HomeSolutionsProductsSupportServicesTrainingPartnersCompanyContact     


assuriaONLINE Customer and Partner resources Logon / register

     


assuria auditor
 


 

Assuria Auditor

Assuria Auditor RA

Assuria Information Manager

Regulatory compliance

CVSS and Assuria Auditor

Browser Web Interface

Assuria Auditor WorkBench

OVAL Compatibility

Assuria and HP

Release history

Supported platforms

System requirements

AssuriaOnline download centre

Regulatory and standards compliance with Assuria Auditor.

Organisations of all sizes and in both the public and private sector are increasingly required to be in compliance with a number of legislative and industry regulations and standards.  Compliance with these regulations should be seen as part of the Information Security Management System (ISMS) or process. 

In the United Kingdom HMG have mandated a number of policies for the UK Public Sector and include Codes of Connection (CoCo) and Good Practice Guides (GPG)from CESG.

In the United States regulations such as SOX, FISMA, HIPPA and in Europe Basel II and privacy legislation are driving organisations to seek tools to assist and automate their compliance.  The impact of some regulations, for example Sarbanes Oxley (SOX) is significant not only in the United States but globally.

The Payment card Industry Data Security Standard (PCI DSS) is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. PCI is intended to help organizations proactively protect customer credit card data.

Most organisations subject to such regulations use controls from standards such as ISO 270001 and guidelines to achieve compliance.

ISO 27001 is the formal standard against which organizations may seek independent certification of their Information Security Management Systems.  AN ISMS is a frameworks to design, implement, manage, maintain and enforce information security processes and controls systematically and consistently throughout the organizations.

Gartner Group represented (below) the relationship between regulations, control objectives and controls.

Assuria Auditor is a software tool that supports the controls within an ISMS.  A key issue with compliance is planning and measuring acceptable levels of compliance.

With Assuria Auditor’s unique mapping of Checks to controls, control objectives and regulations it delivers a powerful tool to help achieve compliance to appropriate and applicable standards.

Assuria Auditor features

Assuria Auditor features regulatory and standards compliance reporting.  The Assuria Auditor Console database includes, where appropriate, the mapping of each Assuria Auditor’s thousands of checks to a specific reference within the standard.

Currently available standards are ISO 27001, ISO 27002 (formerly ISO 17799) PCI, FISMA, HIPAA, SOX and CVE and BID.   Further standards, are planned.

 

 

 

 

Assuria Auditor reporting includes options to report by the selected standard. 

Example report content

An Initial-on-all report sorted by applicable PCI sections.

 
 
 

Policy Navigators

Assuria Auditor Policy Navigators are a great way to discover features and facilities of Assuria Auditor include the currently available Standards mapping.

 

Assuria® is a registered trademark of Assuria Limited.
Assuria Auditor and AutoUpdate are trademarks of Assuria Limited.
© Copyright2009 Assuria Limited.  All rights reserved.

05/08/2010

Legal notice | Site map | Contact Assuria