<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>NetWrix Blog</title>
	<atom:link href="http://blog.netwrix.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.netwrix.com</link>
	<description>Systems Management and Compliance</description>
	<lastBuildDate>Mon, 30 Jan 2012 13:56:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>NetWrix Change Reporter Suite reviewed by respected Concentrated Technology</title>
		<link>http://blog.netwrix.com/2012/01/30/netwrix-change-reporter-suite-reviewed-by-respected-concentrated-technology/</link>
		<comments>http://blog.netwrix.com/2012/01/30/netwrix-change-reporter-suite-reviewed-by-respected-concentrated-technology/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 13:56:16 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[change auditing]]></category>
		<category><![CDATA[Concentrated Technology]]></category>
		<category><![CDATA[Don Jones]]></category>
		<category><![CDATA[NetWrix CHange Reporter Suite]]></category>
		<category><![CDATA[security auditing software]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1545</guid>
		<description><![CDATA[Recently, the NetWrix Change Reporter Suite received an in depth review by the great team over at Concentrated Technology. Don Jones and company took a close look at our change auditing suite of tools and surveyed numerous IT pros, managers &#8230; <a href="http://blog.netwrix.com/2012/01/30/netwrix-change-reporter-suite-reviewed-by-respected-concentrated-technology/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Recently, the <a href="http://www.netwrix.com/change_auditing_solution.html">NetWrix Change Reporter Suite</a> received <a href="http://library.concentratedtech.com/papers/ProductScope_NetWrix_CRS.pdf" rel="nofollow">an in depth review</a> by the great team over at <a href="http://concentratedtech.com/" rel="nofollow">Concentrated Technology</a>. Don Jones and company took a close look at our change auditing suite of tools and surveyed numerous IT pros, managers and senior executives on our approach to provide a comprehensive outline and summary of our compliance and security auditing software.<br />
<a href="http://blog.netwrix.com/wp-content/uploads/2012/01/approved.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2012/01/approved.jpg" alt="Change Reporter Suite of security auditing software" width="298" height="169" class="alignleft size-full wp-image-1546" /></a><br />
Some of the highlights they identified helped reinforce our beliefs and those decisions that have shaped the product into what it is today and validated our vision for what we want to achieve in upcoming releases. For example, <a href="http://www.netwrix.com/change_auditing_solution.html">Change Reporter Suite</a> covers a <a href="http://www.netwrix.com/pdfviewer.html?product=CRsuite&amp;type=QuickStart">broad array of platforms</a> which helps expand its base of appeal. It also includes archiving at no additional cost which is of great benefit to cost-conscious, regulated organizations that need the long-term history. They also recognized and greatly appreciated that it provided full-functionality with or without agents. Additionally, our <a href="http://www.netwrix.com/auditassurance.html">auditing granularity</a> was cited as a great innovation and benefit to anyone looking for detailed, easy to use audit reports.</p>
<p>We were thrilled with the results and have already absorbed the feedback into our future plans to further improve upon the <a href="http://www.netwrix.com/change_auditing_solution.html">Change Reporter Suite</a>. Specifically, we are looking to implement role based security, more real-time alerts and subscription capabilities as well as incorporating Syslog and other platforms into the product like Oracle and further extending our auditing to SIEM solutions such as BMC Remedy. Have a look at the extensive review on their site.</p>
<p>Let us know what YOU need. Leave us your feedback or tell us what you think is missing from change auditing and security below:</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2012/01/30/netwrix-change-reporter-suite-reviewed-by-respected-concentrated-technology/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What makes using Group Policy so challenging?</title>
		<link>http://blog.netwrix.com/2012/01/23/what-makes-using-group-policy-so-challenging/</link>
		<comments>http://blog.netwrix.com/2012/01/23/what-makes-using-group-policy-so-challenging/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 14:38:36 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[gpo settings]]></category>
		<category><![CDATA[group policy editor]]></category>
		<category><![CDATA[group policy management]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1539</guid>
