C5 Enterprise Vulnerability Management
SECURE ELEMENTS INC. 
Novell Technology Partner
product details
C5 EVM determines the applicable risk levels for each enterprise asset including:
- Quantifying the value of a network asset to the enterprise
- Applying control requirements of government regulations, industry best practices, and/or enterprise policies to an organization's network assets
- Defining high-level rules and guidelines down to specific steps, both manual and automated
- Identifying and remediating or mitigating vulnerabilities associated with an enterprise's assets, which includes automatically applying controls, patches, countermeasures and configuration changes over potentially vulnerable points in an environment
The Architecture
C5 EVM consists of a secure sensor/server architecture. C5 EVM provides an asset control and decision-processing framework for implementation of automated responses to security incidents. All automated actions are based on policy templates or user-defined policies that are the basis for assessing, monitoring and responding to security incidents and vulnerabilities. Tasks such as deep asset inventories, patch management, configuration management, attribute monitoring and audit logging for network and system administration are implemented as needed to support the security centric mission of the Security Administrator.
Control Across All Network Assets
C5 EVM identifies, uniquely watermarks and assigns a priority to all network assets. Priorities are assigned based on asset function and operator input to incorporate business critical dependencies. Each asset has a series of attributes that are used in data correlation, policy enforcement, and incident response activities.
Automated, Real-Time Policy Management
C5 EVM allows the operator to import industry Best Practice policy templates as well as create unique policies for individual assets, groups of assets, or asset categories for implementing business critical security procedures.
Depending on the response policy and asset criticality determined by each security administrator, actions are either recommended or automatically implemented when vulnerabilities or policy violations occur. Secure Elements monitors all major threat intelligence sources including CERT and leading commercial threat intelligence vendors. In addition, the C5 EVM Security Adapters provide an out-of-the-box capability to provide a policy-based response for vulnerability scanners including eEye, FoundStone, Harris Stat, ISS, nCircle, Nessus, Tenable, as well as IDS and IPS products.
Remediation Across the Enterprise
C5 EVM responds to incidents in several ways depending on the severity of the security breach, the criticality of the attacked asset and whether security patches and other automated remediation strategies are available. C5 EVM can employ hundreds of tactics, to include:
- Security patch installation or removal
- Configuration modification or rollback
- Start or stop services
- Modification of account privilege
- File management
- System reboot
- Registry key modification
- DLL modification or removal
product compatibility
- Novell Linux Desktop 9
- SUSE Linux Enterprise Server
- Novell Linux Point of Service
architecture
- x86
- x86_64 AMD64® & Intel® EM64T®
quick clicks
regional availability
- Asia Pacific
- Europe, Middle East & Africa
- Japan
- Latin America
- North America
language availability
- English
Novell does not warrant non-Novell products or services. All products and services included in the Novell Partner Product Guide are provided on an "as-is" basis, and in no event shall Novell be liable for any damages whatsoever resulting from use or performance of any such products or services. Any warranty service for non-Novell products or services is provided by the product vendor in accordance with the applicable vendor warranty. The information and related graphics published in the Novell Partner Product Guide may include technical inaccuracies or typographical errors. Novell assumes no responsibility for the content of any site linked to its Web pages. Inclusion of third-party products or services in the Novell Partner Product Guide does not constitute an endorsement of such products or services by Novell.
