<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>dmiessler.com | grep understanding - Latest Comments in Vulnerability Management Without Asset Management, Isn&amp;#8217;t</title><link>http://danielrm26.disqus.com/</link><description>dmiessler.com/about/</description><atom:link href="https://danielrm26.disqus.com/vulnerability_management_without_asset_management_isn8217t/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Fri, 08 Jun 2007 19:58:23 -0000</lastBuildDate><item><title>Re: Vulnerability Management Without Asset Management, Isn&amp;#8217;t</title><link>http://dmiessler.com/blog/vulnerability-management-without-asset-management-isnt#comment-4354141</link><description>&lt;p&gt;Johnathan:&lt;br&gt;arcsight has a few products which product contains the asset discovery tool?&lt;/p&gt;&lt;p&gt;thank you,&lt;br&gt;raymond&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">raymond</dc:creator><pubDate>Fri, 08 Jun 2007 19:58:23 -0000</pubDate></item><item><title>Re: Vulnerability Management Without Asset Management, Isn&amp;#8217;t</title><link>http://dmiessler.com/blog/vulnerability-management-without-asset-management-isnt#comment-4354144</link><description>&lt;p&gt;Heh, yeah...I'm a big fan of that tool. My buddy loves it.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Miessler</dc:creator><pubDate>Mon, 14 May 2007 23:55:29 -0000</pubDate></item><item><title>Re: Vulnerability Management Without Asset Management, Isn&amp;#8217;t</title><link>http://dmiessler.com/blog/vulnerability-management-without-asset-management-isnt#comment-4354145</link><description>&lt;p&gt;There is a product that does just what you want Daniel, it's called ArcSight. It's got a pretty cool Asset Discovery tool and can run all the reports and queries you were using as examples (ie. All Solaris machines with SSH running as of x/x/x)&lt;/p&gt;&lt;p&gt;Check it out if you want/can: &lt;a href="http://www.arcsight.com" rel="nofollow noopener" target="_blank" title="http://www.arcsight.com"&gt;http://www.arcsight.com&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Disclaimer: Not cheap at all and sometimes feels "heavy" or bloated as it's all Java based. YMMV.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jonathan S.</dc:creator><pubDate>Mon, 14 May 2007 16:56:11 -0000</pubDate></item><item><title>Re: Vulnerability Management Without Asset Management, Isn&amp;#8217;t</title><link>http://dmiessler.com/blog/vulnerability-management-without-asset-management-isnt#comment-4354146</link><description>&lt;p&gt;Steven, I agree with that, but I think I'd rather deal with that than having one of these unknown systems spewing spam and/or bot traffic and embarrassing the company.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Daniel Miessler</dc:creator><pubDate>Wed, 09 May 2007 12:14:07 -0000</pubDate></item><item><title>Re: Vulnerability Management Without Asset Management, Isn&amp;#8217;t</title><link>http://dmiessler.com/blog/vulnerability-management-without-asset-management-isnt#comment-4354143</link><description>&lt;p&gt;You talk about security risk in these systems, but it bears underscoring that there is some compelling disaster looming around unknown assets using unlicensed software.&lt;/p&gt;&lt;p&gt;We're true up on our photoshop licenses.....&lt;/p&gt;&lt;p&gt;( until you discover that your Windows shop actually has a hidden department of Macs running CS 3 that one guy got from a Spammy Re-seller? )&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Steven G. Harms</dc:creator><pubDate>Wed, 09 May 2007 12:09:34 -0000</pubDate></item><item><title>Re: Vulnerability Management Without Asset Management, Isn&amp;#8217;t</title><link>http://dmiessler.com/blog/vulnerability-management-without-asset-management-isnt#comment-4354142</link><description>&lt;p&gt;I've actually been involved in both ends - IT Asset Management engagements (mostly using CA products) and vulnerability management/assessments, and I definitely agree that this would be useful!&lt;/p&gt;&lt;p&gt;I have seen Qualys used at a lot of clients, and I'm pretty sure it has an asset discovery feature - but I dont think this works well as an enterprise wide Asset Management tool.&lt;/p&gt;&lt;p&gt;And on the other side, something like CA's asset management products can tell you what systems are where, but I don't think it has the capabilities to launch a qualys or other scan, or alert you to vulnerabilities, etc.. Although if it could tie in to another CA product like their security products, they'd probably be on to something.&lt;/p&gt;&lt;p&gt;disclaimer: I know I focused on one vendor there, but it's just what I'm familiar with from a deployment perspective and I'm FAR from a CA fan-boy/spammer/whatever so please point me in the direction of other similar products (I know they're out there).&lt;/p&gt;&lt;p&gt;The biggest thing about ITAM is, like security, the supporting processes around it are what make or break it. If the organization doesn't follow the framework/policies you work with them to develop, then the software is just going to sit on a shelf and collect dust and not be useful for reporting on your assets and thus, your vulnerabilities. But I'm sure I'm only preaching to the choir here!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">craig</dc:creator><pubDate>Wed, 09 May 2007 10:41:48 -0000</pubDate></item></channel></rss>