Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Lumension Security achieves Security Content Automation Protocol (SCAP)

July 2008 by Marc Jacob

Lumension Security™, Inc., announced the Security Content Automation Protocol (SCAP) Scanner validation of the company’s market-leading Vulnerability Management Solution. One of the first IT security providers to attain SCAP Validation from the National Institute of Standards and Technology (NIST), Lumension Security has achieved this validation in the stringent Federal Desktop Core Configuration (FDCC) Scanning category for its commitment to enforcing stronger security and hardened Windows endpoint configurations within the U.S. government IT environment.

In March 2007, the U.S. Office of Management and Budget (OMB) mandated that all government organizations adopt FDCC best practice recommendations for Microsoft XP and Vista desktops and laptops. Federal agencies must utilize SCAP-validated tools to verify and then continuously monitor their desktop configurations for FDCC compliance.

In support of the OMB initiative, Lumension’s Vulnerability Management Solution is designed on SCAP standards to securely and cost-effectively manage the entire vulnerability lifecycle. Features include:
Agent-based and agentless risk assessment of software flaws and configuration vulnerabilities
Accurate remediation
Continuous validation
Policy compliance reporting

The solution provides automated compliance reporting based on FDCC security best practices and supports interoperability between security technologies based on NIST’s common security content format requirements. By achieving SCAP FDCC Scanner validation, Lumension guarantees accurate FDCC auditing for Federal agencies and prevents them from having to manually implement the mandated configuration requirements.

Lumension’s Vulnerability Management Solution provides a comprehensive list of NIST’s SCAP policies with hundreds of defined checks, allowing organizations to quickly evaluate their security posture and determine what must be fixed to meet a given standard. In addition, customized templates ensure that assessments are tailored to the various compliance policies that fit an organization’s specific requirements. The solution streamlines this process by facilitating the simple importing and exporting of policies across multiple Vulnerability Management Servers, enabling the same policy documents to be shared by network scanner and agent-based assessment. This eliminates the need to manage and interpret a wide range of different policies and results from non-integrated scanners and agents.


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts