Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Need a tool to measure IT security

Status
Not open for further replies.

darkhat01

IS-IT--Management
Apr 13, 2006
144
0
0
US
Dear all,

Currently I’m looking for a tool to measure IT security?

The baseline for the tool is Risk Management, Policy Exceptions, Assessments, Security, Associate Education, Anti-virus info/updates, Spy ware info/updates, Vulnerability Management, and Other 3rd party vendor info.

I found one tool that does what I want it to do, but I would like to find a few more to compare, price is not a problem. A example of the tool of what I found is: Archer (
We need a tool to measure how secure are we each month and create reports, the reports may need to be custom.

Please share your experience about this matter.
If there our any link about this issue, I really appreciate if you share to us (You may contact me privately if you would like or on here) .


Best Regards,

Darkhat01
 
Thanks biglebowski,

This product will not work for us. We are not looking for a product that will do the scanning, but a product that will do the reporting (Create Charts/Text) and we can enter the data into. Maybe a kind of database just like the Archer tool, anyone know of any of Archer’s competitors?

We have many tools that do the scanning for us. We then want to take this data and enter it into something that will give it a risk rating (High, Medium, Low).
 
Firstly Retina does to charts, text, etc., would I use it? No because of chameleon and his history on the underground hacking scene. (chameleon = Marc Maiffret CEO or whatever he wants to be called.) Try Sniffer General from Network Associates, along with Belarc's Advisor ( then go over to CISecurity and run those benchmarks as well... ( If you need to do some serious baselining, go to NIST, read their standards and achieve them with the same tools. Also MBSA comes in handy as well.

perl -e 'print $i=pack(c5,(40*2),sqrt(7600),(unpack(c,Q)-3+1+3+3-7),oct(104),10,oct(101));'
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top