Real-Time Vulnerability Management Operationalizing the VM process from detection to remediation

Similar documents
Real-Time Vulnerability Management Operationalizing the VM process from detection to remediation

Real-Time Vulnerability Management Operationalizing the VM process from detection to remediation

Qualys Cloud Platform

Qualys Cloud Platform

Automating Security Practices for the DevOps Revolution

Regaining Our Lost Visibility

Qualys Cloud Platform

InstallAnywhere: Requirements

First Look Showcase. Expanding our prevention, detection and response solutions. Marco Rottigni Chief Technical Security Officer, Qualys, Inc.

How to manage evolving threats on evolving ICT assets across Enterprise

First Look Showcase. Expanding our prevention, detection and response solutions. Sumedh Thakar Chief Product Officer, Qualys, Inc.

Everything visible. Everything secure.

Community Edition Getting Started Guide. July 25, 2018

Privilege Security & Next-Generation Technology. Morey J. Haber Chief Technology Officer

Technical Review Managing Risk, Complexity, and Cost with SanerNow Endpoint Security and Management Platform

Qualys Cloud Suite 2.30

SYMANTEC DATA CENTER SECURITY

Any platform. Achieve more. Team agility

BigFix 2018 Roadmap. Aram Eblighatian. Product Manager IBM BigFix. 14 May, 2018

Investor presentation

Investor presentation. Philippe Courtot, Chairman and CEO Melissa Fisher, CFO

Investor presentation. Philippe Courtot, Chairman and CEO Melissa Fisher, CFO

Patching and Updating your VM SUSE Manager. Donald Vosburg, Sales Engineer, SUSE

Table of Contents Release Notes 2013/03/25. Introduction in OS Deployment Manager. in Security Manager System Requirements

Consulting Edition Getting Started Guide. October 3, 2018

Chapter 5: Vulnerability Analysis

Frequently Asked Questions

Qualys Cloud Suite 2.28

Christopher Covert. Principal Product Manager Enterprise Solutions Group. Copyright 2016 Symantec Endpoint Protection Cloud

Qualys Indication of Compromise

Automating the Top 20 CIS Critical Security Controls

Client Automation v8.10 Enterprise, Standard, Starter*

Citrix Workspace Cloud

ForeScout Extended Module for Qualys VM

The Evolution of Data Center Security, Risk and Compliance

Meeting PCI DSS 3.2 Compliance with RiskSense Solutions

Javaentwicklung in der Oracle Cloud

ForeScout CounterACT. Security Policy Templates. Configuration Guide. Version

Vulnerability Management

Cyber Hygiene: Uncool but necessary. Automate Endpoint Patching to Mitigate Security Risks

Put an end to cyberthreats

Version 2.38 April 18, 2019

Course 10747D: Administering System Center 2012 Configuration Manager Exam Code:

Kaspersky Security Center 10

MOC 20416B: Implementing Desktop Application Environments

QUALYS SECURITY CONFERENCE Qualys CertView. Managing Digital Certificates. Jimmy Graham Senior Director, Product Management, Qualys, Inc.

Veritas Provisioning Manager

Azure DevOps. Randy Pagels Intelligent Cloud Technical Specialist Great Lakes Region

IBM IBM Tivoli Endpoint Manager V8.1 Implementation.

IBM Security. Endpoint Manager- BigFix. Daniel Joksch Security Sales IBM Corporation

Administering System Center 2012 Configuration Manager

Delivers cost savings, high definition display, and supercharged sharing

DevSecOps Shift Left Security. Prioritizing Incident Response using Security Posture Assessment and Attack Surface Analysis

T68 - FactoryTalk AssetCentre Protecting Your Investment and Reducing Risk

Vulnerability Management

8 Must Have. Features for Risk-Based Vulnerability Management and More

Oracle WebCenter Interaction: Roadmap for BEA AquaLogic User Interaction. Ajay Gandhi Sr. Director of Product Management Enterprise 2.

The following sections provide the ZENworks 2017 Update 2 requirements for hardware and software:

The following sections provide the ZENworks 2017 Update 1 requirements for hardware and software:

RSA IT Security Risk Management

ElasterStack 3.2 User Administration Guide - Advanced Zone

FlexNet Manager Suite 2015 R2 SP5 FlexNet Manager Suite 2015 Release 2 Service Pack 5

Docker and Oracle Everything You Wanted To Know

Qualys Cloud Suite 2.x

Vulnerability Management. If you only budget for one project this year...

The following sections provide the ZENworks 2017 Update 4 requirements for hardware and software:

Think Small to Scale Big

10.4 infinity Release Notes

SCHOOL OF PHYSICAL, CHEMICAL AND APPLIED SCIENCES

Reinvent Your 2013 Security Management Strategy

Portnox CORE. On-Premise. Technology Introduction AT A GLANCE. Solution Overview

Device Discovery for Vulnerability Assessment: Automating the Handoff

Dell Wyse Management Suite. Version 1.1 Migration Guide

NOTHING IS WHAT IT SIEMs: COVER PAGE. Simpler Way to Effective Threat Management TEMPLATE. Dan Pitman Principal Security Architect

PATCH MANAGER AUTOMATED PATCHING OF MICROSOFT SERVERS AND 3RD-PARTY APPS

DevOps Using VSTS and Azure

CounterACT Security Policy Templates

SUSE Linux Enterprise 15. #MultimodalOS

McAfee Endpoint Threat Defense and Response Family

10747D: ADMINISTERING SYSTEM CENTER 2012 CONFIGURATION MANAGER

ForeScout Extended Module for ServiceNow

ForeScout Extended Module for ServiceNow

Ensure that the server where you install the Primary Server software meets the following requirements: Item Requirements Additional Details

