<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Vulnerability Management Without Asset Management, Isn&#8217;t</title>
	<atom:link href="http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt/feed" rel="self" type="application/rss+xml" />
	<link>http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt</link>
	<description>grep understanding</description>
	<lastBuildDate>Thu, 18 Mar 2010 04:37:26 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: raymond</title>
		<link>http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt/comment-page-1#comment-60418</link>
		<dc:creator>raymond</dc:creator>
		<pubDate>Fri, 08 Jun 2007 23:58:23 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1322#comment-60418</guid>
		<description>&lt;p&gt;Johnathan:
arcsight has a few products which product contains the asset discovery tool?&lt;/p&gt;

&lt;p&gt;thank you,
raymond&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Johnathan:
arcsight has a few products which product contains the asset discovery tool?</p>

<p>thank you,
raymond</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt/comment-page-1#comment-55620</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Tue, 15 May 2007 03:55:29 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1322#comment-55620</guid>
		<description>&lt;p&gt;Heh, yeah...I&#039;m a big fan of that tool. My buddy loves it.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Heh, yeah&#8230;I&#8217;m a big fan of that tool. My buddy loves it.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jonathan S.</title>
		<link>http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt/comment-page-1#comment-55539</link>
		<dc:creator>Jonathan S.</dc:creator>
		<pubDate>Mon, 14 May 2007 20:56:11 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1322#comment-55539</guid>
		<description>&lt;p&gt;There is a product that does just what you want Daniel, it&#039;s called ArcSight. It&#039;s got a pretty cool Asset Discovery tool and can run all the reports and queries you were using as examples (ie. All Solaris machines with SSH running as of x/x/x)&lt;/p&gt;

&lt;p&gt;Check it out if you want/can: http://www.arcsight.com.&lt;/p&gt;

&lt;p&gt;Disclaimer: Not cheap at all and sometimes feels &quot;heavy&quot; or bloated as it&#039;s all Java based. YMMV.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>There is a product that does just what you want Daniel, it&#8217;s called ArcSight. It&#8217;s got a pretty cool Asset Discovery tool and can run all the reports and queries you were using as examples (ie. All Solaris machines with SSH running as of x/x/x)</p>

<p>Check it out if you want/can: <a href="http://www.arcsight.com" rel="nofollow">http://www.arcsight.com</a>.</p>

<p>Disclaimer: Not cheap at all and sometimes feels &#8220;heavy&#8221; or bloated as it&#8217;s all Java based. YMMV.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Miessler</title>
		<link>http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt/comment-page-1#comment-54035</link>
		<dc:creator>Daniel Miessler</dc:creator>
		<pubDate>Wed, 09 May 2007 16:14:07 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1322#comment-54035</guid>
		<description>&lt;p&gt;Steven, I agree with that, but I think I&#039;d rather deal with that than having one of these unknown systems spewing spam and/or bot traffic and embarrassing the company.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Steven, I agree with that, but I think I&#8217;d rather deal with that than having one of these unknown systems spewing spam and/or bot traffic and embarrassing the company.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Steven G. Harms</title>
		<link>http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt/comment-page-1#comment-54034</link>
		<dc:creator>Steven G. Harms</dc:creator>
		<pubDate>Wed, 09 May 2007 16:09:34 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1322#comment-54034</guid>
		<description>&lt;p&gt;You talk about security risk in these systems, but it bears underscoring that there is some compelling disaster looming around unknown assets using unlicensed software.&lt;/p&gt;

&lt;p&gt;We&#039;re true up on our photoshop licenses.....&lt;/p&gt;

&lt;p&gt;( until you discover that your Windows shop actually has a hidden department of Macs running CS 3 that one guy got from a Spammy Re-seller? )&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You talk about security risk in these systems, but it bears underscoring that there is some compelling disaster looming around unknown assets using unlicensed software.</p>

<p>We&#8217;re true up on our photoshop licenses&#8230;..</p>

<p>( until you discover that your Windows shop actually has a hidden department of Macs running CS 3 that one guy got from a Spammy Re-seller? )</p>]]></content:encoded>
	</item>
	<item>
		<title>By: craig</title>
		<link>http://danielmiessler.com/blog/vulnerability-management-without-asset-management-isnt/comment-page-1#comment-54006</link>
		<dc:creator>craig</dc:creator>
		<pubDate>Wed, 09 May 2007 14:41:48 +0000</pubDate>
		<guid isPermaLink="false">http://dmiessler.com/archives/1322#comment-54006</guid>
		<description>&lt;p&gt;I&#039;ve actually been involved in both ends - IT Asset Management engagements (mostly using CA products) and vulnerability management/assessments, and I definitely agree that this would be useful!&lt;/p&gt;

&lt;p&gt;I have seen Qualys used at a lot of clients, and I&#039;m pretty sure it has an asset discovery feature - but I dont think this works well as an enterprise wide Asset Management tool.&lt;/p&gt;

&lt;p&gt;And on the other side, something like CA&#039;s asset management products can tell you what systems are where, but I don&#039;t think it has the capabilities to launch a qualys or other scan, or alert you to vulnerabilities, etc.. Although if it could tie in to another CA product like their security products, they&#039;d probably be on to something.&lt;/p&gt;

&lt;p&gt;disclaimer: I know I focused on one vendor there, but it&#039;s just what I&#039;m familiar with from a deployment perspective and I&#039;m FAR from a CA fan-boy/spammer/whatever so please point me in the direction of other similar products (I know they&#039;re out there).&lt;/p&gt;

&lt;p&gt;The biggest thing about ITAM is, like security, the supporting processes around it are what make or break it. If the organization doesn&#039;t follow the framework/policies you work with them to develop, then the software is just going to sit on a shelf and collect dust and not be useful for reporting on your assets and thus, your vulnerabilities. But I&#039;m sure I&#039;m only preaching to the choir here!&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I&#8217;ve actually been involved in both ends &#8211; IT Asset Management engagements (mostly using CA products) and vulnerability management/assessments, and I definitely agree that this would be useful!</p>

<p>I have seen Qualys used at a lot of clients, and I&#8217;m pretty sure it has an asset discovery feature &#8211; but I dont think this works well as an enterprise wide Asset Management tool.</p>

<p>And on the other side, something like CA&#8217;s asset management products can tell you what systems are where, but I don&#8217;t think it has the capabilities to launch a qualys or other scan, or alert you to vulnerabilities, etc.. Although if it could tie in to another CA product like their security products, they&#8217;d probably be on to something.</p>

<p>disclaimer: I know I focused on one vendor there, but it&#8217;s just what I&#8217;m familiar with from a deployment perspective and I&#8217;m FAR from a CA fan-boy/spammer/whatever so please point me in the direction of other similar products (I know they&#8217;re out there).</p>

<p>The biggest thing about ITAM is, like security, the supporting processes around it are what make or break it. If the organization doesn&#8217;t follow the framework/policies you work with them to develop, then the software is just going to sit on a shelf and collect dust and not be useful for reporting on your assets and thus, your vulnerabilities. But I&#8217;m sure I&#8217;m only preaching to the choir here!</p>]]></content:encoded>
	</item>
</channel>
</rss>
