Policy Lifecycle Management

Assess risk, enforce policies, remediate vulnerabilities, and streamline audit tasks — automatically

Next Steps:

Overview

Most IT teams must not only meet internal corporate compliance requirements, but industry and government regulations, as well. If you face governance requirements and HIPAA, GLBA, PCI DSS, or other regulations, leverage the McAfee portfolio to ease your workload and automate processes. The McAfee Policy Lifecycle Management solution helps you define and measure effective policies and processes. We enable these activities with templates and best-practice content that are implemented with workflow and IT control technology to help you efficiently meet your compliance needs.

Multiple, overlapping regulations mean audits are increasing in frequency and detail. McAfee eliminates audit fatigue with innovative tools that integrate and automate tedious manual tasks to help you improve security, cut costs, and achieve compliance quickly. Policy Lifecycle Management helps connect your policies to centrally managed controls that interlock from the endpoint through the network. Wherever your sensitive data and systems reside, McAfee can help you meet your internal and external compliance requirements.

Key Benefits

  • Assess risks and prioritize remediation — automatically
    Calculate business risk and prioritize limited resources based on threats, vulnerabilities, assets, and existing countermeasures.
  • Adopt and adjust policies quickly and easily
    Choose relevant policies with predefined templates for such regulations as PCI, HIPAA, GLBA, and SOX, or auto-import industry benchmarks. Adjust these rules or create your own to support your interpretations of regulations.
  • Improve compliance assessment across your entire infrastructure
    Identify policy violations and vulnerabilities that leave you open to attack and data loss. Automatic scans look across your entire environment to find violations on systems — with or without an agent — and measure your compliance with prescribed IT technical controls.
  • Enjoy end-to-end policy enforcement
    Access the industry’s broadest coverage across policy requirements and interlocking endpoint, network, and cloud-based controls, including system and file integrity solutions for field systems. Tap the McAfee Security Innovation Alliance ecosystem for extended coverage.
  • Support international frameworks and standards
    Assess and map your controls against the best practices in such frameworks as ISO 17799 / 27002 and COBIT. Use McAfee support for open content protocols — including SCAP, XCCDF, and OVAL — to import authoritative policy definitions and integrate audit tools into your existing infrastructure.
  • Prove compliance with extensive, flexible reporting
    Demonstrate compliance to key stakeholders with custom reports that define, measure, and report on the compliance of information systems based on industry, regulatory, and corporate security policies, as well as standards and frameworks.
  • Stay ahead of emerging threats
    Get streaming downloads of the latest threat protections and vulnerability research from McAfee Labs, our Global Threat Intelligence team.

Products

Data Protection

McAfee Total Protection for Data
McAfee Total Protection for Data

McAfee Total Protection for Data offers strong encryption, authentication, data loss prevention, and policy-driven security controls to help block unauthorized access to your sensitive information — anytime, anywhere.

Risk & Compliance

McAfee Total Protection for Compliance
McAfee Total Protection for Compliance

McAfee Total Protection for Compliance makes compliance easy with the industry’s first integrated solution for vulnerability management, compliance assessment and reporting, and comprehensive risk management.

McAfee Change Control
McAfee Change Control

McAfee Change Control enforces change policies and provides alerts to file integrity issues, while providing options to easily block unauthorized changes to critical system files and directories.

McAfee Policy Auditor
Mcafee Policy Auditor

McAfee Policy Auditor automates data gathering and assessment processes required for internal and external system-level IT audits.

McAfee Risk Advisor
McAfee Risk Advisor

McAfee Risk Advisor saves you time and money by proactively correlating threat, vulnerability, and countermeasure information to pinpoint at-risk assets and optimize patching efforts.

McAfee Vulnerability Manager
McAfee Vulnerability Manager

McAfee Vulnerability Manager finds and prioritizes vulnerabilities and policy violations on your network. It balances asset criticality with vulnerability severity, enabling you to focus protection on your most important assets.

Services

Data Loss Prevention Assessment

Detect and prevent the unauthorized transmission or disclosure of sensitive information. McAfee Strategic Security Services reduces your risk of exposure by identifying sensitive data copied or currently in transit from its original intended container.

Identity Theft Red Flags Rule Service

Meet compliance requirements and improve your organization’s overall security posture. McAfee Strategic Security Services experts help you implement an identity theft prevention program, analyzing data flow and risk, as well as developing policies for detecting, preventing, and mitigating identity theft.

Incident Management Check

Build a better, more effective incident response and management program. McAfee Strategic Security Services analyzes the gaps in your incident management program and offers recommendations to improve your emergency response protocol.

Payment Card Industry (PCI) Security Solutions

Meet PCI DSS requirements. McAfee Strategic Security Services’ PCI Security Solutions strengthen data security, ensuring you meet industry requirements.

Regulatory & Compliance Check

Meet information security compliance requirements. McAfee Strategic Security Services assesses gaps in your organization’s regulatory and compliance status and makes next-step recommendations.

Vulnerability Management Check

Assess your vulnerability management program. McAfee Strategic Security Services analyzes the gaps in your program to ensure you have the right balance of people, process, and technology.

Resources

Reports

Risk & Compliance Outlook 2012

In this global study, independent research firm Evalueserve examines the dynamic risk and compliance market, including the state of the industry, the challenges faced by enterprises, and emerging trends that will impact both consumers and vendors.

Risk & Compliance Outlook 2011

In this global study, independent research firm Evalueserve examines the dynamic risk and compliance market, including the state of the industry, the challenges faced by enterprises, and emerging trends that will impact both consumers and vendors.

Community

Forums

No results found

Blogs

  • NCCDC 2013 – Red Team Recap
    Jim Walter - May 07, 2013
              This past April (4/19 to 4/21) I had the great pleasure and experience of joining the Red Team at 9th NCCDC competition.   It was actually my 2nd year on the Red Team and 4th year to attend in total (I judged in 2010 and 2011).  McAfee is actually a perpetual Read more...
  • RDP+RCE=Bad News (MS12-020)
    Jim Walter - March 14, 2012
    See March 15 and 16 updates at the end of this blog. —————————————————-   The March Security Bulletin release from Microsoft was relatively light in volume. Out of the six bulletins released, only one was rated as Critical. And for good reason. MS12-020 includes CVE-2012-0002. This flaw is specific to the Remote Desktop Protocol (RDP) present on Read more...
  • An Update on DNSChanger and Rogue DNS Servers
    Jim Walter - March 06, 2012
    In late 2011, the FBI released documents and data focusing on “Operation Ghost Click.” This malicious operation, leveraging a variety of DNSChanger-type malware, was defined by the FBI as an “international cyber ring that infected millions of computers.” Associated malware samples and events can be traced back several years, and multiple platforms were targeted. To this day many remain Read more...
  • McAfee Q4 Threats Report Shows Malware Surpassed 75 Million Samples in 2011
    David Marcus - February 21, 2012
    Today we released our Fourth Quarter 2011 Threat Report, revealing that malware surpassed the our estimate of 75 million unique malware samples last year. Although the release of new malware slowed a bit in Q4, mobile malware continued to increase and recorded its busiest year to date. Malware The overall growth of PC-based malware actually Read more...
  • Cultural Security: Promoting Security Policies Using Organizational Culture
    Steven Fox - September 06, 2011
    Most of us refer to security policies in much the same way as we refer to our car manuals – when something unexpected happens.  We know these documents have useful information.  However, their utility is tied to situations where answers do not present themselves readily. According to Chris Noel, SVP of Product Management at ANXeBusiness, Read more...