Managing Linux Servers Comparing SUSE Manager and ZENworks Configuration Management

Datacenter Security: Protection Beyond OS LifeCycle

Security Challenges: Integrating Apple Computers into Windows Environments

Cisco Tetration Analytics Demo. Ing. Guenter Herold Area Manager Datacenter Cisco Austria GmbH

Microsoft Office User Manual 2007 Pack 2 Process

Tenable.sc-Tenable.io Upgrade Assistant Guide, Version 2.0. Last Revised: January 16, 2019

Getting Started with ArcGIS Runtime SDK for Qt. Thomas Dunn & Nandini Rao

Ipswitch: The New way of Network Monitoring and how to provide managed services to its customers

LIVE NAVIGATOR. Compatibility Guide for Live Navigator Version February 2018

Agenda. Flexcast Management Architecture XenDesktop 7: Install, Manage, Support Migration/upgrade Best Practices Demo Upgrade tips (if time permits)

TRUSTED IT: REDEFINE SOCIAL, MOBILE & CLOUD INFRASTRUCTURE. John McDonald

Faronics Products SYSTEM REQUIREMENTS Last modified: December 2016

Technology Roadmap for Managed IT and Security. Michael Kirby II, Scott Yoshimura 04/12/2017

Web Applications & APIs

AppDefense Getting Started. VMware AppDefense

P a g e 1. Teknologisk Institut. Online kursus k SysAdmin & DevOps Collection

Azure Compute. Azure Virtual Machines

Transcription:

18 QUALYS SECURITY CONFERENCE 2018 Real-Time Vulnerability Management Operationalizing the VM process from detection to remediation Jimmy Graham Director, Product Management, Qualys, Inc.

Agenda Expanding Vulnerability Management Introducing Qualys Patch Management Unified Dashboard 2 QSC Conference, 2018

Vulnerability Management Lifecycle Asset Inventory Vulnerability Management Patch Management Threat Risk and Prioritization 3 QSC Conference, 2018

Expanding Vulnerability Management Containers Private Cloud IoT Devices ICS / SCADA Mobile Devices Workstations Public Cloud On Premise 4 QSC Conference, 2018

Vulnerability Management Platform Evolution

Elastic VM Dashboard Merges AssetView technology into Qualys VM Build widgets with vulnerability counts Search filters for quickly building queries Replace long-running reports with live widgets 6 QSC Conference, 2018

Opening Up the VM Detections Platform Custom Remote Detections Qualys Remote Detection Interface (QRDI) Create your own or share on Qualys Community Supports HTTP(S) and raw TCP Regex grouping and capturing LUA scripting for advanced logic 7 QSC Conference, 2018

Demo VM Elastic VM Dashboard

Qualys Patch Management Overview

Current Patch Management Tools Challenges and Impact Manual correlation of vulnerability to patch leads to delayed mean-time-toremediation Waiting for vulnerability reports to confirm the patch has fixed the vulnerability Remote systems only patched when connected to corporate network Limited or no coverage of third-party apps Multiple patching solutions for each OS type 10 QSC Conference, 2018

Introducing Qualys Integrated Patch Management Automated correlation of vulnerability and patch data Which patch fixes the CVE? Simple dashboarding for tracking patch deployments Patch using the Qualys Cloud Agent, anywhere Patch OS and third-party applications Single solution for Windows, macos, and Linux 11 QSC Conference, 2018

Shift From Reaction Mode to Operational Security Security and IT teams can speak the same language Collaboration key to successful digital transformation Unify discovery, prioritization, and remediation into one platform Always up-to-date on missing patches Rapid remediation of highprofile vulnerabilities in days vs. weeks Regularly scheduled deployments are repeatable and reported on 12 QSC Conference, 2018

Demo PM Patch Management Beta

Platform Support XP SP3+ Vista Windows 7 Windows 8/8.1 Windows 10 Server 2003 SP2+ Server 2008/R2 Server 2012/R2 Server 2016 OS X 10.10 Yosemite OS X 10.11 El Capitan macos 10.12 Sierra macos 10.13 High Sierra macos 10.14 Mojave RHEL 6,7 CentOS 5.4+,6,7 SUSE Linux Enterprise Server/ Desktop 11,12,15 Oracle Ent Linux 6,7(Server) Ubuntu 14.x,15.x,16.x, 18.x * Beta will focus on Windows- other operating systems will follow later * Roadmap items are future-looking; timing and specifications may change 14 QSC Conference, 2018

Roadmap Beta: Q4 2018 Windows patch deployment General Availability: Q1 2019 Beta 1 Windows patching (desktops and servers) Qualys serves patches Third party Windows applications Beta 2 On-prem Caching of patches (QGS) Direct download from vendors for off-prem Additional tokens for dashboarding Upcoming Mac patching Linux patching Repository integration Automation Rules & Approval workflows 18 QSC Conference, 2018

Unified Dashboards Overview

Unified Dashboard Build dashboards with widgets from multiple Qualys Cloud Apps Target servers, containers, instances, web apps, etc. using Asset Tags 17 QSC Conference, 2018

Demo UD Unified Dashboard Preview

Unified Dashboard Rollout Phase 1 Unified Dashboard App Global dashboard filters Phase 2 Unified widget builder Upgrade existing Cloud App Dashboards Support for: Support for: VM PC FIM IOC WAS WAF SAQ AI PM CRI TP CS CV 19 QSC Conference, 2018

18 QUALYS SECURITY CONFERENCE 2018 Thank You Jimmy Graham jgraham@qualys.com