		<description><![CDATA[Recently on Spiceworks, I shared a handy resource for users interested in Group Policy management. The post was well received by the community and I was quite pleased to have provided it. Basically, it was a TechNet resource called the &#8230; <a href="http://blog.netwrix.com/2012/01/23/what-makes-using-group-policy-so-challenging/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.netwrix.com/wp-content/uploads/2012/01/HelpButton.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2012/01/HelpButton.jpg" alt="GPO Settings" width="200" height="180" class="alignleft size-full wp-image-1541" /></a>Recently on Spiceworks, I <a href="http://community.spiceworks.com/topic/188633-great-tool-for-finding-the-group-policy-setting-you-need?page=1" rel="nofollow">shared a handy resource </a>for users interested in <B>Group Policy management</B>. The post was well received by the community and I was quite pleased to have provided it. Basically, it was a <a href="http://social.technet.microsoft.com/wiki/contents/articles/how-to-find-the-group-policy-you-need.aspx#comment-11774" rel="nofollow">TechNet resource</a> called the <a href="http://gps.cloudapp.net/" rel="nofollow">Group Policy Search Tool</a>. Its purpose is to help you find the desired setting you need in the <B>Group Policy editor</B>. </p>
<p>Without a resource like this, many pointed out that when it comes to using Group Policy, one of the most time-consuming and challenging tasks is simply recalling or locating what setting is needed for the particular task. Group Policy management allows you to control just about every user or machine behavior in your environment. The list of things you can manage with <B>GPO settings</B> is long and likely the primary reason why it’s so difficult to use it effectively unless you <a href="http://www.gpanswers.com/" rel="nofollow">work with it every day</a>. </p>
<p>Most administrators out there juggle multiple responsibilities and know how difficult it can be to acquire a high level of skill in a technology especially one that isn’t used often. Group Policy management can fall into this category. Many GPO settings for objects and behaviors such as <a href="http://social.technet.microsoft.com/Forums/en-US/winserverGP/thread/b3d11cd4-897b-4da1-bae1-f1b69441175b" rel="nofollow">enforcing a password policy</a> and <a href="http://mikecrowley.wordpress.com/2011/02/17/how-to-set-windows-7s-login-wallpaper-with-group-policies/" rel="nofollow">setting default desktop backgrounds</a> are familiar and easily found and understood. Lesser known GPO settings are more like mythical creatures. You’ve <a href="http://technet.microsoft.com/en-us/library/cc749048(WS.10).aspx" rel="nofollow">heard a setting exists</a> yet you can’t say for certain you’ve seen it let alone use it.  </p>
<p>If you need more control over what’s going on in your environment and want to implement change auditing for <B>Group Policy management</B> and <B>GPO settings</B>, take a look at the <a href="http://www.netwrix.com/group_policy_auditing_change_reporting_freeware.html">NetWrix Group Policy Change Reporter</a>. It audits all changes in Group Policy and automatically sends detailed e-mail reports showing who made what changes, when and where as well as before and after information. Furthermore, it can store this data for seven years or more and can generate custom reports.</p>
<p>I hope you visit the links above and get a chance to check out this great free tool to help your <B>Group Policy management</B> tasks. What is your most strange, mythical, mystical or odd <B>Group Policy setting</B> you worked with and how did you use it? Share your stories below and let me know if you found this tool useful too:</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2012/01/23/what-makes-using-group-policy-so-challenging/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Recent Download Poll Suggests IT Spending is on the rise</title>
		<link>http://blog.netwrix.com/2012/01/17/recent-download-poll-suggests-it-spending-is-on-the-rise/</link>
		<comments>http://blog.netwrix.com/2012/01/17/recent-download-poll-suggests-it-spending-is-on-the-rise/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 15:01:26 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[auditing solutions]]></category>
		<category><![CDATA[IT Budgets]]></category>
		<category><![CDATA[IT Spending]]></category>
		<category><![CDATA[software downloads]]></category>
		<category><![CDATA[Software Licensing]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1527</guid>
		<description><![CDATA[In the month of December, we saw one of our most active months for software downloads. Prior to download, a web-based form asks each visitor to choose what motivated them to download the product from a short list of potential &#8230; <a href="http://blog.netwrix.com/2012/01/17/recent-download-poll-suggests-it-spending-is-on-the-rise/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>In the month of December, we saw one of our most active months for software downloads. Prior to download, a web-based form asks each visitor to choose what motivated them to download the product from a short list of potential answers. One such answer common to all software downloads is simply, “Casual Interest/Cannot Disclose”.<br />
<a href="http://blog.netwrix.com/wp-content/uploads/2012/01/it-spending.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2012/01/it-spending.jpg" alt="it spending 2012" width="300" height="175" class="alignleft size-full wp-image-1532" /></a><br />
<BR><br />
