« Better late than never, come on in the waters fine | Main | Are we at risk for not allowing white hats into web web apps? »

April 12, 2007

Questions to Amrit on effective vulnerability management

Amrit has part 1 of an article he is writing on effective vulnerability management up.  As some of you many know, Amrit spent a few years as an analyst in the VM field and certainly knows a thing or two about it.  In many ways reading Amrit's article reminded me of my own VA is dead thesis.  I say AMEN to what you have written about traditional scan and fix being a losing approach Amrit.

I think though Amrit is proposing a Big Fix like (no surprise there) approach as the evolutionary successor to traditional vulnerability management scanning.  So Amrit, while I agree with the dead end that vulnerability assessment scanning seems to be, let me ask you two questions regarding your position on this:

1. Does configuration management boil down to remediation being the only answer? If so what is remediation?  Is it only applying patches or shutting down a port or service?  Could applying limitations on access be part of the equation?  Access control based upon configuration baseline is I think an important part of managing the system.

2. Can configuration management be  done outside of an on board agent.  Looking at some of the traditional VM scanners like nCircle and Tenable, they are claiming configuration management capabilities.  Can their "point in time" scanning compare to always on configuration management agent based solutions? If not, what about unmanaged devices coming on the network without an agent?  Do you fall back to scanning them with a scanner? Is the position really that if all company owned assets are fully compliant, we don't worry about what a guest computer can introduce?  It is for this reason that I think you can never have a pure agent based configuration management system, but need both agent and agentless based.

OK, Amrit there you go.  Looking forward to your answer.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d834f6049c53ef

Listed below are links to weblogs that reference Questions to Amrit on effective vulnerability management:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005