Comprehensive Reports for Monitoring Configuration and Control

Demo

Take a few minutes to see what Tripwire Enterprise is all about.

Watch now

Solution Brief

On Common Ground: Assure compliance and enhance security.

More >

WEBCAST

Knowledge is Power. Learn more about Tripwire and the industry in person and online.

Register today

EVALUATIONS

Test drive. Try an evaluation version of our software.

Download now

Reports for Improving Compliance

Tripwire Enterprise includes a comprehensive library of reports and online dashboards that can be tailored to any environment and need. They provide valuable performance metrics and trends that help you do everything from show change status and history across the enterprise, to perform forensics on an unauthorized change or intrusion.

Actionable change reporting is essential to configuration control and change automation for providing the necessary information to enforce your change/configuration policies and correlate actual changes with change orders. Tripwire Enterprise includes actionable reports and online dashboards that show change status and history across the enterprise and assist in problem/incident resolution, enabling you to improve repair times and fix inconsistencies across systems thought to be similar.

Use the tabs below to view sample reports most helpful for compliance and security. You may also download the Tripwire Enterprise Report Catalog, with samples of all available reports.



Detailed Waivers
For each specified node and test, this report provides a complete listing of all applicable waivers and related details such as waiver start and end dates, reason for the waiver, and who is responsible for remediation.

Usage: Security and IT operations can use this report to manage waivers and remediation more effectively and with less effort.

Scoring
This report shows the overall compliance pass/fail status of a given environment as well as explicit scoring results for each individual node.

Usage: This report enables management to quickly and easily ascertain the true state of compliance across their IT infrastructure.

Detailed Test Inventory
For each specified test, this report provides a test definition that includes details such as test description, type, severity and weighting.

Usage: This report makes it easy for management to generate and share formal test documentation, as well as view this information offline.

Test Results by Node
For each specified node, this report shows both a summary and a detailed breakdown of the latest test results. The report can also be configured to only display failed tests and associated remediation steps.

Usage: This report functions as a prescriptive "punch list" that system administrators can use to expedite necessary remediation tasks.

Compliance History
This report calculates the number of passing and failing policy test results created for all specified nodes for each specified time interval. It is typically used as a management report showing the historic trend of compliance with a policy.

Detailed Test Results
This report lists all policy results for each specified node that meet the specified report criteria. For each result, the output indicates which element was tested, and the outcome (passed/failed). This report is a means of identifying specific settings that are out of compliance with a policy and that may require modification.

Policy Scorecard
For each specified policy test or policy test group, this report indicates the number and percentage of nodes that are in full compliance with the test (or group), and the number of nodes that are not in full compliance. This is used as a high-level management report providing a comprehensive view of compliance throughout your organization.

Report Linking
Report Link Criteria provides the ability to link certain reports allowing for the ability to "drill-down" or link from a report being viewed to a subsequent report with an increased level of detail. For example, one may want to link from a Change Process Compliance report, to a Changed Elements report for a list of unapproved changes, then to a Detailed Changes report on a particular element.

Baseline Elements Report
Lists details about baseline elements for specified nodes.

Usage: This report satisfies the audit requirement of showing that changes are authorized by reporting all changes promoted to the current baseline, including who made the change, approval IDs, and comments that indicate why the change was approved.

Reference Node Variance Report
This report identifies all elements that differ between one "reference" node and one or more other "compare" nodes.

Usage: This report detects configuration drift. Any changes that are inconsistent across the nodes are flagged and reported.

Change Process Compliance Report
This report identifies authorized and unauthorized changes to specified nodes over a period of time. Authorized changes are recognized by the presence of a third-party reference identifier.

Usage: This management report shows trend in effectiveness of change process controls. A Dashboard of the report shows trends by location or IT service.

Changed Elements
Summary information for each changed element can include the time, type (addition, deletion, and modification), attributes, user, and packages affected by the change. Changes can be grouped by approval identifier so all unauthorized, as well as authorized, changes are immediately visible.

Usage: Identifies the who, what, when and where of changes for compliance reporting. Typically executed on an ad hoc basis as known changes are made, or daily/weekly as a record of changes for that interval.

Change Window
This report indicates the number of detected changes for a specified monitored system(s) that have occurred inside and outside a defined change window.

Usage: Management report showing consistency and enforcement of change management policy to assure system integrity.

User Roles
For a specified node or node group, this report identifies the effective user role for a selected user account. The effective user role is the actual level of control that the user has over the specified node or node group.

Usage: Management report showing who has access to what in the Tripwire Enterprise Server. Typically run monthly, potentially more often depending on process maturity.