems? The table below shows unapproved change.critical change control failure points identified by companiesin various industries: For instance, Los Angeles World So how do you identify systems within your infrastructure asAirports (LAX) identified servers housing the database that key change control failure points? A great starting point is tocontrols access to various areas of the airport as critical. If look at various categories of systems that haveunapproved changes were made to these machines, it would characteristics which heighten risk. The following sectioncompromise the integrity of the airport operations and provides some categorization guidelines that Solidcorepotentially the safety of passengers. Network Appliance customers have used to identify their critical change controlidentified their Siebel systems because unapproved changes failure points.
WWWWWhhhhhooooo WWWWWhhhhhaaaaattttt WWWWWhhhhhyyyyy
Servers hosting WebEx meetings Critical to customer SLAsglobally
Transaction processing infrastructure Critical to maintain integrity offinancial transactions
ERP systems on Windows NT Fragile systems where any changeposes an outage risk
Physical access control systems Critical to airport security andpassenger security
Siebel order processing systems Critical for revenue and to avoidcompliance audit weaknessIdentifying Critical Change Control Failure Points
Critical Change Control Failure Points . Production control on factory Windows NTfloorsSystems with Large Fan Out . Legacy ERP systems. Many other applicationsThese are servers on which a lot of machines depend. If theywere to go down, a large number of machines would not be Communication Systemsable to operate. Examples include: Communication outages can bring most organizations to a. Root DNS complete halt:. Active Directory Servers Citrix . Domain Controllers Server . Email. Citrix Presentation Servers . Blackberry Exchange / Lotus. Virtualized Host Operating . VoIPSystems BlackberryDifficult to ServiceCascading Changes These machines are difficult to service and cost more to A local change propagates automatically through the support as a on-site technician is required. In addition peopleinfrastructure. Examples include: at distributed locations can make often make changes withless scrutiny. Systems include:. AD/DNS: Auto-replication Active Directory / DNS:Changes propagate propagates mistakes quickly . ATMs. Production/Disaster Recovery: . Retail POS Retail POSauto-sync can bring down both : . Medical Imaging Devices HHoossppiittaall . Network: Routing changes EEqquuiippmmeennttpropagate quickly; Line of Revenue. Any clustering solution Systems which are in the path of revenue for the company.Access Control Systems For example: Web Fulfillment/CRMSystems which control access to either the network or the . E-commercephysical facilities including: . Order fulfillment etc.. Servers providing a hosted. Checkpoint firewalls on Sun/ service for customersLinux Boxes Perimeter Firewalls. ISA/Windows Firewalls Complex Business Systems. Physical Access Badging Access /BadgingDatabases Systems running database based SAP Configuration(SAP) or j2ee business applicationsLegacy Systems have complex configurations.Changes to these configurations canSystems running fragile legacy applications where any cause downtime and bring businesschange, including OS patches could cause an outage. In use to a halt.across many enterprises forIdentifying Critical Change Control Failure Points
About Solidcore SystemsBenefits of Categorizing Systems by Business Risk Solidcore is a leading provider of changeCategorizing systems according to business risk p... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search