BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Prioritizing Vulnerability Assessment and Remediation Steps: A New Users Guide to Getting Started – Part 2

Posted February 22, 2011    Morey Haber

The odd part about writing weekly blogs is the amount of discussions that start internally, with clients directly, and sometimes through straight blog comments. After writing “A New Users Guide to Getting Started” article, my team indicated several really good ideas for a Part II follow-up blog. Simply, just getting started with vulnerability management is not enough. Assessing vulnerabilities, remediating them, and doing it again week-after-week, month-after-month, is not enough for good security practices. Taking that data and representing it in meaningful ways to security professionals and management is a fundamental component of assessment in a unified vulnerability management lifecycle.

To begin the second step in the process, I would like to demonstrate the value of historical trending and analytics using key reports to help prioritize effort. This would require a month or more of scan activities and could be used to validate historical efforts and help optimize allocation of resources moving forward.  First, look at the example below of a vulnerability summary report filtered by severity for critical vulnerabilities:

This highlights the vulnerability summary by severity month-over-month, the number of open critical vulnerabilities, their average age open (identified), and most importantly the average time in days that it took to remediate them (the vulnerability has been verified fixed). This same data can be plotted to illustrate that the internal processes for vulnerability management  are (or in this sample case, “are not”) working correctly:

A second example of how a new user needs to address vulnerability management problems is by showing the change in vulnerabilities month-after-month. This is shown below in a vulnerability delta report:

As you can see from this sample, a new program was implemented in July, but remediation efforts did not start until November. The peak number of vulnerabilities found in the organization occurred in December 2010 and only after refining the process and performing more remediation activities in January 2011, did the total number of vulnerabilities actually decrease. This data also highlights the ability to drill into monthly VA data to see which vulnerabilities have been added or removed.

Vulnerability management for the new user is not only about scanning for vulnerabilities and reporting them, it is also about establishing a repeatable and reliable process for assessing and remediation of vulnerabilities month-after-month. The business needs to measure the results from this process and these reports (from Retina Insight) enable more than just unified vulnerability management, they enable the business to prove a return on investment for mitigating the risk and manage compliance. All new users should consider how their new processes are actually working and being measured.

Tags:
, , ,

Leave a Reply

Additional articles

red-thumbprint

Why big data breaches won’t always be so easy

Posted September 19, 2014    Byron Acohido

This blog post is republished with the permission of ThirdCertainty. See the original post here. – By: Byron Acohido, Editor-In-Chief, ThirdCertainty Some day, perhaps fairly soon, it will be much more difficult for data thieves to pull off capers like the headline-grabbing hacks of Home Depot and Target. That’s not a pipe dream. It’s the projected outcome…

Tags:
, , , , ,
pbps-blog2

8 Reasons Your Privileged Password Management Solution Will Fail

Posted September 18, 2014    Chris Burd

Leveraging complex, frequently updated passwords is a basic security best practice for protecting privileged accounts in your organization. But if passwords are such a no-brainer, why do two out of three data breaches tie back to poor password management? The fact is that not all privileged password management strategies are created equal, so it’s critical…

Tags:
, , , , , , ,
pbps-customer-campaign-image

You Change Your Oil Regularly; Why Not Your Passwords?

Posted September 11, 2014    Chris Burd

There are many things in life that get changed regularly:  your car oil, toothbrush and hopefully, your bed sheets.  It’s rare that you give these things much thought – even when you forget to change them. But what if you’re forgetting something that can cost you millions of dollars if left unchanged for long periods…

Tags:
, , ,