Welcome!

IoT User Interface Authors: Elizabeth White, Liz McMillan, AppDynamics Blog, Yakov Fain, Jason Bloomberg

Related Topics: @CloudExpo, Java IoT, Microservices Expo, IoT User Interface, Agile Computing, Cloud Security

@CloudExpo: Article

Security Posture Management Enters the Cloud

A “pure” cloud-based IT security monitoring and compliance management product

When eGestalt of Santa Clara, CA, announced in November they were launching a cloud-based security and compliance solution, it set the stage to change the way enterprise businesses could cope with complex compliance and security issues.

The solution, powered by Rapid7 scanning technology, was to deliver a "pure" cloud-based IT security monitoring and compliance management product that worked in real time without requiring any hardware, "a first of its kind solution," say the vendors.

Called Aegify, the technology delivers Security Posture Management (SPM), which first measures the security status of all assets within a network, then delivers a report that can be used to remediate problems, strengthen security, and create and manage compliance policies. It leverages the compliance and security engine of eGestalt's SecureGRC (governance, risk management and compliance) product with Rapid7's Nexpose vulnerability management technology.

Aegify uses a patent-pending expert systems technology from eGestalt to automatically map the security vulnerabilities to compliance mandates, thereby automating the task of security posture management and compliance management, which is manually done today. The tool can import data from other standard vulnerability scanners in the industry as well.

The advantage of using a cloud-based solution to perform this type of sophisticated network diagnoses is a vast reduction in complexity and time, said Anupam Sahai, President of eGestalt.

"Currently, you do this with on-site hardware," Sahai explained. "You run a scan and get a report. Then the IT person has to study it and perform the needed remediation. That takes time, and then once this is performed the network settings change" and you can fall back out of compliance and into a weakened security state all over again.

With a cloud-based solution like Aegify, scanning and remediation can be run in perpetuity, and IT administrators can "see results on the fly," said Sahai. The cloud solution does the work, and you get SPM and/or the compliance posture in real time, or you can schedule it.

"You don't need specialized IT resources to understand and interpret the results or have to deal with remediation," Sahai explained.

The combined solution from eGestalt and Rapid7 performs a massive amount of work, combining asset discovery with vulnerability analysis and compliance mandates. This gives even the largest company an easy way to identify exactly what they have operating in their network, check the level of their exposure to a potential threat, and make any adjustments that have them falling out of compliance. It can identify 28,000 vulnerabilities and perform over 85,000 checks across physical and virtual networks.

"It's a completely multi-tenant solution," said Sahai, who adds that the cloud-based approach and the integration of the security, compliance, and scanning system in Aegify solves the cumbersome, time consuming and inefficient method of approaching the task with separate, siloed applications that don't communicate well with one another.

Aegify will be marketed to the customer and partner bases of both eGestalt and Rapid7. Sheldon Malm, senior director of Strategic Partners and Alliances at Rapid7, said the alliance creates "a very complementary offering that will benefit our joint customers."

On the compliance side, Aegify covers practically every industry that falls under compliance regulations. The cloud solution can control and manage compliance across more than 400 regulations, from the commonly known ones such as PCI, HIPAA/HITECH, SOX, FISMA, and GLBA, to compliance rules from other countries outside the U.S.

An added advantage of Aegify being a cloud solution is that an IT reseller or consultant can manage it remotely for customers and present the reporting wrapped with upsell and cross-sell offerings. And Aegify can be white-labeled with a reseller's or consultant's own branding, said Sahai.

Public cloud services like Aegify are predicted to grow five times faster than traditional on-premise IT, at a growth rate of 19 percent through 2015, according to a study by MarketBridge. The reason for this growth is multi-faceted. The simplicity that cloud computing offers by moving the complexity away from the customer also means customers no longer have to maintain upgrades or version enhancements. The capital expense of purchasing additional server or storage capacity is also greatly reduced with a cloud-based service.

Still, traditional legacy IT networks dominate the computing landscape, which is why Aegify is such an effective solution for reaching out to these networks and keeping them secure and in compliance. In a press release, Bryan Britz, a research director at Gartner, said a mixture of cloud solutions and traditional networks "will permeate most organizations in the coming years."

