Providing comprehensive vulnerability assessments Home  Contact
 

 

Vulnerability Management Solutions - Overview

It is not enough to try to prevent security breaches.  You must prepare for them.  To aid you in your preparations, Digital Defense’s Vulnerability Management Solutions provide a comprehensive view of your current network security posture, empowering you to proactively prioritize, perform, and track risk reduction actions.  This service delivers an accurate and thorough evaluation of the weaknesses in your existing computing infrastructure such as potential external hacking targets, insider threats and weaknesses, and risks associated with misconfigured network assets.  You will receive a detailed description of the vulnerabilities identified, complete with information related to the remedial actions required to mitigate or eliminate your risk.
Vulnerability Management, both external and internal, helps clients secure their networks from potential attack from sources outside and inside the organization.  While there is no “silver bullet” that can eliminate every threat, a strong information security program that includes recurring identification and remediation of vulnerabilities is the most effective way to minimize the risk of a network breach or system compromise.

External Vulnerability Management

Digital Defense employs a variety of proprietary scanning techniques to survey each client’s existing security posture.  These scans proactively test for known vulnerabilities and the existence of best practice security configurations.  An External Vulnerability Management (EVM) scan addresses all Internet-facing assets such as routers, firewalls, web servers, and email servers for potential security weaknesses, checking for the "open doors" that could allow a hacker to gain unauthorized access to the network and exploit critical assets.

Internal Vulnerability Management

Properly implemented network security controls are essential to ward off unintentional mistakes from trusted insiders and prevent exposure of sensitive information.  According to data contained within a Computer Crime and Security Survey published by the FBI and the Computer Security Institute (CSI), approximately half of all security breaches come from within the organization.  This information underscores the growing need for sound due diligence in validating your network security posture from an internal perspective.  Internal Vulnerability Management (IVM) scans address all internal assets such as workstations, intranet servers, and printers for Trojans, improper configurations, peer-to-peer (PTP) file sharing programs such as Morpheus, Kazaa, etc., and more.

Vulnerability Management Solutions Testing Levels

Automated Vulnerability Scan (AVS)
This is our most basic and affordable vulnerability management service.  We utilize proprietary technology to conduct a vulnerability scan on your internal and/or external systems.  We then provide you with an easy to read and actionable report that you access via the secure Frontline™ web portal.

Vulnerability Lifecycle Management (VLM)
This is our comprehensive vulnerability management service, which includes all the services in the Automated Vulnerability Scan service plus all the added functionality of our Frontline™ interface.

Vulnerability Lifecycle Management – Pro (VLM – P)
Using our industry leading Frontline technology and our expert security services, DDI will engineer, configure and schedule your vulnerability management processes; including reporting on findings from optional penetration tests, and then “project manage” your remediation efforts, regardless of whether they are handled by your IT staff or a third-party provider.  DDI does not perform the remediation itself under this program, thereby ensuring the objectivity of our assessment services.  Instead, we prioritize the remediation efforts based upon the severity of each threat and the relative risk that you assign to each asset.  You will also continue to enjoy unlimited access within Frontline™ to view Executive Summary and Detailed Technical reports required during regulatory examinations for demonstrating compliance with security requirements.

Additional Vulnerability Management Solution Information

For additional information regarding Vulnerability Management Solution options, benefits and technology, please call 888.273.1412 or contact the appropriate representative listed on our Contact page.


2004 CSI/FBI Computer Crime and Security Survey, Lawrence A. Gordon, Martin P. Loeb, William Lucyshyn and Robert Richardson, Computer Security Institute.