NAVEX > 实例探究 > Major University with Diverse Requirements Automates Information Security

Major University with Diverse Requirements Automates Information Security

NAVEX Logo
公司规模
1,000+
地区
  • America
国家
  • United States
产品
  • NAVEX IRM
技术栈
  • Vulnerability Management
实施规模
  • Enterprise-wide Deployment
影响指标
  • Digital Expertise
  • Productivity Improvements
技术
  • 网络安全和隐私 - 云安全
适用行业
  • 教育
适用功能
  • 商业运营
用例
  • 网络安全
服务
  • 系统集成
关于客户
The customer in this case study is a major university's biosciences division. This division is large, with 5,000 faculty and staff members spread across 32 departments. Each department has its own IT support and unique cybersecurity requirements. The university is committed to open inquiry and interdisciplinary research, which involves freely sharing information throughout the university, with other institutions, and around the world. This open culture, while beneficial for academic pursuits, introduces significant risk from an information security perspective. The division also has to comply with the Federal Information Security Management Act (FISMA) procedures and controls for protecting government information, operations, and assets.
挑战
The biosciences division of a major university, comprising 5,000 faculty and staff across 32 departments, faced a significant challenge in managing its information security. Each department had its own IT support and unique cybersecurity requirements, creating a siloed environment that hindered the security team's ability to assess the entire IT landscape. This resulted in gaps in security controls, inconsistencies in applying these controls, and duplication of efforts. The university's commitment to open inquiry and interdisciplinary research, which involved freely sharing information, introduced additional risk. The security team also struggled to comply with the Federal Information Security Management Act (FISMA) procedures and controls for protecting government information, operations, and assets.
解决方案
The university division selected NAVEX's governance, risk management, compliance (GRC) platform, NAVEX IRM, for its capabilities in integrated risk management (IRM). NAVEX IRM enables the university to gain a comprehensive view of their business and operations from a risk perspective—connecting individual risk disciplines and managing them in one centralized program. The security team completed some groundwork before implementing NAVEX IRM, which included process mapping, defining roles and responsibilities, classifying and taking inventory of information systems, and defining a process for automating cybersecurity tasks like scanning, prioritizing, assessing, and reporting vulnerabilities. Assets were given a confidentiality, integrity, and availability (CIA) score to determine their importance to the division’s operations. NAVEX IRM automatically performed a Priority Impact Analysis (PIA) on each new vulnerability detected across the IT landscape of 32 departments. The team consulted a heat map on a dashboard showing the PIA score, along with the asset CIA score. As a result, the team could address the most severe vulnerabilities first and manage the entire process more efficiently.
运营影响
  • The security team’s unified approach to vulnerability management was accepted by all 32 departments.
  • Automating scanning and processing activities promoted accountability among departments.
  • Automated notifications and reminders compelled IT custodians to take action to stop notification and prevent escalation.
  • Individual dashboards reported only information that was applicable to each role, empowering stakeholders in managing vulnerabilities and remediation activities.
  • NAVEX IRM automated vulnerability management, making it accurate, accepted, and accountable.
数量效益
  • Response time to address vulnerabilities was reduced by 77%
  • 100% of vulnerabilities were addressed

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。