Policy Audit and Reporting

XACML-Based Policy Management

 

NextLabs Audit, Tracking, and Reporting provides ad hoc query, canned reports, and a dashboard summary of all policy activity.
 

  • Graphical summary with drilldown to details
  • Ad-hoc and pre-built report templates
  • Provides a central activity journal, analysis engine, and web-based reporting that enables analysts to generate charts and reports showing access rights, access attempts, authorization decisions, end user activity and trend analysis.

 

Centralized Activity Monitoring, Analysis, and Reporting

Performing quarterly compliance audits, responding to legal inquiries, or investigating a data loss incident is typically a manual and costly process for IT organizations. Typically authorization and access data must be collected and analyzed from many systems and applications. Control Center centralizes the collection and analysis of entitlements and user activity to simplify compliance reporting.

NextLabs Report Server provides a central activity journal, analysis engine, and web-based reporting application that enables analysts to generate charts and reports showing access rights, access attempts, authorization decisions, end user activity and trend analysis.

Key Benefits

  •  

Reduces Cost of Compliance Audit
Automates collection of authorization policy and data activity required to respond to compliance audits, legal inquiries, or data loss incidents.

  •  

Provides End-to-End Visibility
Collects data activity across applications and enables policy analysts to track sensitive data across the enterprise, from access, to use, to duplication, to deletion.

  •  

Identifies Authorization Risk
Provides analysis to help identify areas of risk, including users or resources where too much access is given as well as areas where overly stringent entitlements may be impeding business productivity.

  •  

Administrator Accountability
Provides accountability for administrative users with complete policy version history and audit trail.

Report Server Features

Centralized Activity Journal

Report Server aggregates and normalizes activity data from multiple applications and correlates data into a single report view.

Shared Charts and Reports

Allows multiple analysts to work together to create, save and share reports, allowing teams of compliance professionals to review and base decisions on a common set of facts.

Summary and Trend Analysis

View activity and policy enforcement by user, business unit, data class, resource, or policy. Analyze activity or policy enforcement trends over time to discover trends in information risk.

Integration with Incident Management and SIEM

Central Activity Journal is accessible through a set of well defined Web Service interfaces which directly integrate into external incident management tools and SIEM (Security Incident and Event Management).

Activity Reporting

Data activity reporting provides detailed event information for data activity including access, duplication, and use.

Compliance Reporting

Facilitates compliance auditing activity by providing detailed reports on entitlements, authorization decisions, and access attempts by user and resource.

 

 

Learn More

 

Resources

 

Related Links