For analysts, Vericept has some of the better query functions. These functions allowed me to search by one or more categories
and then hone in on activity for a specific workstation. To create presentation-quality reports or perform deeper data mining,
you need separate software. Vericept has nine Crystal Report templates, which I used with Crystal Report, a third-party application,
to build charts and summarized tables.
As noted, Vericept is more attuned to spotting trends than to generating immediate alerts on every troublesome message. Viewed
in this context, the software meets its design goals. In this part of testing, I distributed the task of reviewing certain
events by creating Workflow Policies and Rules. I assigned an HR user to manage activities such as shopping and game playing
under Acceptable Use policies; a security group employee was responsible for nonpublic personal information such as Social
Security numbers.
On a set schedule (typically each hour), reviewers receive activity reports about their specific compliance area. After scanning
the summaries, auditors can annotate events, reassign the case (even to those who are not Vericept users), or download event
details to their workstation.
In Version 7.1, reviewers can now free-form search the metadata fields. I successfully searched Web mail traffic on a particular
network subnet for messages containing a particular person’s name.
Vericept’s Intelligent Protection Platform 7.1 accurately scans all forms of Internet traffic using predefined categories.
It also offers easy rule customization. The system correctly noted both structured and unstructured proprietary data on the
network.
Moreover, it traces this data back to a user, user name, workstation, or IP address. Users in responsible departments received
alerts and reports, enabling them to manage problem communications without much effort. If you need categories that address
specific compliance legislation or blocking, Vericept isn’t best. But for discovering inside threats before they grow into
serious compliance problems, Vericept gets the job done right.
Vontu 4.0
Vontu 4.0 is a feature-rich data-loss-prevention solution that meets or exceeds each of my test requirements. It accurately
monitors all network traffic; selectively stops confidential data from going outside an enterprise; is easy to manage with
role-based access, even in large deployments; and provides multiple levels of reports to identify risks and demonstrate corporate
and regulatory compliance.
Setting up and configuring the Vontu Manager server, network-inspection Monitors, and inline Prevent component (which directs
MTAs to block, reroute, or quarantine messages based on content), should take about half a day.
Vontu 4.0’s Policy Authoring contributed greatly to this short setup cycle. I used some of 50 prebuilt templates (including
regulatory enforcement, customer data protection, IP, and acceptable use) as the formula for my custom policies. For instance,
it was a snap tuning the Gramm-Leach-Bliley template to look for an exact match of Social Security numbers contained in a
customer database, to block e-mail containing numerous violations, and to create an autoresponse notification for less-serious
infractions. Just as important, I had Vontu 4.0 regularly scan my database for updates; this helped ensure 100 percent accurate
detection of structured data.
Similarly, the clear-cut process enabled me to create from scratch a policy to protect source code based on data matches,
sender, recipient, geographical location, and other parameters.

iLumin Assentor Compliance 3.3
iLumin Software Services, ilumin.com
|
Good 7.8 |
 |
| criteria |
score |
weight |
| Ease-of-use |
8 |
20% |
 |
| Features |
8 |
20% |
 |
| Performance |
7 |
20% |
 |
| Reliability |
8 |
20% |
 |
| Scalability |
8 |
10% |
 |
| Value |
8 |
10% |
 |
|
 |
Cost: Basic Mailbox Management begins at $15 per mailbox
Platforms: Microsoft Windows 2000 Server or Windows Server 2003
Bottom Line: Assentor Compliance scans and archives messages, and helps ensure e-mail follows corporate and regulatory requirements. It
works well with all e-mail platforms, plus it supports IM, Bloomberg, and BondDesk. The UI isn’t pretty, but admins can use
it to quickly adjust message-retention length and other characteristics such as keywords to watch.
|
 |
About our Reviews and Scoring Methodology
|
|

Reconnex iGuard 3300, Version 1.4
Reconnex, reconnex.com
|
Excellent 8.9 |
 |
| criteria |
score |
weight |
| Ease-of-use |
9 |
20% |
 |
| Features |
9 |
20% |
 |
| Performance |
9 |
20% |
 |
| Reliability |
9 |
20% |
 |
| Scalability |
9 |
10% |
 |
| Value |
8 |
10% |
 |
|
 |
Cost: $70,000
Platforms: Proprietary appliances
Bottom Line: iGuard analyzes multiple protocols and content types at network speeds, giving immediate views to insider threats. Users easily
create customizable rules for message monitoring, capture, storage, and data mining. Examiners receive notifications of violations
and effortlessly view the actual content. This system is notable for saving all communications.
|
 |
About our Reviews and Scoring Methodology
|
|

Tablus Content Alarm NW 2.1
Tablus, tablus.com
|
Very Good 8.4 |
 |
| criteria |
score |
weight |
| Ease-of-use |
8 |
20% |
 |
| Features |
8 |
20% |
 |
| Performance |
8 |
20% |
 |
| Reliability |
9 |
20% |
 |
| Scalability |
9 |
10% |
 |
| Value |
9 |
10% |
 |
|
 |
Cost: Starts at $25,000
Platforms: Hardened Linux appliances
Bottom Line: Content Alarm’s distributed, scalable architecture is especially appropriate for global enterprises. A combination of linguistics
analysis, keywords, and signatures initially discover the damaging data. File crawlers accurately classify information and
manage documents through their lifecycle. An encrypted audit log maintains message details.
|
 |
About our Reviews and Scoring Methodology
|
|

Vericept Enterprise Risk Management Platform 7.1
Vericept, vericept.com
|
Very Good 8.5 |
 |
| criteria |
score |
weight |
| Ease-of-use |
9 |
20% |
 |
| Features |
8 |
20% |
 |
| Performance |
8 |
20% |
 |
| Reliability |
9 |
20% |
 |
| Scalability |
9 |
10% |
 |
| Value |
8 |
10% |
 |
|
 |
Cost: Ranges from less than $3,000 to $1,000,000, depending on implementation, number of users, and modules
Platforms: Appliance or licensed application running under Red Hat Enterprise Linux 3.0
Bottom Line: Vericept’s monitoring, reporting, and inquiry tools help spot general data-leak problems; reports verify compliance. Flexibility
is strong, with time-based inspection of inbound and outbound traffic and automatic routing of problematic messages to designated
auditors, but messages aren’t blocked. Managers can either use built-in categories or customize rules.
|
 |
About our Reviews and Scoring Methodology
|
|