<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: foundstone]]></title>
    <link>http://securityratty.com/tag/foundstone</link>
    <description></description>
    <pubDate>Sun, 13 Apr 2008 17:58:13 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[What's new in vulnerability management?]]></title>
      <link>http://securityratty.com/article/c6608547b09e0cfbcec61b74ceefeff7</link>
      <guid>http://securityratty.com/article/c6608547b09e0cfbcec61b74ceefeff7</guid>
      <description><![CDATA[For too long the vulnerability management vendors have been quiet. In fact the whole sector has taken on the &quot;mature&quot; label which seems to indicate there is no new innovation happening. Recently...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>For too long the vulnerability management vendors have been quiet. In fact the whole sector has taken on the &quot;mature&quot; label which seems to indicate there is no new innovation happening.&nbsp; Recently though we have seen some new announcements in this area.&nbsp; Also, Gartner should have a new marketscope due out soon.&nbsp; Here is a recap of some recent developments:</p>

<p>1. <strong>Qualys</strong> - I had a chance to speak with Philippe and his son at RSA. After riding high on the PCI wave and pioneering the SaaS in security movement, Qualys is now clearly moving into the compliance arena. This <a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20080407" target="_blank">release</a> details what Qualys is doing but clearly they see compliance and risk management as a new driver for the business.</p>

<p>2. <strong>McAfee</strong>- Say goodbye to Foundstone. Years after buying the company McAfee is finally getting rid of the Foundstone name for the vulnerability product and renaming it Vulnerability Manager 6.5 (I think I like the Foundstone name better), as part of the <a href="http://www.eweek.com/c/a/Security/McAfee-Governance-Risk-and-Compliance-Business-Unit/" target="_blank">new business unit</a> they have started around GRC. Foundstone founder George Kurtz is heading that unit up. They indicate they will supplement the old Foundstone scanner with abilities to scan applications, web sites and data and databases.</p>

<p>3,. <strong>nCircle</strong> - I spoke with Andrew Storms and Elizabeth Ireland at RSA. nCircle has been touting their compliance and risk management capabilities for a while now.&nbsp; They also are showing off web application scanning as well. Though they don't get the press that Qualys does, they appear to be holding their own.&nbsp; The question in my mind is how do they break out to the next level (see my post on <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/shimmys-theory.html" target="_blank">shimmy's theory of relativity</a>).5. </p>

<p>4. eEye - After many of us including me raised doubts about their viability, eEye has announced the addition of web application scanning to their Retina product. I understand this is an OEM of another companies product and does not represent a lot of investment on eEye's point.&nbsp; I think at the end of the day they are trying to be an endpoint company but can't afford to jettison the scanner business.&nbsp; Their long term viability according to my relativity theory is still in doubt if you ask me.</p>

<p>5. <strong>ISS/IBM</strong> - I hear nothing on this one, do you?&nbsp; You have to question what is the game plan from Big Blue on this.&nbsp; Do they buy an update or put the money into actually taking this dinosaur out of the Jurassic?&nbsp; I guess we will have to see.</p>

<p>So I am sure some of you ask, OK Shimmy enough about the competition what is StillSecure doing with its VAM product?&nbsp; Well the purpose of this blog post was to set the stage for that. I will post an update on some of the cool stuff we have planned with VAM shortly. </p></div>
]]></content:encoded>
      <pubDate>Sun, 13 Apr 2008 18:58:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/unit">unit</category>
      <category domain="http://securityratty.com/tag/business unit">business unit</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/risk management capabilities">risk management capabilities</category>
      <category domain="http://securityratty.com/tag/foundstone">foundstone</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/foundstone scanner">foundstone scanner</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/whats-new-in-vu.html">What's new in vulnerability management?</source>
    </item>
    <item>
      <title><![CDATA[What's new in vulnerability management?]]></title>
      <link>http://securityratty.com/article/8a2f19eefde655e44f34cc0710699d5d</link>
      <guid>http://securityratty.com/article/8a2f19eefde655e44f34cc0710699d5d</guid>
      <description><![CDATA[For too long the vulnerability management vendors have been quiet. In fact the whole sector has taken on the &quot;mature&quot; label which seems to indicate there is no new innovation happening. Recently...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>For too long the vulnerability management vendors have been quiet. In fact the whole sector has taken on the &quot;mature&quot; label which seems to indicate there is no new innovation happening.&nbsp; Recently though we have seen some new announcements in this area.&nbsp; Also, Gartner should have a new marketscope due out soon.&nbsp; Here is a recap of some recent developments:</p>

