Subscribe to the Free Print Edition!
Celebrating 25 Years

FDIC insures its systems

Sidebar | Choosing compliance tools: Scan the field

By William Jackson

It doesn't hurt to get a second opinion, especially for network scanning products that focus on patch and configuration management. These tools can be useful additions to your toolkit when you are trying to pass an information technology security audit.

"You need to have multiple tools so you can have checks and balances in place," said Sanjeev Purohit, assistant operations director of the Federal Deposit Insurance Corp.’s technology division. "No one tool can do everything.”

A second opinion can also be helpful in selecting the proper tool.

"Take the product for a test drive and talk to people who are using it," said Mark Krolicki, FDIC senior IT specialist. "And don't believe every trade magazine you read.”

A key factor in FDIC's selection of NetChk products from Shavlik Technologies is that auditors and its own inspector general also use the tools. That lets the agency and the auditors discuss audit results in the same language and confirm corrections when shortcomings are found, Krolicki said.



GCN Popup