How SCAP Brought Sanity to Vulnerability Management

Orbitz CISO Ed Bellis explains how the proliferation of vulnerability assessment products and services has created chaos, and how SCAP may be the answer.

» View Article

READER FEEDBACK
Preview
ron
Tue, 2009-05-12 20:00

(snip)
What's SCAP, you ask? Until last year I hadn't heard of it either.
(/snip)
yes, I thought it rang a bell but I kept asking through 2/3 of the article! Funny thing, you defined SaaS immediately.

A method of unifying and homoginizing all of the various security related logs and reports will be a god send. I look forward to hearing that you have a tool that we can all use. Good luck.

reply
Becky Boyd
Wed, 2009-05-20 19:03

Ron - Look at SecureFusion from Gideon Technologies at http://www.gideontechnologies.com. SecureFusion combines Vulnerability, Policy, & Configuration Management and Asset Discovery. It is SCAP-validated. SecureFusion automates and orchestrates compliance measurement and reporting. SecureFusion gathers standards-based IT risk metrics into a central service-oriented architecture portal where you can view all IT assets, vulnerabilities, configuration details, and policy compliance metrics.
Becky

reply
Dan Stroud
Thu, 2009-09-10 19:36

With regard to the SecureFusion suite from Gideon, I have researched the product and it is certainly an impressive technology stack that would solve all of my problems with one minor exception, it forces you to use the built-in scanner.

What if I don't want to use the built-in scanner?

What if I have a set of scanners that I am required to use and I need to get all the different results imported into some sort of centralized system?

I need a "scanner-agnostic" vulnerability management system, anyone have any ideas?

reply
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.