<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tradtional]]></title>
    <link>http://securityratty.com/tag/tradtional</link>
    <description></description>
    <pubDate>Mon, 09 Jun 2008 07:38:11 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Dynamic vulnerability assessment]]></title>
      <link>http://securityratty.com/article/309d2a70126b92b32ee6bbcdc8526758</link>
      <guid>http://securityratty.com/article/309d2a70126b92b32ee6bbcdc8526758</guid>
      <description><![CDATA[A few weekes ago I wrote about the current state of vulnerability assessment being like a parody of an Obama/Hillary commerical. Who answers the phone at 3am? For vulnerability assessment, the results...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>A few weekes ago <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/05/are-current-vul.html">I wrote</a> about the current state of vulnerability assessment being like a parody of an Obama/Hillary commerical.&nbsp; Who answers the phone at 3am?&nbsp; For vulnerability assessment, the results are only as good as who answers the scan.&nbsp; This has been a problem for security managers and vulnerability assessors for some time.&nbsp; Balancing scanning during prime time and impacting network performance versus scanning during down times when the devices you need to scan may not be available.</p>

<p>Today StillSecure <a href="http://stillsecure.com/news_events/prdetails.php?id=446">announced</a> our reponse to ending this problem. We call it Dynamic Vulnerability Assessment (DVA).&nbsp; With DVA you will have vulnerability and compliance data as of at least the last time a device logged on the network.&nbsp; This closes the loophole and gives organizations a much more comprehensive and secure assessment of who is on the network and what they look like.</p>

<p>To accomplish this we are using some of our NAC technology from Safe Access. This allows us to detect devices as they come on the network. We can also use the purpose built Safe Access testing engine to deep compliance checks to supplement the tradtional vulnerability checks.&nbsp; We think this is a big step up in vulnerability assessment and management.&nbsp; Am interested in what others think.</p> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/22fb0815-34f1-4155-b7b6-d163817220fd/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=22fb0815-34f1-4155-b7b6-d163817220fd" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 08:38:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/vulnerability assessment">vulnerability assessment</category>
      <category domain="http://securityratty.com/tag/dynamic vulnerability assessment">dynamic vulnerability assessment</category>
      <category domain="http://securityratty.com/tag/tradtional vulnerability checks">tradtional vulnerability checks</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network performance versus">network performance versus</category>
      <category domain="http://securityratty.com/tag/safe access">safe access</category>
      <category domain="http://securityratty.com/tag/prime time">prime time</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/dynamic-vulnera.html">Dynamic vulnerability assessment</source>
    </item>
    <item>
      <title><![CDATA[Dynamic vulnerability assessment]]></title>
      <link>http://securityratty.com/article/bb77e1c8113060b122c368b2e0250f98</link>
      <guid>http://securityratty.com/article/bb77e1c8113060b122c368b2e0250f98</guid>
      <description><![CDATA[A few weekes ago I wrote about the current state of vulnerability assessment being like a parody of an Obama/Hillary commerical. Who answers the phone at 3am? For vulnerability assessment, the results...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>A few weekes ago <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/05/are-current-vul.html">I wrote</a> about the current state of vulnerability assessment being like a parody of an Obama/Hillary commerical.&nbsp; Who answers the phone at 3am?&nbsp; For vulnerability assessment, the results are only as good as who answers the scan.&nbsp; This has been a problem for security managers and vulnerability assessors for some time.&nbsp; Balancing scanning during prime time and impacting network performance versus scanning during down times when the devices you need to scan may not be available.</p>

<p>Today StillSecure <a href="http://stillsecure.com/news_events/prdetails.php?id=446">announced</a> our reponse to ending this problem. We call it Dynamic Vulnerability Assessment (DVA).&nbsp; With DVA you will have vulnerability and compliance data as of at least the last time a device logged on the network.&nbsp; This closes the loophole and gives organizations a much more comprehensive and secure assessment of who is on the network and what they look like.</p>

<p>To accomplish this we are using some of our NAC technology from Safe Access. This allows us to detect devices as they come on the network. We can also use the purpose built Safe Access testing engine to deep compliance checks to supplement the tradtional vulnerability checks.&nbsp; We think this is a big step up in vulnerability assessment and management.&nbsp; Am interested in what others think.</p>

<fieldset class="zemanta-related"><legend>Related articles</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a title="Open in new window" href="http://www.computerworld.com/action/webcast.do?command=viewWebCastDetail&amp;contentId=9057900&amp;source=rss_topic85">Addressing Compliance Challenges with Automated Vulnerability Management</a> [via Zemanta]</li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/22fb0815-34f1-4155-b7b6-d163817220fd/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=22fb0815-34f1-4155-b7b6-d163817220fd" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=wDvfBs"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=wDvfBs" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Mmh29I"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Mmh29I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DYkFuI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DYkFuI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=0pzoGI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=0pzoGI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ExZ6TI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ExZ6TI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=hA7Roi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=hA7Roi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=5JxCRi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=5JxCRi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/308139432" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 07:38:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/vulnerability assessment">vulnerability assessment</category>
      <category domain="http://securityratty.com/tag/tradtional vulnerability checks">tradtional vulnerability checks</category>
      <category domain="http://securityratty.com/tag/dynamic vulnerability assessment">dynamic vulnerability assessment</category>
      <category domain="http://securityratty.com/tag/vulnerability management">vulnerability management</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network performance versus">network performance versus</category>
      <category domain="http://securityratty.com/tag/safe access">safe access</category>
      <category domain="http://securityratty.com/tag/prime time">prime time</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/308139432/dynamic-vulnera.html">Dynamic vulnerability assessment</source>
    </item>
  </channel>
</rss>
