McAfee PASCDE-AB-IA Product Guide - Page 10

Getting started with McAfee Policy Auditor, Introduction to compliance audits

Page 10 highlights

Getting started with McAfee Policy Auditor McAfee Policy Auditor is an extension to ePolicy Orchestrator software software versions 4.5 and 4.6 that automates the process for risk and compliance system audits. Audits can perform tasks such as check system settings, including password length, open or closed ports, file changes, and the presence of software updates. Contents Introduction to compliance audits Auditing systems What's new Software components and what they do Use of ePolicy Orchestrator software features Managed systems vs. unmanaged systems Introduction to compliance audits Before using McAfee Policy Auditor, it is important to understand what audits are, when you should use them, and why you should use them. What are compliance audits? A compliance audit is a comprehensive review of an organization's adherence to external regulatory guidelines or internal best practices. McAfee Policy Auditor automates the compliance audit process and allows you to demonstrate compliance to auditors by producing an audit trail showing compliance, compliance history, and actions taken to mitigate risks. Organizations that are out of compliance might be subject to fines or other sanctions, including criminal liability. When should you use audits? Use compliance audits when you are subject to government regulations that require your organization to determine system compliance and maintain records.You should also use audits to determine compliance with organizational requirements such as password complexity, password length, the presence of unsupported software, and software patch requirements. Why should you use audits? McAfee Policy Auditor automates the process for mandated and organizational audits. Its companion product, McAfee Benchmark Editor, contains built-in benchmarks that the software can use for mandated audits, such as Sarbanes-Oxley (SOX) and the Payment Card Industry Data Security Standards (PCI DSS).The reporting system allows you to demonstrate compliance to auditors while the Findings feature helps you to find solutions to audit issues. 10 McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98

Getting started with McAfee Policy Auditor
McAfee Policy Auditor is an extension to ePolicy Orchestrator software software versions 4.5
and 4.6 that automates the process for risk and compliance system audits. Audits can perform
tasks such as check system settings, including password length, open or closed ports, file
changes, and the presence of software updates.
Contents
Introduction to compliance audits
Auditing systems
What's new
Software components and what they do
Use of ePolicy Orchestrator software features
Managed systems vs. unmanaged systems
Introduction to compliance audits
Before using McAfee Policy Auditor, it is important to understand what audits are, when you
should use them, and why you should use them.
What are compliance audits?
A compliance audit is a comprehensive review of an organization's adherence to external
regulatory guidelines or internal best practices. McAfee Policy Auditor automates the compliance
audit process and allows you to demonstrate compliance to auditors by producing an audit trail
showing compliance, compliance history, and actions taken to mitigate risks. Organizations that
are out of compliance might be subject to fines or other sanctions, including criminal liability.
When should you use audits?
Use compliance audits when you are subject to government regulations that require your
organization to determine system compliance and maintain records.You should also use audits
to determine compliance with organizational requirements such as password complexity,
password length, the presence of unsupported software, and software patch requirements.
Why should you use audits?
McAfee Policy Auditor automates the process for mandated and organizational audits. Its
companion product, McAfee Benchmark Editor, contains built-in benchmarks that the software
can use for mandated audits, such as Sarbanes-Oxley (SOX) and the Payment Card Industry
Data Security Standards (PCI DSS). The reporting system allows you to demonstrate compliance
to auditors while the Findings feature helps you to find solutions to audit issues.
McAfee Policy Auditor 6.0 software Product Guide for ePolicy Orchestrator 4.6
10