Re: Vulnerability scanners

From: Alex Russell (alex@netWindows.org)
Date: 03/27/03

  • Next message: Nicolas Gregoire: "Re: Vulnerability scanners"
    From: Alex Russell <alex@netWindows.org>
    To: "Jeff Williams @ Aspect" <jeff.williams@aspectsecurity.com>, "Dan Lynch" <dan.lynch@placer.ca.gov>, <pen-test@securityfocus.com>
    Date: Thu, 27 Mar 2003 15:51:45 -0600
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    On Thursday 27 March 2003 12:58 pm, Jeff Williams @ Aspect wrote:
    > Let's assume that you're talking about 256 IPs (based on Qualys'
    > published pricing), and you want to scan weekly. That's at least a day a
    > week of effort for someone (probably more to generate a very nice report
    > and summaries). The cost of a full-time sysadmin (including salary,
    > benefits, office, etc...) probably costs well north of $100K. You'd have
    > to include some equipment costs in there. So I doubt you could do it
    > much cheaper. I think vulnerability scanning is a reasonable thing to
    > outsource for companies that are not in the security or networking field
    > already.

    This sounds like a false economy to me.

    First: how does the Qualis box remove the need for a sysadmin? It's just one
    more appliance to manage, and something your existing admin should be able
    to do anyway. And if you already didn't have an admin, you'd need one now
    that you're thinking in terms of security. No extra cost here (aside from
    incremental admin time).

    Secondly: if you've got a trained monkey doing your report generation, then
    you're right about the costs. If, however, you have a developer automate
    most of that, then you can add more nodes to be scanned at much lower
    incremental cost (change a config file). Additionally, using public
    signature sets may have downsides, but using Open Source tools is good both
    for your own internal flexiblity and for the world at large (checks aren't
    quite right? set that developer to work writing and contributing back
    better ones!).

    All in all, your initial costs to do it in house with smart people and Open
    Source tools might be higher, but your incremental costs do not grow at
    nearly the same rate. OTOH, if you don't have any admins or developers,
    then Qualys might look like a very nice option.

    HTH

    - --
    Alex Russell
    alex@netWindows.org
    alex@SecurePipe.com
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.7 (GNU/Linux)

    iD8DBQE+g3J/oV0dQ6uSmkYRAvN6AJ44Qwzu3sSypJkLDRbl1W1ZjrrnswCZASf0
    m88qoVsnBJR2vt7vXZaYyKc=
    =kMak
    -----END PGP SIGNATURE-----

    top spam and e-mail risk at the gateway.
    SurfControl E-mail Filter puts the brakes on spam & viruses
    and gives you the reports to prove it. See exactly how much
    junk never even makes it in the door. Free 30-day trial:
    http://www.surfcontrol.com/go/zsfptl1


  • Next message: Nicolas Gregoire: "Re: Vulnerability scanners"

    Relevant Pages

    • Re: Vulnerability scanners
      ... firewall using SSL to hit Qualys's web/scanner server. ... It breaks it down into reports for techies and reports for non-techies ... >> to include some equipment costs in there. ... And if you already didn't have an admin, ...
      (Pen-Test)
    • Re: expression i need to write rate -admin costs*driver percentage
      ... still leaves out the admin costs. ... >>currency, driver percentage is number, intger,and currency. ...
      (microsoft.public.access.queries)
    • Re: expression i need to write rate -admin costs*driver percentage
      ... Rate is a dollar amount and the admin ... costs is a percentage of that dollar amount. ... I need the driver percentage based on the rate minus ...
      (microsoft.public.access.queries)
    • Re: Domain users members of local administrator
      ... You should only need to install once as admin; non-admin should be able to ... reconfigure without needing admin privileges. ... frustration) costs of having non-Admin users greatly outweigh the costs of ...
      (microsoft.public.security)
    • Re: Questions about hiring .NET developer
      ... the screw-up go WAY UP beyond his/her immediate costs if their crappy ... then you will eventually need to hire a competent developer ... starting out the competent developer somewhere BELOW ground zero. ... Lost productivity costs (if the crappy project made it into production) ...
      (microsoft.public.dotnet.languages.csharp)