Find White Papers
Home
About Us
List Your Papers
    
> Qualys > Vulnerability Management Buyer's Checklist - Key Questions to Ask Before You Select a VM Solution

Vulnerability Management Buyer's Checklist - Key Questions to Ask Before You Select a VM Solution

White Paper Published By: Qualys

Choosing a solution for Vulnerability Management (VM) is a critical step toward protecting your organization’s network and data. Without proven, automated technology for precise detection and remediation, no network can withstand the daily onslaught of new vulnerabilities that threaten security.



Tags : 
qualys, vm solution, vulnerability management, saas, database security, network patching, vulnerability patching, networking

Qualys
Published:  Jan 07, 2009
Type:  White Paper
Length:  14 pages

VM BUYER'S CHECKLIST

Vulnerability Management Buyer's Checklist
Key Questions to Ask Before You Select a VM Solution
Vulnerability Management (VM) means systematically finding and eliminating network vulnerabilities. Choosing a solution for VM is a critical step toward protecting your organization's network and data. Without proven, automated technology for precise detection and remediation, no network can withstand the daily onslaught of new vulnerabilities that threaten security. To help finalize your decision on which solution to buy, Qualys provides this 12-point short list of considerations that will help you determine what will work best for your organization.

12 Key Decision Points Architecture
Architecture ............ ....1 How is the VM solution delivered?
Security ................... ....2 Is there software or hardware that you need to install and maintain, or is software Scalability / delivered as a service (SaaS) and simply requires logging in to your account via a web Ease of Use ........... ....3 browser to start scanning? A system that requires you to manage installation, updates, hardware, database security, etc. ends up costing more than just the purchase price of Accuracy / the software, and may require additional manpower for ongoing operations. Performance.......... ....4 Discovery / Mapping....5 Does the solution offer a graphical user interface?
Scanning ................. ....6 Some offerings - particularly older, low-end or "no-cost" solutions - only have command Reporting................. ....7 line interfaces that can be tough to operate and have limited customization features (or access controls). Understand how the solution is delivered and test it before you buy it. Remediation............ ....9 Policy Compliance.. ....10 Do I have to run an agent on all my networked devices?
Management............ ....11 Software-based VM products may require you to install and update agents on every system to be scanned. Look for architecture that does not require an agent, or any other Cost .... .................... ....12 software to operate other than a standard, SSL-enabled web browser for accessing the Solution Vendor...... ....14 interface.
Does the product require me to run a database?
Software-based VM products may require you to install and operate a database to house info for vulnerability management. The SaaS architecture does not carry that requirement.
Why should I consider using SaaS for VM?
For an application like VM, a SaaS solution makes more sense than software for most companies. It is easier to deploy and manage, is more flexible in supporting evolving business needs, has lower and more predictable costs, is scalable, does not lock you into a long-term license, is easier to use, and is more reliable.
Copyright © 2009, Qualys, Inc. All Rights Reserved. VM Buyer's Checklist - 2
Security
What is the security model used to protect the solution?
It's crucial that the VM solution itself be secure, especially since it houses critical data about the network's assets and potential vulnerabilities. With software-based solutions, you are responsible - and it can be a complex task to secure such systems and information. With a hosted, SaaS solution, the security is handled by the SaaS provider. Make sure the SaaS solution provides end-to-end security for sensitive vulnerability data and uses multiple standard proactive controls to protect all layers of the application.
How is the solution physically protected?
Make sure you understand this from your vendor. Again, traditional software-based solutions require you to do all of this work. By contrast, SaaS-based solutions handle this for you. For example, the QualysGuard service is run in Secure Operations Centers that successfully pass annual SAS70 Type II certifications. QualysGuard machines and racks are locked in a private vault requiring badge and biometric authentication for access. Physical access is restricted to designated Qualys employees, who undergo third-party reference and background checks, and sign a confidentiality agreement. It is secured behind a host-based firewall and a policy-driven file system and integrity checking system, plus an IDS architecture. Staff continuously monitor all systems and administer proper remediation and count... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search