Seguridad Mania.com - España y América Latina
Portal sobre tecnologías para la seguridad física
- Destacamos »
- software Anti Blanqueo
PR Newswire
SAN JOSE, Calif., Jan. 19, 2022
SAN JOSE, Calif., Jan. 19, 2022 /PRNewswire/ --
News Summary:
New research has quantified the success of various strategies for vulnerability management and the exploitability of entire organizations, expanding the risk-based playbook for cybersecurity practices.
With an average of 55 new software vulnerabilities published every day in 2021, even the best staffed and resourced IT teams cannot fix all of the vulnerabilities across their infrastructures. Fortunately, there is a better solution.
The research conducted by Kenna Security, now part of Cisco and a market-leader in risk-based vulnerability management, and the Cyentia Institute, shows that properly prioritizing vulnerabilities to fix is more effective than increasing an organizations' capacity to patch them, but having both can achieve a 29 times reduction in an organizations' measured exploitability.
The findings are explained in Kenna's latest report, Prioritization to Prediction, Volume 8: Measuring and Minimizing Exploitability.
"Exploitations in the wild used to be the best indicator for which vulnerabilities security teams should prioritize. Now we can show the likelihood of a particular organization being exploited, which is what we've always wanted to do," said Ed Bellis, co-founder and chief technology officer of Kenna Security, now part of Cisco. "This gives organizations a much better chance at combating potential cyber threats effectively and the research shows that our customers are successfully managing their vulnerability risk every day."
Exploitability was determined using the open Exploit Prediction Scoring System (EPSS); a cross-industry effort including Kenna Security and the Cyentia Institute that is maintained by FIRST.org.
The research confirms a recent Cybersecurity and Infrastructure Security Agency (CISA) directive that suggests it's wiser to move away from prioritizing fixing of vulnerabilities based on CVSS scores and instead focus on high-risk vulnerabilities. Analysis shows that factors like exploit code and even Twitter mentions are better signals than CVSS scores.
"It's clear that a shift to exploitability is going to make a huge difference based on the data and findings in this report. An analysis of CISA's published vulnerabilities suggests that they may also be moving course away from CVSS scores as we were conducting this research," said Wade Baker, partner and co-founder of Cyentia Institute. "We took it a step further to account for remediation velocity when making our calculations, which should better inform security teams."
The research also suggests that:
Additional Resources
About Cisco
Cisco (NASDAQ: CSCO) is the worldwide leader in technology that powers the Internet. Cisco inspires new possibilities by reimagining your applications, securing your data, transforming your infrastructure, and empowering your teams for a global and inclusive future. Discover more on The Network and follow us on Twitter.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Cisco's trademarks can be found at www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
View original content to download multimedia:https://www.prnewswire.com/news-releases/ciscos-kenna-security-research-shows-the-relative-likelihood-of-an-organization-being-exploited-301463427.html
SOURCE Cisco Systems, Inc.
Publicamos interesante Informe de más de 48 págs y varios videos demostrativos sobre los posibles ataques a los robots de montaje de las fábricas. ... Leer más ►
Publicado el 22-Jun-2017 • 10.48hs
Publicado el 20-Jun-2017 • 20.22hs
Dirigido tanto a los principiantes, como a los expertos en seguridad informática y sistemas de control industrial (ICS), este libro ayudará a los lectores a comprender mejor la protección de normas de control interno de las amenazas electrónicas. ... Leer más ►
Publicado el 3-Ene-2012 • 20.16hs
Publicado el 25-Set-2009 • 01.26hs
Publicado el 17-Dic-2008 • 08.32hs