Interestingly, more than 60% of our product poll responses this month showed an increase in this answer as compared to last month’s results. The percentage of increases for this particular answer ranged from 4% to more than 22% per product with an average increase of just over 9% per downloaded software installer. You may be asking yourself, “Why didn’t they just choose an answer that best suits their situation?” My answer to that is, with the arrival of 2012, organizations needed to plan in advance for additional software licensing as they are more frequently being accepted as essential to the operation. However, to what extent they are essential may not yet be fully defined hence the increase in “Casual Interest” responses. </p>
<p>When I look at these numbers I also believe they tell a story of <a href="http://www.readwriteweb.com/biz/2011/11/smb-it-budgets-on-the-rise-acc.php" rel="nofollow">recovering IT budgets</a>. New and heightened needs in <a href="http://www.washingtonpost.com/business/capitalbusiness/federal-health-care-it-spending-set-to-grow/2012/01/03/gIQARiOsjP_story.html?tid=pm_business_pop" rel="nofollow">various industries</a> and other <a href="http://www.channelinsider.com/c/a/Spotlight/IT-Spending-2011-Expected-to-Rise-Gartner-706836/" rel="nofollow">economic factors</a> are driving <B>IT spending</B>. While they may not have supplied a more accurate answer, Administrators are few in number and constantly pressed for time. They recognize the need for efficient and cost-effective IT auditing solutions to help them demonstrate regulatory compliance, address important security challenges and simplify day-to-day management tasks. They need constant oversight of their network resources and detection of even the smallest of changes or problems to keep users safe and productive. Information needs to be stored centrally and reported on automatically without all the noise associated with traditional native logging data. While there may be widespread acceptance of these needs, each organization and IT team have different needs and may now be exploring their options through casual trial of various applications that may help them better define their requirements.</p>
<p>Products such as the <a href="http://www.netwrix.com/change_auditing_solution.html">NetWrix Change Reporter Suite</a> are designed to help administrators implement change auditing throughout the enterprise. Managing users can be one of the <a href="http://www.techrepublic.com/blog/security/hitting-windows-8-reset-button-security-bonus-saves-time-and-money/7236?tag=nl.e102" rel="nofollow">most time consuming help desk tasks</a>. With the <a href="http://www.netwrix.com/account_lockout_examiner.html">NetWrix Account Lockout Examiner</a>, IT staff can get users back onto the network and productive quickly. All of our tools are cost-effective and robust while simple to operate and manage. If you need to improve your security and/or meet regulatory requirements, download one of our many free titles to see if they might meet your needs. If you need more features, all products are available in full-featured edition trials as well. </p>
<p>Are you seeing more spending at your organization for 2012? Does this make you more or less likely to investigate new tools to help you manage your environment? Please share your thoughts below.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2012/01/17/recent-download-poll-suggests-it-spending-is-on-the-rise/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TechRepublic names audit logging among top 10 best practices for Windows security</title>
		<link>http://blog.netwrix.com/2012/01/10/techrepublic-names-audit-logging-among-top-10-best-practices-for-windows-security/</link>
		<comments>http://blog.netwrix.com/2012/01/10/techrepublic-names-audit-logging-among-top-10-best-practices-for-windows-security/#comments</comments>
		<pubDate>Tue, 10 Jan 2012 14:01:27 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[audit logging]]></category>
		<category><![CDATA[windows security auditing]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1518</guid>
		<description><![CDATA[TechRepublic recently produced a list of 10 best practices for Windows security. In it was mention of audit logging as a best practice to improve Windows security. They consider Windows auditing challenging because of the vast amounts of raw data &#8230; <a href="http://blog.netwrix.com/2012/01/10/techrepublic-names-audit-logging-among-top-10-best-practices-for-windows-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.netwrix.com/wp-content/uploads/2012/01/needle-haystack.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2012/01/needle-haystack.jpg" alt="Windows Audit Log Detail" width="121" height="181" class="alignleft size-full wp-image-1519" /></a>TechRepublic recently produced a list of <a href="http://www.techrepublic.com/blog/10things/10-best-practices-for-windows-security/2383" rel="nofollow">10 best practices for Windows security</a>. In it was mention of audit logging as a best practice to improve Windows security. They consider <a href="http://www.winvistatips.com/security-log-size-pdc-problem-t808741.html" rel="nofollow">Windows auditing challenging</a> because of the vast amounts of raw data that typically is produced.</p>
