McAfee Total Protection for Compliance

McAfee Total Protection for Compliance

Simplified compliance through unified IT policy auditing and risk management

Next Steps:

Overview

McAfee Total Protection for Compliance uses agent-based and agentless technology to audit, assess, and report across managed and unmanaged systems, reducing the time and effort required for IT audits from weeks to days.

The Total Protection for Compliance suite includes McAfee Policy Auditor, McAfee Vulnerability Manager, McAfee ePolicy Orchestrator (ePO) platform, McAfee Labs Global Threat Intelligence service, and McAfee Risk Advisor with countermeasure-aware risk management.

Optimize your security investment — Our integrated solution proactively combines threat, vulnerability, and countermeasure information to pinpoint assets that are truly at risk. It takes the guesswork out of when and where to focus your security efforts, saving you time and money.

Total protection through unified IT policy auditing — Our single solution defines, assesses, and reviews policies across the widest range of devices and systems. By eliminating standalone processes and integrating critical tools, Total Protection for Compliance boosts efficiency and reduces the window of noncompliance.

Integrated technology — Integrated agent-based and agentless scanning and reporting give you deep policy assessments on host systems for automated snapshots of compliance. Total Protection for Compliance further extends compliance coverage across your network into policy settings for account, file, network, and system access.

Comprehensive support — Assessments and reports include content for PCI DSS, SOX, FDCC, FISMA, HIPAA, and many more.

Simplified compliance — With customized policies and checks, you can target a specific group of assets, select a template, and conduct an audit.

ESG Risk Management Technology brief

Features & Benefits

Reduce costs with centralized management of security and compliance

Automate all risk and compliance activities under the centralized management of the McAfee ePolicy Orchestrator (ePO) platform. Use this shared platform to deploy, manage, and report on system security and policy compliance in both agent-based and agentless systems. Define and select a policy benchmark once, then apply it across many different asset types.

Reduce audit time

Automate time-consuming auditing tasks on both host and network systems. Successfully pass external audits using internal reports.

Get real-time compliance accuracy

Assess compliance levels against regulations and standards with built-in support for benchmarks like XCCDF and OVAL content. Ensure data is always current for internal and external audits.

Add intelligence to protection

Correlate threat information with vulnerabilities and deployed countermeasures to understand your risk posture and where to focus remediation efforts.

Demonstrate measurable ROI for existing security products

Illuminate the positive impact of multilayered defenses as threats materialize.

Improve operational efficiencies

Reduce patching costs by automating the manual and time-consuming process of correlating threats to critical assets at risk.

System Requirements

Demos / Tutorials

Demos

Learn how McAfee Risk Advisor takes the guesswork out of protecting your critical assets.

Tutorials

Awards / Reviews

SC Magazine Reprints
ToPS for Compliance Receives Five-Star Rating by SC Magazine

SC Magazine looks at McAfee Total Protection for Compliance and gives McAfee an overall rating of 5 stars. This evaluation mentions that Total Protection for Compliance is a great solution and helps you address the question: "Where and when should I spend my next dollar on security?"

News / Events

News

Events

No results found

On Demand

No results found

Resources

Reports

Miercom Lab Test Report — McAfee Risk Management Solution

Miercom conducted an extensive battery of tests that the McAfee Risk Management solution passed in four major areas, including vulnerability lifecycle management, security and compliance assessment, risk management, and reporting.

ESG Technology Brief: Real-Time Risk Management

Learn about the benefits of Real-time Risk Management, a new discipline CISOs need to implement to address the rapidly changing threat landscape with up to the minute information about threats, vulnerabilities, and assets; comprehensive visibility of the entire IT infrastructure; and continuous assessment of existing security controls.

Solution Briefs

White Papers

Community

Forums

No results found

Blogs

  • RDP+RCE=Bad News (MS12-020)
    Jim Walter - March 14, 2012
    See March 15 and 16 updates at the end of this blog. —————————————————-   The March Security Bulletin release from Microsoft was relatively light in volume. Out of the six bulletins released, only one was rated as Critical. And for good reason. MS12-020 includes CVE-2012-0002. This flaw is specific to the Remote Desktop Protocol (RDP) present on Read more...
  • An Update on DNSChanger and Rogue DNS Servers
    Jim Walter - March 06, 2012
    In late 2011, the FBI released documents and data focusing on “Operation Ghost Click.” This malicious operation, leveraging a variety of DNSChanger-type malware, was defined by the FBI as an “international cyber ring that infected millions of computers.” Associated malware samples and events can be traced back several years, and multiple platforms were targeted. To this day many remain Read more...
  • McAfee Q4 Threats Report Shows Malware Surpassed 75 Million Samples in 2011
    David Marcus - February 21, 2012
    Today we released our Fourth Quarter 2011 Threat Report, revealing that malware surpassed the our estimate of 75 million unique malware samples last year. Although the release of new malware slowed a bit in Q4, mobile malware continued to increase and recorded its busiest year to date. Malware The overall growth of PC-based malware actually Read more...
  • Cultural Security: Promoting Security Policies Using Organizational Culture
    Steven Fox - September 06, 2011
    Most of us refer to security policies in much the same way as we refer to our car manuals – when something unexpected happens.  We know these documents have useful information.  However, their utility is tied to situations where answers do not present themselves readily. According to Chris Noel, SVP of Product Management at ANXeBusiness, Read more...
  • Building an Arsenal of Best-in-Breed Database Security Solutions
    Eric Schou - August 19, 2011
    Visit any news site on the Web, and undoubtedly you’ll come across a barrage of articles publicizing the details of yet another data breach. With the prominence of SQL injection attacks, and malicious insiders and hackers exploiting sensitive data stored on unpatched and vulnerable databases, enterprise organizations have found themselves reevaluating their security strategies. Following Read more...