[ news_security_news ] CIOview Announces Availability Of SecurityNOW!
SecurityProNews Staff Writer
2004-09-14
Insider Reports RSS Feed
CIOview announced availability of SecurityNOW! SX, a free software package that lets organizations complete a comprehensive IT security self-assessment in 30 minutes or less.
SecurityNOW! is designed for the security novice and expert alike to:
-- Rapidly identify key security vulnerabilities and assign a financial cost to each
-- Forecast how their security environment will change over time
-- Evaluate various loss control policies and their effectiveness at reducing risk
-- Calculate the Return On Security Investment (ROSI) for 100s of possible strategies
Part and parcel of SecurityNOW! is a risk quantification using the commonly accepted framework, Risk Assessment Value (RAV). RAV allows organizations to compare their security between departments and over time. In fact, RAV is increasingly the most common security measure demanded by regulatory bodies. According to Pete Herzog, Managing Director of the Institute for Security and Open Methodologies (ISECOM), "This is the first time that a software product has embodied an international security assessment methodology along with a rapid method to determine the financial implications of IT security. Organizations now can have their cake and eat it too -- a practical, easy-to-use metrics software package based on a recognized methodology that's also free."
Endorsed by ISECOM
CIOview's SecurityNOW! has been given ISECOM's Seal of Approval for bringing financial transparency to the world of IT security. SecurityNOW! takes ISECOM's internationally-accepted security methodology and transforms it into a world-class, easy-to-use software package. The software embodies the six capabilities described by ISECOM as the key to making security transparent:
-- Accelerated - 30 minutes or less to complete
-- Accessible - 5 MB of industry benchmark data
-- Objective - a consistent, open methodology
-- Customized - quantifies risk based on a user's responses
-- Forward-looking - forecasts risk over time
-- Graphical - charts compare security to financial costs, tying the two together
Two Versions: Professional reduces time to deliver audit results by 90%
SecurityNOW! is available in two versions: SX and Professional. SecurityNOW! SX is a complete security analysis software system based on the OSSTMM, and is available at no charge at the CIOview web site as well as Security Partner sites.
Security professionals and auditors will benefit from SecurityNOW! Professional. It provides added automation features that reduce the time to deliver audit results from 30 days to 3 days. Built upon the foundation of the SX version, SecurityNOW! Professional adds the following capabilities:
-- Validated data can be imported from a number of network port and vulnerability detection scans;
-- Verified data from OSSTMM or similar security audits can be directly entered;
-- A financial and business case for security spending as well as a certified audit report can be published with one mouse click;
-- All business case reports can be electronically shared with collaborators and coworkers using the free SecurityNOW! SX version.
Endorsed by Worldwide Security Partners
SecurityNOW! is endorsed by a variety of worldwide Security Partners, who have made the software available via their web sites, including:
-- ISECOM : an open-source collaborative community dedicated to providing practical security awareness, research, certification and business integrity.
-- Above Security: specializes in mitigating computer risk and offers complete 24/7 managed monitoring and strategic information security services.
-- CISSP Open Study Guides: is a web portal dedicated to helping security professional reach their CISSP or SSCP certification.
-- Fullerton Infosec is a full service security-consulting firm specializing in OSSTMM security testing as well as various forms of security education.
-- GCP Global is dedicated to protecting an organization's information assets against attacks committed by competitors, hackers, industrial spies, etc.
About the Author:
SecurityProNews is a daily online and email publication focusing on internet security issues.
More news_security_news Articles
Insider Reports RSS Feed
|
|