<p>If <a href="http://social.technet.microsoft.com/Forums/en/winserversecurity/thread/f58962a2-3f0a-4d3c-a2af-75b10b9753b3" rel="nofollow">too much logging</a> occurs, it makes the value next to nothing and more like searching for <B>a needle in a haystack</B>. There’s also the risk of logs being overwritten if they aren’t set to handle all the events. It’s essential to know what is necessary and only audit those changes instead of using a broad approach hoping critical problems will jump out at you. Trying to keep up with all the native security data each day is nearly impossible without the proper resources. But what if you aren’t ready or able to commit to only a few aspects and need a broader overview? This is where you need the help of a tool that can automatically gather all the logs, remove unnecessary noise and produce readable reports in plain language you can understand.</p>
<p>Fact is, organizations that implement audit logging are far less at risk of a security or compliance problem than without even if they may be unsure at the outset what is and isn’t important. With <a href="http://www.netwrix.com/change_auditing_solution.html">NetWrix Change Reporter Suite</a>, you can audit effectively and easily without the massive volumes of raw data and monitor changes that are important. In addition to Windows Servers, this solution audits changes to Active Directory, Group Policy, Exchange, SQL, SharePoint, VMware, EMC, NetApp, File Servers, Network Devices such as Cisco firewalls and more. It shows who made what change, when and where as well as many before and after settings in easy-to-read reports. It scales to environments large or small, sets up quickly and is cost-effective. </p>
<p>Have you tried Windows security auditing on your own successfully (be honest!)? What were the results? How more/less effective were you at maintaining Windows security before/after implementing a procedure to audit your environment or more specifically, your Windows systems? Please share your experiences, thoughts and comments below:</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2012/01/10/techrepublic-names-audit-logging-among-top-10-best-practices-for-windows-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The ABCs of Security and Compliance</title>
		<link>http://blog.netwrix.com/2012/01/03/the-abcs-of-security-and-compliance/</link>
		<comments>http://blog.netwrix.com/2012/01/03/the-abcs-of-security-and-compliance/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 13:15:40 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[improving network security]]></category>
		<category><![CDATA[security auditing]]></category>
		<category><![CDATA[security concepts]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1511</guid>
		<description><![CDATA[Understanding Security and Compliance is as easy as ABC: Access, Breaches and Changes. At a distance security and compliance share many similarities. As you get into the details, what you’ll find is that their implementation differs though the steps to &#8230; <a href="http://blog.netwrix.com/2012/01/03/the-abcs-of-security-and-compliance/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.netwrix.com/wp-content/uploads/2012/01/ABC.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2012/01/ABC.jpg" alt="ABCs of Security and Compliance" width="254" height="238" class="alignleft size-full wp-image-1512" /></a>Understanding Security and Compliance is as easy as ABC: <b>Access, Breaches</b> and <b>Changes</b>. At a distance security and compliance share many similarities. As you get into the details, what you’ll find is that their implementation differs though the steps to achieve end result (Secure and Compliant) may achieve both.</p>
<p><b>(A)	Access</b> control to the network resources is the most important role for IT. Granting, denying, monitoring all involved some form of privileged and systemic action to meet the needs of your end users. You will want to see who has access to what in <a href="http://www.netwrix.com/active_directory_snapshot_reporting.html">snapshot reports</a> of your environment including what access did users have previously as compared to the current state. For example, who has access to this folder now and who had access to it 6 months ago. </p>
<p><b>(B)	Breaches</b> are your virtual border crossings of information and access. For security and compliance, you need to report when users do something in case it is incorrect or damaging. Because of network complexity and existing rights that may not suit the users roles, you need to monitor who breaches data and resources using their granted permissions and rights. Just because a user has a right or permission does not mean they should be exercising it. You need detailed <a href="http://www.netwrix.com/file_access_auditing.html#security">access reports</a> on all uses of permissions both failed and successful throughout the environment. </p>
<p><b>(C)	Changes</b> are your worst enemy when it comes to meeting security and compliance objectives. You need <b>change auditing</b> to uncover the details of each change including who changed what permission and when on files, Active Directory OUs, SharePoint sites, SQL databases and so on.  Knowing who changed <b>what security groups</b> and when, and even who changed the security policy to retain logs from 30 days to 2 helps sustain compliance and improve security. Do this <a href="http://www.netwrix.com/change_auditing_solution.html">change auditing</a> task on a regular basis and you are simultaneously improving both security and demonstrating compliance.  </p>
