A security management apparatus is capable of taking various security
measures while referencing machine information and hence excellent in
flexibility and widely applicable. The apparatus includes a security
diagnostic unit for making a security diagnosis on the basis of security
information obtained from a security information providing apparatus for
providing information concerning security in a network and further on the
basis of machine information obtained from at least one network machine
connected to a network to judge a type of security-related processing to
be executed for the network machine and also judge whether or not the
security-related processing needs to be executed. A security execution
unit executes predetermined security measure processing for the network
machine on the basis of a result of diagnosis made by the security
diagnostic unit.