February 3, 2008

Vulnerability Management Lifecycle (Part 2 of 2)

by Shon Harris, CISSP, MCSE

Step 10 - Standardize Procedures

Develop standardized procedures and checklists to follow when a new vulnerability is identified. This formalized approach reduces wasted time and operational costs. These procedures should outline the necessary steps that should be taken when a vulneraiblity is identified and the roles responsible for completing these steps. The following flow chart addresses many of the steps that should take place.

vulnerability management standardize procedures

 The actual steps you develop for your environment may be slightly different than the previous flow chart, but your procedures should cover the common components of vulnerability management action steps: vulnerability identification, threat analysis, and remediation procedures.

Vulnerability Idenfitication

Threat Analysis

Remediation

 

Some of Today’s Top Vulnerability Management Products

Foundstone Enterprise (recently purchased by McAfee)

http://www.foundstone.com

Symantec NetRecon

http://enterprisesecurity.symantec.com/products/products.cfm?ProductID=46&EID=0

QualysGuard

http://www.qualys.com/solutions/overview/

eEye Digital Security Products

http://www.eeye.com/html/products/index.html

Step 11 - Improve Preventive Controls

 In your vulnerability management procedures, improvement of current countermeasures is an important step. In most situations, when a compromise takes place it is an indication that the current preventive safeguards are lacking or have been penetrated. When an intrusion is endured, not only should the incident response team contain the damage and restore the production environment, the security staff should treat this as an opportunity to reinforce necessary security barriers. Too many times companies just "plug the hole" without investigating the layers of controls that had to be penetrated for this threat to be successful.

Step 12 - Continual Monitoring

Vulnerability management is a process, not a product or a project. This means that you need to continue to monitor for al of the possible threats your company can be faced with. Many companies spend most of their attention and money on monitoring incoming ports (ingress filtering), but it is important to also review these possible threats and more:

These vulnerabilities and remediation steps can be found at http://www.sans.org/top20.

vulnerability management technologies 

Let’s Regroup

Even if your environment is complex and the sophistication of the threats increase over time, you can still get a handle on identifying and controlling the vulnerabilities and threats in your organization. It is all about laying out achievable steps and keeping up the day-in-day-out discipline that is required to ensure that your company’s acceptable risk level is not compromised.

Let’s make sure we understand the goals we are trying to accomplish and the necessary processes to achieve these goals.

Vulnerability Management Goals

Vulnerability Management Process

Do not fall into the common misconception that vulnerability management can be solved with just a product. Although many of the products on the market today can greatly reduce the manual steps of this piece of your security program, it is still very important that you and your team understand how to use the product as a tool in your vulnerability management process - not as the solution. Proper education on the issues and integration of vulnerability management as a business process is more important than any tool. With these two pieces in place, you and your team can choose the right tool for the right purpose.

In addition, do not think that security issues can be solved by throwing money and staff at the problem. You have to develop a strategic and ongoing process that is integrated into everyday activities. A large corporation of over 200,000 employees created an 80-person staff dedicated just to vulnerability management. They could not keep up and be successful because of lack of organization, vision, strategy, and process integration - not from a lack of money.

vulnerability management goals

 

Filed under by

Spread the word

del.icio.us Digg Furl Reddit Help

Permalink • Print