Computer hardware, software, and connections are required for computing. A technical system audit includes a detailed inventory of all computer hardware, software, and systems (processes). SysAuditor provides a standard method for capturing and documenting systems, identifying and defining a system and its components.
Until now, system auditing has been a costly task requiring time, manpower, technical expertise, tools, and wizardry.
SPDX is an open standard system of software components supporting a range of risk management use cases. SysAuditor is a framework that utilizes SPDX components data for business and technical operations.
System auditing is important for financial and business compliance. SysAuditor is an easy-to-use and practical tool suite to save money and reduce risk.
It is simple:
Capture data to create an inventory
Amalgamate data inventories
Analyse data use as part of operations
The SysAuditor tool set automates the collection, amalgamation, and analysis of a computing environment, including containers, system changes, and vital system parameters. The collection tools gather detailed hardware information (chips, memory, buses, etc.), and software drivers associated with hardware components are linked and captured. Operating system (OS) details, versions, licensing, and related information is important for any audit. Processes, connectivity, and numerous other data elements are captured and inventoried for later analysis.
The SysAuditor is an operational set of tools designed to capture and utilize metadata related to systems, processes, and operations to build a comprehensive picture of IT organizations, applications, and systems environments.
SysAuditor Suite uses the SPDX 3.1 standard to capture and store metadata to create an inventory, such as hardware, software, relationships, and licenses on a device. This data can then be analysed for issues such as vulnerabilities and system weaknesses. The visualization tool provides a quick and easy way to review all the components, relationships while supporting enhancements and changes. SysAuditor combines multiple inventories into a collection to help define systems and auditing operations.
SPDX is a graph language with an integrated ontology for universal data capture and sharing multidimensional information.
The following image othlines SPDX 3.1 profiles (Bill of Materials) to establish usable facts such as standards and licensing for compliance, processes, supply chains, and operations for system identification.
SPDX is a graph language with an integrated ontology for universal data capture and sharing multidimensional information. Sysuditor is a universal standard for mapping, naming, identifying, and defining systems. SysAuditor inventories a wide range of elements such as software, hardware, AI, operations, cryptology, functional design, and security.
The SysAuditor helps you answer questions such as:
Is this system (computer and software) the one I ordered? Does it have all the correct components?
What is installed? Do all the components adhere to your policies, and is it operating as expected?
Can you create an amalgamated inventory of all the computers, software, connections and containers within your environment?
Can you document all components with a computer, including hardware and software trees with relationships?
Can you save the information related to hardware, software, connections, AI, licences, so the information can be shared internally or externally?
How do you interlink records and enhance or enrich records with 3rd party data sets?
Can you analyze your data to identify vulnerabilities and threats?