Feature
|
Function |
Benefit |
| Whitelist |
Assign permissions for authorized applications to users or user groups, and by default those not authorized are not allowed |
Eliminates unknown or unwanted applications in your network, reducing the risk of malware and spyware and ultimately improving network stability |
| Standard File Definitions |
Classified, pre-loaded whitelist of all supported OS files |
Speeds and simplifies whitelist definition |
| Automated Application Discovery |
Process of identifying, categorizing and authorizing applications which produces a record of all executables on client computers, file servers and/or local directories |
Provides flexible and fast options to create or update whitelists |
| Automatic Authorization of Software Updates |
Automatic authorization of Microsoft software updates through integration with Windows Updates: SUS and WSUS |
Eliminates risk of accidentally restricting user access to frequently updated Microsoft applications |
Script / Macro Protection |
Controls the execution of specific VBScript, Microsoft Office VBA and JavaScript with central authorization or a prompt to local users |
Extends application policy enforcement to include specific scripts/macros, enabling business without compromising protection |
| Path Protection |
Optional file authorization based on location or path rules; Create a trusted owner, such as administrator, to reinforce security |
Provides flexibility to support executable files for which hash definitions are not useful or applicable (i.e. auto-changing .exe files) |
| Non-Blocking Mode |
Execute and log activity for administrator review |
Enables Lumension Controls to identify current state before defining and enforcing policy |
| Flexible File Authorization |
Versatile File Processor (FileTool.exe) enables directory and subdirectory scans to discover new applications and packages while online or offline |
Provides flexible and fast option to identify new and updated applications for review and ultimately to generate whitelists |
| Nested Executable File Groups |
Hierarchical structure of organizing file groups |
Provides fast administration of file groups and assignment of user permissions |
| Relaxed Logon |
Executes logon scripts without authorization and automatically switches system into blocking mode after either a set of time or at the end of the script |
Eliminates need to administer logon scripts in Lumension Controls without compromising the security of the system |
| Local Authorization/td>
| Trusted users can authorize applications locally, while maintaining a log for administrator review |
Delivers flexibility to the user, without giving up administrative control |
| Spread Check |
Disables suspicious executables that are locally authorized on too many computers |
Contains risk of malicious code spreading through network due to local authorization |
| Highly Scalable Architecture |
Three tier architecture with Database, one or more Application servers, and Client |
Provides flexible and scalable deployment options in large and complex networks |
| Powerful Log Analysis and Reporting |
Detailed log analysis with flexible filter, sort and display options and stored query templates as well as central reporting |
Demonstrates policy compliance and drills down on suspicious behavior for legal or management follow up |
| Offline Computer Protection |
Local copy of updated hashes and permissions is kept on each machine |
Ensures that remote/ disconnected users are constantly protected |
| Active Directory and eDirectory Support |
Leverages user and user group definitions in existing Active Directory and eDirectory |
Reduces setup and maintenance of users and user groups |
| Multi-Language Support |
Supports 12 languages on Lumension Controls client machines |
Improves user experience in international organizations |
| Custom Reports |
Custom query templates can be scheduled to automatically generate reports in HTML, XML or CSV formats and delivered via email or network file share |
Extends application policy enforcement to include specific scripts/macros, enabling business without compromising protection |