Categories: General

Considering Moving To Drupal

I’ve been doing some work for a client recently in the realm of
vulnerability management. It’s an interesting area of information security
because it draws on so many disciplines. The single biggest thing I’ve
learned about this problem is the criticality of asset management.

Quite simply, you can’t hope to “manage” what you don’t know about. What I’d
specifically like to see is a move toward security scanners that leverage
rich data about an organization’s assets. I know of one product doing this
(largely unsucessfully), but I’d like to see it become common in the space.

Here are a few things that asset management offers us:

  • Show me all Vista systems that are vulnerable to MS08-001 that are in my
    building.

  • Find all Solaris boxes in our Indiana offices that have SSH enabled, as
    of yesterday.

  • Make me a report of all systems running Telnet that Bob Smith manages.

And if we factor in other rich, user-added security data into the database,
such as “importance”, “exposure”, or “risk”, we could say:

  • Display all high-risk systems in North America that run Windows Vista or
    XP, but don’t have HIPS installed.

  • List all webservers running Apache 1.3.x in our Wyoming offices that are
    exposed to the Internet but aren’t running SELinux.

Then add to that the ability to run scans off of those queries. An
information loop from the asset-management database to the security scanner,
and then (potentially) back into the asset-database. This is how I think we
should be moving forward — gathering as much information as possible on what
you are protecting, and use that information to improve the quality of your
security testing.

Thoughts?

Gerald Businge

Leave a Comment
Share
Published by
Gerald Businge

Recent Posts

The Changing World of Crypto: How to Stay in the Game Without Losing Faith in Yourself

Want to explore the world of cryptocurrency and see what’s really going on behind the…

1 month ago

Betrayal in the City by Francis Imbuga

1. Introduction to the Text Title: Betrayal in the City Author: Francis Imbuga (Kenya) Genre:…

4 months ago

The Moon also sets by Osi Ogbu

Brief Context Author & Publication: Written by Nigerian author Osita (Osi) Ogbu, the novel was…

4 months ago

Meet Musinguzi John Paul – Your AI Teacher of Christian Religious Education for O-Level in Uganda

Step into a deeper understanding of faith, values, and biblical truth with Musinguzi John Paul,…

5 months ago

Meet Mbabazi Bridget – Your AI Teacher of Entrepreneurship for O-Level in Uganda

Are you ready to unlock your business potential and become a future innovator, job creator,…

5 months ago

Meet Alinda Violet – Your AI Agriculture Teacher for O-Level in Uganda!

Step into the future of farming, food security, and environmental stewardship with Alinda Violet, your…

5 months ago