I recommend Nessus and SARA. My reasons are that both are free and have good reputations, and at the time of that last study, a combination of the two tools covered all of the common vulnerabilities that they were looking for. The reason I recommend the free tools, at least to start, is that you may as well clean up all the problems that the free tools find before you bother to invest any money in the commercial products. ISS is a very fine product, but it can be quite expensive. SARA is nice in that the reports that it produces link to the CVE database and generally tell you how to fix the problems that are found. I've often thought that if the Nessus engine had the SARA reporting mechanism, you'd have the best of both worlds. Now, my job has not included scanning systems for about 18 months, so perhaps Nessus has improved its reporting capability in that time. To me, that was always the main drawback to Nessus.
For more info on this topic, visit these SearchSecurity.com resources:
This was first published in May 2004