IBM Tool Polices Policy

New Tivoli Compliance Insight Manager catches non-compliant behavior

Dark Reading logo in a gray background | Dark Reading

IBM's governance and risk management picture is filling out: Today the company will officially debut the fruits of its acquisition earlier this year of security audit and compliance vendor Consul. (See IBM Buys Into Security Compliance, IBM Closes on Consul, and IBM to Enter Web App Security.)

The new Tivoli Compliance Insight Manager -- based on Consul's InSight -- is an automated security information and event management (SIEM) product that tracks and reports non-compliant behavior on networks, and sends out alerts when data or systems are at risk of exposure, or when there's been unauthorized or inappropriate access. The new software is part of IBM’s IT Governance & Risk Management portfolio of technologies and services.

Kris Lovejoy, director of strategy for IBM governance & risk management and the former CTO for Consul, says that most IT failures are due to human error, not security breaches. "Things get missed," she says. "Our technology helps organizations from a business process policy standpoint, whether the IT processes and policies are followed. If not, we provide an alert or report."

It's all about change management, Lovejoy says. Even the smallest changes that don't require IT testing can cause a system outage, so organizations need to get a handle on change management. If they don't, they could pay the price when the auditors come knocking: "Auditors recognize that the bulk of outages are associated with a lack of control around change and identity management... So they look at whether those policies are documented or logged or monitored [so] any anomalies can be identified and reported on."

That's where Tivoli Compliance Insight Manager comes in, she says, to help identify any deficiencies in change management, as well as to help an organization prepare for an audit. The software works with IBM Tivoli Security Operations Manager, and can receive data from IBM Tivoli Identity Manager and IBM Tivoli Access Manager.

IBM says CSOs are spending more than 50 percent of their time reporting audit results, so the idea is to simplify the compliance process.

Tivoli Compliance Insight Manager, as well as a version for its iSystem mainframes, will ship on July 6. IBM had not yet finalized pricing details as of press time.

— Kelly Jackson Higgins, Senior Editor, Dark Reading

Read more about:

2007

About the Author

Kelly Jackson Higgins, Editor-in-Chief, Dark Reading

Kelly Jackson Higgins is the Editor-in-Chief of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, Virginia Business magazine, and other major media properties. Jackson Higgins was recently selected as one of the Top 10 Cybersecurity Journalists in the US, and named as one of Folio's 2019 Top Women in Media. She began her career as a sports writer in the Washington, DC metropolitan area, and earned her BA at William & Mary. Follow her on Twitter @kjhiggins.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights