Home > Ask the Security Experts > Platform Security Questions & Answers > For asset management systems, is there a tool more comprehensive than Nmap?
Ask The Security Expert: Questions & Answers
EMAIL THIS

For asset management systems, is there a tool more comprehensive than Nmap?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 15 October 2006
Is there any product available that can serve as an application and middleware asset management system and if so, can this product be integrated into an existing vulnerability management product? I know that there are a lot of products that strictly perform Nmap/Amap functions, but we need something more comprehensive.

>
Asset management is a fundamental IT discipline at the heart of risk management. Due to the variety of diverse devices that can connect to a network, however, vulnerability scanners have a ways to go before being truly integrated within an asset management system. Given that Nmap is considered to be the best network discovery tool available, you are not going to find anything more comprehensive. Nmap has been around for several years, won numerous awards, and is included with many operating systems. It has become the tool of choice for many network administrators who want to map their networks and test them for vulnerabilities. This versatile utility can determine what hosts are available on a network, what services those hosts are offering, and what type of packet filters and firewalls are in use. The open source tool also has the ability to remotely fingerprint a machine's operating system. You can output the results in XML format so that they can be easily imported into a database or converted into HTML for analysis. Since Nmap is free, it is obviously a better deal than any proprietary network-mapping software you might choose.

If you run a purely Windows-based network, you might want to consider Microsoft's Systems Management Server. This product can map the hardware base, including BIOS and chassis enclosure data, existing applications, version information and the current service pack and hotfix levels of devices on the network. Machines and users can also be specifically targeted with software updates and patches.

For whatever product you choose, you will need to create sustainable, systematic processes to achieve strong asset and vulnerability management. Start by regularly scanning your network to fully discover the devices present on it. These may include laptops and handheld devices that may not always be connected. Next, schedule regular vulnerability scanning for specific devices and ranges of IP addresses. It is most important to maintain a record of all these activities from asset discovery to fixes and patching. This information is critical for reporting results to managers and auditors; it demonstrates to outside regulatory agencies that the organization is managing the security risks within the business.

More information:

  • Check out our Nmap Technical Guide, and learn how this free tool can help make your organization more secure.
  • Learn how to define the scope of the information risk management team's responsibilities.


  • BROWSE BY TAG
    Platform Security,   Application and Platform Security,   Enterprise Vulnerability Management,   Vulnerability Risk Assessment,   Open Source Security Tools and Applications,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Platform Security
    Should developers create libraries of common cryptographic algorithms?
    How to secure USB ports on Windows machines
    What is the best database patch management process?
    What is an encryption collision?
    What are new and commonly used public-key cryptography algorithms?
    Should management processes change based on a patch release schedule?
    Does an EULA make it truly illegal to decompile software?
    Should businesses delay Windows Vista adoption and just buy Windows 7?
    Why should we place data files on a separate partition than the OS?
    Should Windows Mobile updates come from Microsoft?

    Vulnerability Risk Assessment
    Screencast: How to launch an OpenVAS scan
    Trusteer CEO criticizes Adobe, touts better patch deployments
    Patch management study shows IT taking significant risks
    Vulnerability mitigation study shows need for faster patching
    Microsoft to issue security report card, new tool at Black Hat
    Newest malware threats
    Are Web application penetration tests still important?
    PCI compliance requirement 6: Systems and applications
    Cybercrime and threat management
    McAfee to acquire Solidcore Systems for whitelisting
    Vulnerability Risk Assessment Research

    Open Source Security Tools and Applications
    Screencast: How to launch an OpenVAS scan
    Could Metasploit popularity erode?
    Metasploit Project acquired by vulnerability management firm Rapid7
    SSH key compromise shuts down Apache website
    Screencast: Smoothwall offers firewall defense in lean times
    Screencast: Samurai offers pen-testing nirvana
    Rootkit Hunter demo: Detect and remove Linux rootkits
    When to use open source security tools over commercial products
    Screencasts: On-screen demonstrations of security tools
    Maltego demo: Identifying a website's trust relationships

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    gray hat  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts