|
|||||||||||
|
Re: Vulnerability scanners
From: Alex Russell <alex(at)netWindows.org>
Date: Thu Mar 27 2003 - 16:51:45 EST -----BEGIN PGP SIGNED MESSAGE-----
On Thursday 27 March 2003 12:58 pm, Jeff Williams @ Aspect wrote:
This sounds like a false economy to me. First: how does the Qualis box remove the need for a sysadmin? It's just one more appliance to manage, and something your existing admin should be able to do anyway. And if you already didn't have an admin, you'd need one now that you're thinking in terms of security. No extra cost here (aside from incremental admin time). Secondly: if you've got a trained monkey doing your report generation, then you're right about the costs. If, however, you have a developer automate most of that, then you can add more nodes to be scanned at much lower incremental cost (change a config file). Additionally, using public signature sets may have downsides, but using Open Source tools is good both for your own internal flexiblity and for the world at large (checks aren't quite right? set that developer to work writing and contributing back better ones!). All in all, your initial costs to do it in house with smart people and Open Source tools might be higher, but your incremental costs do not grow at nearly the same rate. OTOH, if you don't have any admins or developers, then Qualys might look like a very nice option. HTH
iD8DBQE+g3J/oV0dQ6uSmkYRAvN6AJ44Qwzu3sSypJkLDRbl1W1ZjrrnswCZASf0
m88qoVsnBJR2vt7vXZaYyKc=
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:34 EDT |
||||||||||
|
|||||||||||