C5 Compliance Platform - Overview
C5 Element Manager
The C5 Element Manager is the server that acts as a centralized manager of the element sensors and as a decision support and reporting system. Delivered as a industry-standard Intel-based 1U server, with a hardened operating system and embedded database, that can be installed in minutes.
C5 Element Sensors
The C5 Element Sensors are lightweight software agents that have an extremely small memory footprint and a very low-impact processor utilization design. Available for workstation and server platforms running Windows, Linux, and UNIX, and is portable to any platform that can support a JVM or Windows .Net CLR environment.
The element sensors are responsible for continuous monitoring of hosts and reporting element survey results back to the element manager on a scheduled basis. In addition, the element sensors can perform actions - on demand - for auditing IS controls and configurations, evaluating asset policy conformance, assessing the host for vulnerabilities, or remediating and enforcing actions.
C5 Command Center
The C5 Command Center supports unified views of your compliance posture, with support for many activities such as scheduling asset discovery scans, policy development and enforcement, IS control auditing, vulnerability assessment and remediation, asset inventory, user/role management, and 360 reporting and analysis. The 360 reporting and analysis capability, as well as IS control auditing and vulnerability assessment capabilities, are also available via web browsers.

C5 Compliance Content
The C5 Security Labs are staffed by highly skilled Information Security Engineers. A best practice for any information security program is to monitor for relevant information security threats so that you can adjust your defenses as required.
The C5 Security Lab publishes the C5 Alert Service, an RSS based threat notification service that includes severity of threat and recommended mitigation actions. Since were monitoring sources for new threats and vulnerabilities 24x7, you can be assured that youll get the information you need most - when you really need it!
In addition, this team maintains one of the largest standards-based library of rules and actions for compliance and vulnerability management. This library, maintained as XML content, is updated on a daily basis, and tested and validated within the C5 Compliance Platform prior to publishing. If updates are required such as a vendor publishing a revised security patch our engineers make the update and publish as part of the customers subscription service.
These feeds include content for:
-
Audit rules system configuration checks and interrogatories
-
Vulnerability checks software vulnerabilities
-
Asset-based policy enforcement actions
-
OS and application remediations
-
Industry, regulatory, and best practice templates NIST SCAP, FISMA, ISO 17799, SOX, GLBA, HIPAA
-
Patch, configuration, and policy content
C5 Compliance Platform - Overview C5 Compliance Platform - Benefits |