ISACARuSec – Telegram
ISACARuSec
2.27K subscribers
1.76K photos
13 videos
303 files
5.63K links
Канал направления ИБ Московского отделения ISACA

Направление канала новости ISACA, новости в области управления ИБ в России и мире, обмен лучшими практиками.

https://engage.isaca.org/moscow/home

Связь с администрацией
@popepiusXIII
Download Telegram
Vulnerability Management vendors and Vulnerability Remediation problems

It’s not a secret, that #VulnerabilityManagement vendors don’t pay much attention to the actual process of fixing vulnerabilities, that they detect in the infrastructure (Vulnerability Remediation).

In fact, most of VM vendors see their job in finding a potential problem and providing a link to the Software Vendor’s website page with the #remediation denoscription. How exactly the #remediation will be done is not their business.

Remediation is a painful topic and it’s difficult to sell it as a ready-made solution. And even when Vulnerability Vendors try to sell it this way, it turns out pretty ugly and does not really work. Mainly because the Remediation feature is sold to the Security Team, and the IT Team will have to use it.

#Windows #remediation #patch #Linux #VulnerabilityManagement

Read more: https://avleonov.com/2019/04/29/vulnerability-management-vendors-and-vulnerability-remediation-problems/
Теперь для устранения критических уязвимостей в интернет системах американским фоив дают 15 дней, а не 30, как раньше.

DHS Shortens Deadline For Gov Agencies to Fix Critical Flaws | Threatpost
https://threatpost.com/dhs-deadline-gov-agencies-fix-critical/144269/
Американская счетная палата считает, что 6 человек мало для обспечения кибербезопасности американских трубопроводов.

Only six TSA staffers are overseeing US oil & gas pipeline security | ZDNet
https://www.zdnet.com/article/only-six-tsa-staffers-are-overseeing-us-oil-gas-pipeline-security/
Гартнер в 2019 планирует обновить исследования по vulnerability management.

https://blogs.gartner.com/blog/category/all/?c=vulnerability-management
Обновилась база техник атакующих MITRE ATT&CK. Кратко на фото, зеленные - новые техники, жёлтым - изменённые

https://attack.mitre.org/resources/updates/updates-april-2019/index.html