<p>Access, breaches and changes are your three ABCs to meeting your security and compliance goals. This is an ongoing activity of producing <b>snapshot reports</b>, <a href="http://www.netwrix.com/file_access_auditing.html#security">access reports</a> and <b>change auditing</b> must be performed daily if not very frequently in order to be successful at these two objectives. NetWrix provides the <a href="http://www.netwrix.com/change_auditing_solution.html">Change Reporter Suite</a> for your compliance and security ABCs simply and easily. Using <a href="http://www.netwrix.com/auditassurance.html">AuditAssurance™</a> and AuditIntelligence™ technologies, data is complete and accurate extracted from multiple sources, stored as single records and reported daily (or more frequently) to show your access, breaches and changes throughout the network. </p>
<p>Are you already following the ABCs of Security and Compliance or do you have your own simple approach to conceptualizing meeting your security and compliance goals?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2012/01/03/the-abcs-of-security-and-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Letter to Customers from NetWrix CEO</title>
		<link>http://blog.netwrix.com/2011/12/27/letter-to-customers-from-netwrix-ceo/</link>
		<comments>http://blog.netwrix.com/2011/12/27/letter-to-customers-from-netwrix-ceo/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 19:13:13 +0000</pubDate>
		<dc:creator>Michael Fimin</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1494</guid>
		<description><![CDATA[Dear Customers, as 2012 approaches, I want to extend my best wishes to you, your family and your colleagues for a healthy and Happy New Year. <a href="http://blog.netwrix.com/2011/12/27/letter-to-customers-from-netwrix-ceo/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Dear Customers,</p>
<p>As 2012 approaches, I want to extend my best wishes to you, your family and your colleagues for a healthy and Happy New Year. Thanks to your continued support, 2011 has been the best year yet exceeding even our own expectations. We have continued to grow in all directions: technology innovation, sales, customer service, regional support. And we look forward to another successful year of win-win partnership between you and NetWrix.</p>
<p>NetWrix prides itself on its relationship with its customers and that includes maintaining open communications with NetWrix senior management.  So please feel free to contact me personally about anything at any time &#8211; reply to this post or connect with me on <a href="http://www.linkedin.com/in/michaelfimin" target="_blank">LinkedIn</a>.</p>
<p>Thank you for being our valued customer!</p>
<p>Warmest Regards,</p>
<p>Michael Fimin<br />
CEO and President<br />
NetWrix Corporation</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2011/12/27/letter-to-customers-from-netwrix-ceo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Three Simple Concepts to Improving Network Security</title>
		<link>http://blog.netwrix.com/2011/12/27/three-simple-concepts-to-improving-network-security/</link>
		<comments>http://blog.netwrix.com/2011/12/27/three-simple-concepts-to-improving-network-security/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 15:11:08 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[improving network security]]></category>
		<category><![CDATA[security auditing]]></category>
		<category><![CDATA[securtiy concepts]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1468</guid>
		<description><![CDATA[Security means different things to different people. For IT, it means securing the network from external intruders and protecting valuable data from prying eyes internally. Since the dawn of the information age, readily available information has come with a price. &#8230; <a href="http://blog.netwrix.com/2011/12/27/three-simple-concepts-to-improving-network-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Security means different things to different people. For IT, it means securing the network from external intruders and protecting valuable data from prying eyes internally. Since the dawn of the information age, readily available information has come with a price. Securing information in our interconnected world is not always as easy as putting a lock on the virtual door. There is an entire world filled with all kinds of people having <a href="http://federalcrimesblog.com/2011/07/05/jason-cornish-charged-in-a-criminal-complaint-with-allegedly-knowingly-transmitting-computer-code-with-the-intent-to-damage-computers-in-interstate-commerce/" rel="nofollow">varying motivations</a>. Time and again we see headlines of intrusions wreaking havoc. Those responsible for security auditing scramble to provide answers and plug the holes. Here I’ll discuss three simple security concepts you must know and integrate into your technical consciousness.<br />
<a href="http://blog.netwrix.com/wp-content/uploads/2011/12/info_age.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2011/12/info_age-300x225.jpg" alt="info security basics" width="300" height="225" class="alignleft size-medium wp-image-1470" style="padding:3px" /></a><br />