<p>1. <strong>Qualys</strong> - I had a chance to speak with Philippe and his son at RSA. After riding high on the PCI wave and pioneering the SaaS in security movement, Qualys is now clearly moving into the compliance arena. This <a href="http://www.qualys.com/company/newsroom/newsreleases/usa/?view=20080407" target="_blank">release</a> details what Qualys is doing but clearly they see compliance and risk management as a new driver for the business.</p>

<p>2. <strong>McAfee</strong>- Say goodbye to Foundstone. Years after buying the company McAfee is finally getting rid of the Foundstone name for the vulnerability product and renaming it Vulnerability Manager 6.5 (I think I like the Foundstone name better), as part of the <a href="http://www.eweek.com/c/a/Security/McAfee-Governance-Risk-and-Compliance-Business-Unit/" target="_blank">new business unit</a> they have started around GRC. Foundstone founder George Kurtz is heading that unit up. They indicate they will supplement the old Foundstone scanner with abilities to scan applications, web sites and data and databases.</p>

<p>3,. <strong>nCircle</strong> - I spoke with Andrew Storms and Elizabeth Ireland at RSA. nCircle has been touting their compliance and risk management capabilities for a while now.&nbsp; They also are showing off web application scanning as well. Though they don't get the press that Qualys does, they appear to be holding their own.&nbsp; The question in my mind is how do they break out to the next level (see my post on <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/04/shimmys-theory.html" target="_blank">shimmy's theory of relativity</a>).5. </p>

<p>4. eEye - After many of us including me raised doubts about their viability, eEye has announced the addition of web application scanning to their Retina product. I understand this is an OEM of another companies product and does not represent a lot of investment on eEye's point.&nbsp; I think at the end of the day they are trying to be an endpoint company but can't afford to jettison the scanner business.&nbsp; Their long term viability according to my relativity theory is still in doubt if you ask me.</p>

<p>5. <strong>ISS/IBM</strong> - I hear nothing on this one, do you?&nbsp; You have to question what is the game plan from Big Blue on this.&nbsp; Do they buy an update or put the money into actually taking this dinosaur out of the Jurassic?&nbsp; I guess we will have to see.</p>

<p>So I am sure some of you ask, OK Shimmy enough about the competition what is StillSecure doing with its VAM product?&nbsp; Well the purpose of this blog post was to set the stage for that. I will post an update on some of the cool stuff we have planned with VAM shortly. </p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=TII961"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=TII961" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BXE9w2G"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BXE9w2G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=buMzw2G"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=buMzw2G" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=EoPB2tG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=EoPB2tG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=JennaCG"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=JennaCG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=MfVIVZg"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=MfVIVZg" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Vy2M06g"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Vy2M06g" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/269748929" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 13 Apr 2008 17:58:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/unit">unit</category>
      <category domain="http://securityratty.com/tag/business unit">business unit</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/risk management capabilities">risk management capabilities</category>
      <category domain="http://securityratty.com/tag/foundstone">foundstone</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/foundstone scanner">foundstone scanner</category>
      <category domain="http://securityratty.com/tag/blog post">blog post</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/269748929/whats-new-in-vu.html">What's new in vulnerability management?</source>
    </item>
  </channel>
</rss>
