RE: QualysGuard

From: DeGennaro, Gregory (Gregory_DeGennaro_at_csaa.com)
Date: 08/30/04

  • Next message: Alexandre Verriere: "Re: listing directory structure within webserver root"
    Date: Mon, 30 Aug 2004 08:24:40 -0700
    To: "Eric Danso" <edanso@myblackberry.com>, "Haseeb Chaudhary" <haseeb.chaudhary@viacom-outdoor.co.uk>, <pen-test@securityfocus.com>
    
    

    This is completely true.

    Again, you have to accept the risk that the data at Qualys can either be
    compromised or viewed by Qualys. Yes, I am sure that the data is quite
    safe. However just like data vaults which in a sense Qualys is a data
    vault, they do have a copy of your encryption keys and therefore there
    is a chance that they can view your data or your data could be
    compromised by an elite cracker or through an inside job by either a
    disgruntle employee or in error.

    Someone brought up the fact that your local machine can be cracked too.
    This is very true, however you are in complete control of your data and
    if you do encryption correctly with proper passwords, offline key
    escrow, back-ups, and fire proof safes, your data will most likely be
    more secure than at Qualys.

    However if you feel that Qualys is safe, you do not need a risk
    acceptance, and you have the budget, then Qualys is a very reliable,
    portable, and useful tool.

    Qualys does offer demonstration packages, perhaps you should contact a
    Qualys account manager to see for yourself and determine if this is the
    right product for you.

    As for my careful team, we will stick to devices and services that are
    completely under our control.

    This my opinion and I am sure that other professionals will share their
    opinion's as well.

    Regards,
     
    Greg DeGennaro Jr., CISSP, CCNP
    Systems Engineer

    -----Original Message-----
    From: Eric Danso [mailto:edanso@myblackberry.com]
    Sent: Wednesday, August 25, 2004 5:05 PM
    To: Haseeb Chaudhary; 'Eric Danso'; pen-test@securityfocus.com
    Subject: RE: QualysGuard

    Thanks for the info

    the one thing that i wanted to verify is I heard through
    other users that Qualys is a distrbuted solution where the
    reports are all stored at a database at Qualys. This
    allows you to get reports anywhere but I'm not sure what
    value you get from that. I can set up a webserver and
    allow certain users to view the reports.

    Is this true.??

    ------------------------------------------------------------------------------
    Ethical Hacking at the InfoSec Institute. All of our class sizes are
    guaranteed to be 12 students or less to facilitate one-on-one interaction
    with one of our expert instructors. Check out our Advanced Hacking course,
    learn to write exploits and attack security infrastructure. Attend a course
    taught by an expert instructor with years of in-the-field pen testing
    experience in our state of the art hacking lab. Master the skills of an
    Ethical Hacker to better assess the security of your organization.

    http://www.infosecinstitute.com/courses/ethical_hacking_training.html
    -------------------------------------------------------------------------------


  • Next message: Alexandre Verriere: "Re: listing directory structure within webserver root"

    Relevant Pages

    • RE: Vulnerability scanners
      ... CyberCop, Nessus, Foundscan, and now Qualys. ... for single system reports. ...
      (Pen-Test)
    • RE: Vulnerability scanners
      ... Qualys was that all you had to do is plug the appliance into your network ... It breaks it down into reports for techies and reports for ... >> to include some equipment costs in there. ...
      (Pen-Test)
    • RE: Vulnerability scanners
      ... Don't forget that Qualys is not a managed service. ... You still need to setup the scans, customize the reports, setup scheduling, and make sense of the resulting reports. ... the incremental cost of their service must be far less than that. ... SurfControl E-mail Filter puts the brakes on spam & viruses ...
      (Pen-Test)