Cyberoam Endpoint Data Protection 3.2 review
in Software
Verdict
Cyberoam takes endpoint control to the next level with a remarkable range of security features
Review Date: 31 Mar 2010
Reviewed By: Dave Mitchell
Price when reviewed: £50 (£59 inc VAT)
Features & Design
![]()
Value for Money
![]()
Ease of Use
![]()
![]()
Cyberoam made an impressive entry into the UK security market last year, with its CR15i UTM appliance grabbing a place on the PC Pro A List. It's now turned its attention to endpoint security.
Its Endpoint Data Protection (EDP) software is split into four modules, with the device control option handling workstation ports and devices. Application control determines what software users can run, while asset management provides full inventory and vulnerability assessments.
The data protection module applies encryption to removable storage devices, runs shadow copies of data being transferred to removable devices and controls file transfers for IM and email. The Management Suite covers all modules, but you can choose any as they all run from the same console.
EDP comprises a central server, console and client agents. Take care if you're installing the server on Vista, 7 or Server 2008, as the wizard tries to load MSDE, which isn't supported. You have to install SQL Server Express 2005 manually before loading the server.
A separate utility is used for agent deployment. Although it displays all discovered systems, it can't tell what OS is on each one. The EDP console displays all systems in the left pane, and you can create and populate custom groups using drag and drop. The audit tab offers basic details about each system such as the installed OS, computer name, uptime and logged-in user, as well as graphs of active applications.
To create a policy, you select the system or group and pick either the basic or advanced policy tab. The console can show AD users and allows a restricted set of policies to be assigned to them, but not system policies.
Basic policies control access rights to system operations and settings. These can prevent users loading features such as the Control Panel and Task Manager, and block access to Registry editing and System Restore.
Device policies restrict access to ports. As with DeviceLock, EDP can block unwanted USB storage, optical and network devices but allow the use of human interface devices.
We used the application control module to stop users loading P2P apps such as BitTorrent, and with EDP's advanced policies we could control file transfers over IM. You can also control email attachments, limit access to specific document types and determine printing privileges.
The asset management module provides critical patch lists and endpoint vulnerability assessments, while the event log provides real-time views of IM chats and allows you to look at all received email and attachments.
Cyberoam's EDP offers plenty of controls and is easy to manage. If you want better integration with Active Directory we suggest DeviceLock, but if you want controls for applications, IM and email plus inventory and change management, Cyberoam EDP should be your first port of call.
Author: Dave Mitchell
From around the web
advertisement
- Autonomy's Lynch joins 27,000 on way out of HP
- ICO: no fines for breaking cookie rules
- HP set to slash up to 30,000 jobs
- Government sites to miss cookie deadline
- Microsoft tweaks multi-monitor support in Windows 8
- Apple patches Leopard, despite ending support last year
- Defra opens rural broadband funding applications
- BT's broadband sales surpass calls revenue
- Apple patches multiple security issues
- FBI warns travellers to beware attacks via hotel Wi-Fi
- Laptop bag reviews: nine tested
- Sony VAIO T Series Ultrabook review: first look
- Revealed: the military standards and robots HP uses to test its laptops
- Windows 8: multi-monitors and double standards?
- Why is TalkTalk's year-old porn filter suddenly big news?
- Why are laptop screens so far behind mobiles?
- HP EliteBook Folio review: first look
- The shoebox-sized all-in-one printer
- Forget the Ultrabook: here comes the HP Sleekbook
- HP Spectre XT review: first look
- The death of email
- Backups: ten tips to keep your data safe
- Tablets for work: the best apps, kit and advice
- Why everyone hates the IT department
- Is online shopping security fundamentally broken?
- New cookie laws: why website owners should be worried
- Are work web blockers a waste of time?
- 11 golden rules for virtualisation
- When is it right to go public with security flaws?
- Is your business ready for VoIP?
- Why you have to be left in the dark on OS patches
- Is Microsoft mismanaging Windows on ARM?
- Dealing with spam surrogates
- Why 3G broadband can be better and cheaper than ADSL
- Is Twitter bad for business?
- Publishing your email address isn't a security disaster
- Why you'll need a fax machine to develop iOS apps
- Learning to adapt to the mobile web
- Why you shouldn't use WPS on your Wi-Fi network
- Disabled users suffer when software breaks the rules
advertisement






