C5 Compliance Platform - Overview
How it works - standards based XML Content Subscriptions from our Security Lab
Our Security Lab is staffed by highly skilled Information Security Engineers. They are supported by an automated system that performs 24 X 7 electronic monitoring of numerous security feeds and sources so you don't have to.
They create and publish XML content feeds in industry standard XML formats (OVAL, XCCDF)with industry standard enumerations and scoring (CPE, CCE, CVE, CVSS) for automatic delivery to the customer site. These feeds include content for the following:
- Compliance & Vulnerability Checks
- Industry, regulatory and best practice templates & checklists
- NIST SCAP checklists
- OS and Application Remediations
- Patch, Configuration, & Policy Content
C5 Element Manager
The C5 Element Manager is the server that acts as a centralized manager of the element sensors, and serves as a decision support and reporting system. The C5 Element Manager is typically delivered as a turnkey appliance on industry-standard Intel-based 1U server that can be installed in minutes. The Element Manager also serves to compile the XML content into actionable code delivered via web services to the C5 Element Sensors. This architecture minimizes impact to both hosts and network traffic, works across NAT'd firewalls, and delivers enterprise class scalability for on demand and continuous host-based compliance and vulnerability scans.
C5 Element Sensors
The C5 Element Sensors are lightweight software agents that have an extremely small memory footprint - less than 500KB - and a very low-impact processor utilization design.
Available for workstation and server platforms running Windows (as a native .NET component) and Linux/UNIX (as a native java component). The sensors are responsible for continuous monitoring of hosts and reporting survey results back to the element manager on a scheduled basis. In addition, the element sensors can perform actions - on demand - for auditing IS controls and configurations, evaluating asset policy conformance, assessing the host for vulnerabilities, or performing remediation or enforcement actions.
C5 Command Center
The C5 Command Center includes both Administrative Console for many activities such as policy development, vulnerability remediation, scheduling asset discovery scans, asset inventory, and RBAC-based user/role management. In addition, it includes components that are available within the console for 360 reporting and analysis, and for IS control auditing and vulnerability assessment.
C5 Adapters
The C5 Adapters are data adapters for importing from sources such as XML, CSV, or native vendor data formats. Typically the data is imported from network vulnerability scanners, asset inventory or discovery systems, enabling out of the box integration and setup with your existing tools and processes for vulnerability and asset management. This also enables the ability to manage vulnerabilities from all the tools your organization may use, in addition to our host based vulnerability assessment capabilities, providing a single view for compliance and remediation tracking.
C5 Compliance Platform C5 Compliance Plaftorm - Benefits |