当前位置:首页 > 报告详情

IT 漏洞管理的综合方法 (David Frier).pdf

上传人: a****d 编号:402810 2025-01-10 23页 3.05MB

1、PATCH YOUR SH!(Or,as it appears on the program:A Comprehensive Approach to IT Vulnerability ManagementA Comprehensive Approach to IT Vulnerability ManagementIn case you were wondering if you came to the wrong room)David C.Frier,RIMSDavid C.Frier,RIMS-CRMP,CISM,etc.CRMP,CISM,etc.Rochester Security Su

2、mmit 2024Rochester Security Summit 2024overviewThis is an Introduction to Vulnerability ManagementSpiced with some tips from my sliver of experience with VMVM is a continuous,proactive processabout this guyDavid C Frier,RIMS-CRMP,CISM,CISSP,CRISC,CCSKvCISO and Senior Cybersecurity Program Manager at

3、 Sedara.but Ibut I speak only for myself,speak only for myself,not fornot for SedaraSedara!0 x2d years into IT,0 x13 years into InfosecAvid player of poker.Orioles and Cubs fan.enthusiastic-if-slow rider of a Trek.None of the“usual”social media aside from LinkeDin,but I can be sighted in the Fediver

4、se(#checkin)about.me or wheretofind.megeekosaurussteps in vulnerability managementAsset InventoryNetwork ScopingInternal and External ScanningClassifying ResultsPrioritizing VulnerabilitiesRemediation AssignmentMeasuring&Reportingasset inventory(1/2)Identify all hardware and softwareDocument asset t

5、ypes and locationsAsset discovery toolsCMDBNmap,etc.Discovery scansasset inventory(2/2)Criticality ranking(business impact)Regular updates for accuracyEnsuring full scope for scanningnetwork scoping(1/2)Define internal/external network boundariesIdentify critical systems for scanningInclude servers,

6、endpoints,network devicesSegment your network however it makes sense for your orgStaff/team scope,or locations,or functionsnetwork scoping(2/2)Avoid unnecessary scans(non-critical assets)About end-user computersConsider network segments,subnets,firewallsMake sure your scanner can access everythingKe

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要介绍了漏洞管理的全过程,强调了这是一个持续的、主动的过程。关键步骤包括:资产清单、网络范围定义、内外部扫描、结果分类、漏洞优先级排序、修复任务分配、测量和报告。资产清单要识别所有硬件和软件,网络范围定义要明确内部和外部网络的边界,内外部扫描要针对关键系统和网络设备进行。分类结果要根据风险水平、利用可能性、影响和资产重要性等因素进行。漏洞优先级排序要考虑威胁景观、活跃利用等因素。修复任务分配要根据任务紧急性和机会进行。测量和报告要跟踪漏洞修复情况和风险分数的减少。最后,文章强调了持续改进的重要性。
"VM流程中如何进行资产清单管理?" "如何利用扫描工具评估网络边界?" "如何根据风险分数自动化优先处理漏洞?"
客服
商务合作
小程序
服务号
折叠