Sahai of eGestalt agrees and pointed out that a residual effect of Aegify is helping preserve the investment a company has in its traditional IT network.

"Many customers claim they have no security or compliance issues," Sahai said, adding that this makes Aegify community edition, a free tool downloadable from the web (www.egestalt.com), a conversation starter with customers - a conversation that can lead to the purchase of traditional network equipment, or more cloud services.

"We are solving a number of problems by making networks cheaper, better, and more effective by delivering it to the cloud," he said.

More Stories By Dan Neel

Dan Neel is an award-winning journalist who has covered technology trends and best practices for over 15 years working with leading technology publications like Infoworld, CRN, VARbusiness and Investment Management Weekly. He led the direction of technology channel content at United Business Media, and is the recipient of 9 industry awards, including Best News Story for 2000 from the American Society of Business Press Editors.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


@CloudExpo Stories
Many banks and financial institutions are experimenting with containers in development environments, but when will they move into production? Containers are seen as the key to achieving the ultimate in information technology flexibility and agility. Containers work on both public and private clouds, and make it easy to build and deploy applications. The challenge for regulated industries is the cost and complexity of container security compliance. VM security compliance is already challenging, ...
The essence of data analysis involves setting up data pipelines that consist of several operations that are chained together – starting from data collection, data quality checks, data integration, data analysis and data visualization (including the setting up of interaction paths in that visualization). In our opinion, the challenges stem from the technology diversity at each stage of the data pipeline as well as the lack of process around the analysis.
Designing IoT applications is complex, but deploying them in a scalable fashion is even more complex. A scalable, API first IaaS cloud is a good start, but in order to understand the various components specific to deploying IoT applications, one needs to understand the architecture of these applications and figure out how to scale these components independently. In his session at @ThingsExpo, Nara Rajagopalan is CEO of Accelerite, will discuss the fundamental architecture of IoT applications, ...
A strange thing is happening along the way to the Internet of Things, namely far too many devices to work with and manage. It has become clear that we'll need much higher efficiency user experiences that can allow us to more easily and scalably work with the thousands of devices that will soon be in each of our lives. Enter the conversational interface revolution, combining bots we can literally talk with, gesture to, and even direct with our thoughts, with embedded artificial intelligence, wh...
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. MangoApps provides modern company intranets and team collaboration software, allowing workers to stay connected and productive from anywhere in the world and from any device. For more information, please visit https://www.mangoapps.com/.
SYS-CON Events announced today that Tintri Inc., a leading producer of VM-aware storage (VAS) for virtualization and cloud environments, will exhibit at the 18th International CloudExpo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, New York, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Enterprise networks are complex. Moreover, they were designed and deployed to meet a specific set of business requirements at a specific point in time. But, the adoption of cloud services, new business applications and intensifying security policies, among other factors, require IT organizations to continuously deploy configuration changes. Therefore, enterprises are looking for better ways to automate the management of their networks while still leveraging existing capabilities, optimizing perf...
SYS-CON Events announced today that Alert Logic, Inc., the leading provider of Security-as-a-Service solutions for the cloud, will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. Alert Logic, Inc., provides Security-as-a-Service for on-premises, cloud, and hybrid infrastructures, delivering deep security insight and continuous protection for customers at a lower cost than traditional security solutions. Ful...
In his session at 18th Cloud Expo, Bruce Swann, Senior Product Marketing Manager at Adobe, will discuss how the Adobe Marketing Cloud can help marketers embrace opportunities for personalized, relevant and real-time customer engagement across offline (direct mail, point of sale, call center) and digital (email, website, SMS, mobile apps, social networks, connected objects). Bruce Swann has more than 15 years of experience working with digital marketing disciplines like web analytics, social med...