<B>Control Access:</B> Use password policies to keep users honest and secure machines so passersby can’t sit down and rewrite the company financials for the past quarter. You need to know who’s accessing your network including who is successful and who’s not and from where. <a href="http://blog.deurainfosec.com/defense-in-depth-and-network-segmentation" rel="nofollow">Segregate information</a> on the network such that you can implement tighter controls over your more valuable assets. As simple as it sounds, lock your server room or data center. Require people to sign-in and out for access. Require identification. Lock servers and configure them to all logout after a period of inactivity. <a href="http://www.asisonline.org/certification/psp/pspabout.xml" rel="nofollow">Physical security</a> is widely overlooked and the simplest measure to implement. If you have a dispersed network of locations and mobile users, this information needs to be automatically logged and centrally stored so it can be reviewed on an ongoing basis. Find a tool that will let you do this easily and quickly.</p>
<p><B>Determine what is at risk:</B> Document not only where the outside meets the inside, but also internal network segmentation and structural topology. These will be the points where you will want to carefully watch who is attempting to come in, from where and using what services. Document what’s accessible from the outside as well as what can be accessed between the internal borders of your network. Eliminate or manage through auditing your entry and exit points. Look for ways to close off ports that are unnecessary and retire old systems where possible. Make documentation a top-3 or top-5 priority. If you share responsibilities with other administrators, teams or subordinates, it’s time to get everyone on the same page and make network security a cultural priority. </p>
<p><B>Know your 4Ws:</B> Changes are the single most important thing to be aware of. Know who is changing what, when and where. By detecting and reporting on changes, you are in a far greater position than someone waiting for the phone to ring or that e-mail to tell you there’s a problem. Most who will do harm or steal information want to do so as silently as possible. Reporting on changes provides greater visibility into the day-to-day activities in your environment and keeps everyone more honest and accountable.</p>
<p>Your responsibility is to implement standards and controls for users and systems, understand what is at risk and what changes are taking place each day while. At NetWrix, we provide change auditing solutions for the enterprise focusing on robust, easy-to-use and affordable software solutions. Our products detect changes on Active Directory, Group Policy, Exchange, SQL, File servers and appliances, VMware, Server Configurations, Event Logs, Password Management, User Management and a wide variety of tools for other areas aimed at securing your environment such as our USB blocker. Our widespread use of snapshot reporting gives you immediate visibility into who has access and to what. Many of these products are packaged as suites, such as our <a href="http://www.netwrix.com/change_auditing_solution.html">Change Reporter Suite</a> that includes a number of our products bundled together to address a wide variety of needs. </p>
<p>What are you doing to secure your environment? Do you have your own set of basic principles for security? Share your thoughts below:</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2011/12/27/three-simple-concepts-to-improving-network-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetWrix Change Reporter Suite &#8211; Voted WindowSecurity.com Readers&#8217; Choice Award Winner</title>
		<link>http://blog.netwrix.com/2011/12/23/netwrix-change-reporter-suite-voted-windowsecurity-com-readers-choice-award-winner/</link>
		<comments>http://blog.netwrix.com/2011/12/23/netwrix-change-reporter-suite-voted-windowsecurity-com-readers-choice-award-winner/#comments</comments>
		<pubDate>Fri, 23 Dec 2011 17:39:22 +0000</pubDate>
		<dc:creator>Daniel Pershing</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[awards]]></category>
		<category><![CDATA[change auditing software]]></category>
		<category><![CDATA[change reporter]]></category>
		<category><![CDATA[Change Reporter Suite]]></category>
		<category><![CDATA[Readers' Choice Awards]]></category>
		<category><![CDATA[winner]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1477</guid>
		<description><![CDATA[We are pleased to announce that NetWrix has just been honored with another great award &#8211; this time thanks to WindowSecurity.com readers &#8211; making it the 17th award within the two-month period. NetWrix Change Reporter Suite was selected the winner &#8230; <a href="http://blog.netwrix.com/2011/12/23/netwrix-change-reporter-suite-voted-windowsecurity-com-readers-choice-award-winner/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>We are pleased to announce that NetWrix has just been honored with another great award &#8211; this time thanks to WindowSecurity.com readers &#8211; making it the 17th award within the two-month period.</p>
