
Security Governance System Case Study

An international pharmaceutical company has integrated Flexeye SGS into its infrastructure to monitor the effectiveness of 25 security controls (e.g. patch status, password lengths and virus protection definitions) on over 100,000 PCs and servers.
Information about the status of assets is automatically collected on a daily basis from key security management systems and then mapped onto a model of the organisation. Personalised navigable world views of this information are calculated for over 700 people with some level of risk ownership, to allow them to instantly see an up to date view of the compliance of each system they are responsible for and navigate from a high level to a low level.
The System supports the management of workflow around risk acceptance, risk exception and risk remediation. It also allows the company to assess the effectiveness of the company's outsourced IT solution provider against SLAs and compliance levels.
The System has driven substantially higher standards of security, and allowed the company to redeploy 14 employees who had previously been involved with reporting on compliance for SOX 404.
back