SYS-CON Events announced today Object Management Group® has been named “Media Sponsor” of SYS-CON's 18th International Cloud Expo, which will take place on June 7–9, 2016, at the Javits Center in New York City, NY, and the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
SYS-CON Events announced today that EastBanc Technologies will exhibit at SYS-CON's 18th International Cloud Expo®, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. EastBanc Technologies has been working at the frontier of technology since 1999. Today, the firm provides full-lifecycle software development delivering flexible technology solutions that seamlessly integrate with existing systems – whether on premise or cloud. EastBanc Technologies partners with p...
SYS-CON Events announced today that AppNeta, the leader in performance insight for business-critical web applications, will exhibit and present at SYS-CON's @DevOpsSummit at Cloud Expo New York, which will take place on June 7-9, 2016, at the Javits Center in New York City, NY. AppNeta is the only application performance monitoring (APM) company to provide solutions for all applications – applications you develop internally, business-critical SaaS applications you use and the networks that deli...
The cloud market growth today is largely in public clouds. While there is a lot of spend in IT departments in virtualization, these aren’t yet translating into a true “cloud” experience within the enterprise. What is stopping the growth of the “private cloud” market? In his general session at 18th Cloud Expo, Nara Rajagopalan, CEO of Accelerite, will explore the challenges in deploying, managing, and getting adoption for a private cloud within an enterprise. What are the key differences betwee...
SYS-CON Events announced today that ContentMX, the marketing technology and services company with a singular mission to increase engagement and drive more conversations for enterprise, channel and SMB technology marketers, has been named “Sponsor & Exhibitor Lounge Sponsor” of SYS-CON's 18th Cloud Expo, which will take place on June 7-9, 2016, at the Javits Center in New York City, New York. “CloudExpo is a great opportunity to start a conversation with new prospects, but what happens after the...
As machines are increasingly connected to the internet, it’s becoming easier to discover the numerous ways Industrial IoT (IIoT) is helping to shape the business world. This is exactly why we have decided to take a closer look at this pervasive movement and to examine the desire to connect more things! Now if you need a refresher on IIoT and how it is changing the world, take a moment and listen to Greg Gorbach with ARC Advisory Group. Gorbach believes, "IIoT will significantly change the worl...
SYS-CON Events announced today the Docker Meets Kubernetes – Intro into the Kubernetes World, being held June 9, 2016, in conjunction with 18th Cloud Expo | @ThingsExpo, at the Javits Center in New York, NY. Register for 'Docker Meets Kubernetes Workshop' Here! This workshop led by Sebastian Scheele, co-founder of Loodse, introduces participants to Kubernetes (container orchestration). Through a combination of instructor-led presentations, demonstrations, and hands-on labs, participants learn ...
The IoT is changing the way enterprises conduct business. In his session at @ThingsExpo, Eric Hoffman, Vice President at EastBanc Technologies, discuss how businesses can gain an edge over competitors by empowering consumers to take control through IoT. We'll cite examples such as a Washington, D.C.-based sports club that leveraged IoT and the cloud to develop a comprehensive booking system. He'll also highlight how IoT can revitalize and restore outdated business models, making them profitable...
The IoTs will challenge the status quo of how IT and development organizations operate. Or will it? Certainly the fog layer of IoT requires special insights about data ontology, security and transactional integrity. But the developmental challenges are the same: People, Process and Platform. In his session at @ThingsExpo, Craig Sproule, CEO of Metavine, will demonstrate how to move beyond today's coding paradigm and share the must-have mindsets for removing complexity from the development proc...
Customer experience has become a competitive differentiator for companies, and it’s imperative that brands seamlessly connect the customer journey across all platforms. With the continued explosion of IoT, join us for a look at how to build a winning digital foundation in the connected era – today and in the future. In his session at @ThingsExpo, Chris Nguyen, Group Product Marketing Manager at Adobe, will discuss how to successfully leverage mobile, rapidly deploy content, capture real-time d...
In his session at 18th Cloud Expo, Andrew Cole, Director of Solutions Engineering at Peak 10, will discuss how the newest technology advances are reducing the cost and complexity of traditional business continuity and disaster recovery solutions. Attendees will: Learn why having a full disaster recovery strategy is more important now than ever before Explore the key drivers of a successful disaster recovery solution Achieve measurable operational and business value from a disaster recovery ...