<p><a href="http://www.netwrix.com/change_auditing_solution.html" target="_blank">NetWrix Change Reporter Suite</a> was selected the winner in the Network Auditing Software category of the WindowSecurity.com Readers&#8217; Choice Awards. GFI LANguard and Admin Report Kit for Windows Enterprise (ARKWE) were runner-up and second runner-up respectively.<a href="http://blog.netwrix.com/wp-content/uploads/2011/12/Windows-Security-Readers-Choice1.jpg"><img class="size-full wp-image-1480 aligncenter" src="http://blog.netwrix.com/wp-content/uploads/2011/12/Windows-Security-Readers-Choice1.jpg" alt="NetWrix Change Reporter Suite wins getting impressive 26% of all votess" width="454" height="313" /></a>&#8220;Our Readers’ Choice Awards give visitors to our site the opportunity  to vote for the products they view as the very best in their respective  category,” said Sean Buttigieg, WindowSecurity.com manager.  “WindowSecurity.com users are specialists in their field who encounter  various network security solutions at the workplace. The award serves as  a mark of excellence, providing the ultimate recognition from peers  within the industry.”</p>
<p>WindowSecurity.com<em> </em>conducts monthly polls to discover which  product is preferred by Network Security administrators in a particular  category of third party network security solutions. The awards draw a  huge response per category and are based entirely on the visitors’  votes.</p>
<p>Just about a month before getting this honor NetWrix VMware Change Reporter won a <a title="Virtualization Award 2011" href="http://blog.netwrix.com/2011/12/06/netwrix-vmware-change-reporter-wins-a-virtualizationadmin-com-readers-choice-award-november-2011/" target="_blank">VirtualizationAdmin.com Readers Choice Award</a> which made it a second important award from TechGenix Media &#8211; one of the largest providers of free high quality technical content to IT professionals all over the World.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2011/12/23/netwrix-change-reporter-suite-voted-windowsecurity-com-readers-choice-award-winner/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why do some IT pros dislike Facebook?</title>
		<link>http://blog.netwrix.com/2011/12/19/why-do-some-it-pros-dislike-facebook/</link>
		<comments>http://blog.netwrix.com/2011/12/19/why-do-some-it-pros-dislike-facebook/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 14:07:08 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[group settings on Facebook]]></category>
		<category><![CDATA[IT Auditing]]></category>
		<category><![CDATA[IT Pros]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1444</guid>
		<description><![CDATA[Recently on Spiceworks, I posted an announcement about a new Facebook group to discuss IT Auditing, Compliance, Security, and Forensics. I did not expect some of the negative responses I received. Some IT pros don’t like Facebook, though, I should &#8230; <a href="http://blog.netwrix.com/2011/12/19/why-do-some-it-pros-dislike-facebook/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Recently on Spiceworks, I <a href="http://community.spiceworks.com/topic/173927-new-facebook-group-on-it-auditing-compliance-security-and-forensics" rel="nofollow">posted an announcement</a> about a new Facebook group to discuss <a href="http://www.facebook.com/groups/itfacs" rel="nofollow">IT Auditing, Compliance, Security, and Forensics</a>. I did not expect some of the negative responses I received. Some IT pros don’t like Facebook, though, I should clarify. </p>
<p><a href="http://blog.netwrix.com/wp-content/uploads/2011/12/fb.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2011/12/fb-300x113.jpg" alt="Facebook" width="300" height="113" class="alignleft size-medium wp-image-1445" style="padding:4px" /></a><br />
Many of the responses could be grouped into two categories. The first group said that Facebook was for personal things and not well suited for business or technical discussion. The second group felt that because Facebook has a <a href="http://www.nytimes.com/2010/05/06/technology/internet/06facebook.html">well documented history of security and privacy problems</a>, using it to host a group on security topics might be like having former ENRON executives give lectures on business ethics.</p>
<p>Both groups make a fair point. Facebook is most commonly for personal things that you share among friends and other people close to you in some way. Facebook does have a history of security problems and in principal, I see their point. I don’t entirely agree or disagree with these two positions.</p>
<p>How you use Facebook is a personal matter. I know of many professionals (including myself) that happily incorporate personal friends and business relationships via Facebook. There’s so much value in Facebook at so many different levels, I and millions of others are willing to accept the responsibilities that come with having an account in return for what it has to offer. Some in the post did state that it is a matter of personal preference and what you are comfortable with. If you would like to control interaction between personal, professional and other friends on Facebook, see this <a href="http://sociability.ca/blog/facebook-friends-business/" rel="nofollow">helpful post</a> on how to do that.</p>
<p>Security is an entirely other matter. To not use Facebook for discussions could be a huge mistake because of the size of the audience. If you want to participate and benefit from a group, joining one on Facebook opens up the possibility of millions of potential contributors. There are risks and having the ability to moderate and establish guidelines is important. Here’s a <a href="http://www.it.cornell.edu/policies/socialnetworking/facebook.cfm" rel="nofollow">great article</a> on IT and Facebook responsibilities. Note that in <a href="http://www.facebook.com/help/groups/basics" rel="nofollow">group settings</a> on Facebook, you do not need to be friends with someone to be part of a group. While there are many examples of groups gone bad because of a few, again, I would argue it’s an acceptable risk to see where it goes and hope that people will contribute constructively and be decent to one another. </p>
