McAfee Secure 網站能協助您遠離身份竊取、信用卡詐欺、間諜軟體、垃圾郵件、病毒和線上詐騙

管理變更

控制 IT 環境的變更

後續步驟:

概觀

當您處理多個作業系統、網路、伺服器、桌上型電腦/筆記型電腦、使用者、應用程式與資料庫時,管理變更會是一場常態的挑戰。McAfee 風險管理解決方案不只可處理環境與生俱來的變更,也會指引您進行修補管理與原則執行的工作,並將變更對作業的影響降到最低。透過持續監控與管理,您便可自動將有益的變更融合到您的環境中,並避免引起破壞性的變更。我們的目標是讓您的系統可供使用,並讓使用者保有生產力。

重要優勢

  • 減少來自未經授權應用程式的風險
    阻擋不需要的應用程式與相關的風險。使用者會不慎將會安裝惡意軟體、產生支援問題與違反軟體授權的軟體帶入工作環境,這些都可能危害系統與整體企業。McAfee Application Control 只會讓被信任的應用程式在伺服器與端點上執行。
  • 落實變更政策與程序
    確保只允許處理程序中的變更。McAfee Change Control 會主動在系統發生處理上的變更或不必要的變更之前,將這些變更阻擋在系統之外。
  • 減少營運成本
    使用 Change Control 阻止未經授權或不常應用的變更,並減少追蹤與說明系統變更所需的人工作業。Change Control 可減少運作中斷、安全缺口和違規行為,避免導致額外的 IT 成本。
  • 自動化稽核和設定的評估作業
    取得最新的資料、強大的儀表板和報告,以及內建的豁免管理,以簡化稽核和設定程序的每一個步驟。
  • 符合與保持 PCI DSS 規範
    取得所有 POS 基礎結構上的變更事件資訊,以符合 PCI DSS 的需求。McAfee Integrity Control 會通知您伺服器產生的變更,包含發生的時間、造成變更的使用者、變更方法、變更檔案的內容,以及變更是否經過核准等。
  • 簡化進行法規遵循的作業
    使用業界第一個整合式、代理程式型和無代理程式的解決方案來進行修補評估、法規狀態報告和風險分析,以自動化法規遵循作業。

產品

風險與法規遵循

McAfee Total Protection for Compliance
McAfee Total Protection for Compliance

McAfee Total Protection for Compliance 是業界第一個弱點管理、法規遵循評估和回報,以及全方位風險管理的整合式解決方案,能容易地達成法規遵循目的。

McAfee Application Control
McAfee Application Control

McAfee Application Control 確保只有被信任的應用程式可以在伺服器與端點上執行。它能減少來自未經授權軟體的風險、大幅提升端點控制能力、擴充原有功能系統的可行性而無須影響效能,並且還能減少營運支出。

McAfee Change Control
McAfee Change Control

McAfee Change Control 能落實原則並對檔案完整性問題發出警示,同時能選擇是否阻擋對關鍵系統檔案和目錄所發生的未經授權變更。

McAfee Configuration Control
McAfee Configuration Control

McAfee Configuration Control 能防範關鍵伺服器上未經授權的變更,大幅提升環境的可見度,並且能簡化內部和外部的 IT 稽核程序。

McAfee Integrity Control
McAfee Integrity Control

McAfee Integrity Control 結合了領先業界的白名單和變更控制技術,確保只有受到信任的應用程式可以在固定系統裝置上運作,如服務點 (POS) 系統、ATM 和電子資訊站。

McAfee Policy Auditor
McAfee Policy Auditor

McAfee Policy Auditor 會自動化內部和外部系統層級之 IT 稽核所需的資料收集和評估程序。

安全管理

McAfee ePolicy Orchestrator

McAfee ePolicy Orchestrator (ePO) 是 McAfee Security Management Platform 的主要元件之一,也是唯一可以統一管理端點、網路和資料安全性的企業級軟體。McAfee ePO 軟體具備端對端可見度以及可以大幅縮短回應時間的強大自動化功能,能大幅強化防護,並且降低管理安全性的成本。

服務

Data Loss Prevention Assessment

偵測與防止未經授權傳輸或公開機密資訊。McAfee Foundstone 會辨識出遭複製的機密資料,或目前正從其原始應有容器中向外傳輸的機密資料。

Identity Theft Red Flags Rule Service

符合法規需要,改善組織整體安全態勢。Foundstone 專家會協助您實行防止身分竊取程式、分析資料流量與風險,以及開發可偵測、預防與減輕身分竊取的政策。

Incident Management Check

建立更好、更有效的事件回應與管理程式。McAfee Foundstone 會分析您事件管理程式中的漏洞,並提出改善您緊急回應通訊協定的建議。

Vulnerability Management Check

評估弱點管理程式。McAfee Foundstone 會分析程式的漏洞,確保人員、程序與技術會達到正確的平衡。

資源

報告

Risk & Compliance Outlook 2012 (English)

In this global study, independent research firm Evalueserve examines the dynamic risk and compliance market, including the state of the industry, the challenges faced by enterprises, and emerging trends that will impact both consumers and vendors.

Risk & Compliance Outlook 2011 (English)

In this global study, independent research firm Evalueserve examines the dynamic risk and compliance market, including the state of the industry, the challenges faced by enterprises, and emerging trends that will impact both consumers and vendors.

社群

部落格

  • RDP+RCE=Bad News (MS12-020)
    Jim Walter - 三月 14, 2012
    See March 15 and 16 updates at the end of this blog. —————————————————-   The March Security Bulletin release from Microsoft was relatively light in volume. Out of the six bulletins released, only one was rated as Critical. And for good reason. MS12-020 includes CVE-2012-0002. This flaw is specific to the Remote Desktop Protocol (RDP) present on Read more...
  • An Update on DNSChanger and Rogue DNS Servers
    Jim Walter - 三月 06, 2012
    In late 2011, the FBI released documents and data focusing on “Operation Ghost Click.” This malicious operation, leveraging a variety of DNSChanger-type malware, was defined by the FBI as an “international cyber ring that infected millions of computers.” Associated malware samples and events can be traced back several years, and multiple platforms were targeted. To this day many remain Read more...
  • McAfee Q4 Threats Report Shows Malware Surpassed 75 Million Samples in 2011
    David Marcus - 二月 21, 2012
    Today we released our Fourth Quarter 2011 Threat Report, revealing that malware surpassed the our estimate of 75 million unique malware samples last year. Although the release of new malware slowed a bit in Q4, mobile malware continued to increase and recorded its busiest year to date. Malware The overall growth of PC-based malware actually Read more...
  • Cultural Security: Promoting Security Policies Using Organizational Culture
    Steven Fox - 九月 06, 2011
    Most of us refer to security policies in much the same way as we refer to our car manuals – when something unexpected happens.  We know these documents have useful information.  However, their utility is tied to situations where answers do not present themselves readily. According to Chris Noel, SVP of Product Management at ANXeBusiness, Read more...
  • Building an Arsenal of Best-in-Breed Database Security Solutions
    Eric Schou - 八月 19, 2011
    Visit any news site on the Web, and undoubtedly you’ll come across a barrage of articles publicizing the details of yet another data breach. With the prominence of SQL injection attacks, and malicious insiders and hackers exploiting sensitive data stored on unpatched and vulnerable databases, enterprise organizations have found themselves reevaluating their security strategies. Following Read more...

部落格

沒有找到結果