<p>From IT and non-IT perspectives, tell me if this is going to crash and burn or if you think it has an opportunity to thrive? Do you have any opinions on why not to start or join a group on Facebook? Is it time to let the individual decide if they can be responsible enough to have a Facebook account and can personal and professional worlds intermingle successfully?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2011/12/19/why-do-some-it-pros-dislike-facebook/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>NetWrix announces the Bulk Password Reset  full-featured edition is now available for Free</title>
		<link>http://blog.netwrix.com/2011/12/15/netwrix-announces-the-bulk-password-reset-full-featured-edition-is-now-available-for-free/</link>
		<comments>http://blog.netwrix.com/2011/12/15/netwrix-announces-the-bulk-password-reset-full-featured-edition-is-now-available-for-free/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 15:08:12 +0000</pubDate>
		<dc:creator>Chris Rich</dc:creator>
				<category><![CDATA[Freeware]]></category>
		<category><![CDATA[New Releases]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[bulk password reset tool free]]></category>
		<category><![CDATA[privileged account management]]></category>
		<category><![CDATA[reset bulk admin passwords]]></category>

		<guid isPermaLink="false">http://blog.netwrix.com/?p=1457</guid>
		<description><![CDATA[As of today, our full-featured edition of the Bulk Password Reset tool is now totally 100% free including all the standard edition features not found in the previous freeware version. Use it as you wish up to 1 million users. &#8230; <a href="http://blog.netwrix.com/2011/12/15/netwrix-announces-the-bulk-password-reset-full-featured-edition-is-now-available-for-free/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>As of today, our full-featured edition of the <a href="http://www.netwrix.com/local_admin_bulk_password_reset_freeware.html">Bulk Password Reset</a> tool is now totally 100% free including all the standard edition features not found in the previous freeware version. Use it as you wish up to 1 million users. <B>The License code is provided on the download page</B> after a brief registration. We are very excited to offer this tool for free to anyone who can make use of it and it should be especially helpful to those environments that need a one-time mass-reset of local passwords on multiple systems including the local Administrator account. This is often found in environments that have seen many stale, unused or unknown local accounts and need to do this for security purposes.<br />
<a href="http://blog.netwrix.com/wp-content/uploads/2011/12/free_software.jpg"><img src="http://blog.netwrix.com/wp-content/uploads/2011/12/free_software.jpg" alt="Free bulk password reset software" width="252" height="200" class="alignleft size-full wp-image-1458" /></a><br />
Too often, accounts left unattended are hacked and used for malicious purposes. Resetting passwords in bulk is a great way to reset your primary defense when it comes to these idle local accounts. Some notable features that are now included for free that previously required a paid license: </p>
<p>•	Reset passwords on all local accounts.<br />
•	Enable or disable local accounts.<br />
•	Re-processing of password reset attempts both automatic and manual if for example, the host system were powered off during the first or previous attempts.<br />
•	Scheduled processing of password resets including multiple retries.<br />
•	Ability to specify alternate account credentials for network access.<br />
•	Support for workgroup environments (non-domain) via alternate account access.<br />
•	Specify systems individually, by Domain, or select the entire organization.<br />
•	Specify systems by text file.</p>
<table width="100%">
<tr>
<td align="center">
<table style="height: 50px" width="200">
<tbody>
<tr>
<td width="35px"></td>
<td><a class="btn" href="http://www.netwrix.com/requestd.html?product=bpr">Download now</a></td>
</tr>
</tbody>
</table>
</td>
</tr>
</table>
<p>With just a few mouse clicks, you can reset all your local user and Administrator accounts on multiple machines at once. Please also have a look at our <a href="http://www.netwrix.com/privileged_identity_management.html">Privileged Account Manager</a> for managing of Administrative accounts without having to store logins and passwords in unsecured spreadsheets and text files and also to track who used what admin accounts and when. </p>
<p>What are you doing now to prevent unauthorized account usage on your systems? Have you experienced security problems when local accounts are accessed fraudulently? Please share your thoughts and experiences below:</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.netwrix.com/2011/12/15/netwrix-announces-the-bulk-password-reset-full-featured-edition-is-now-available-for-free/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

