Home > Security Tips > Risk Management Strategies > How to select the best security assessment tool for the job
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

RISK MANAGEMENT STRATEGIES

How to select the best security assessment tool for the job


Kevin Beaver, CISSP
11.22.2004
Rating: -3.80- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


A wide range of testing gizmos are available that can perform security vulnerability assessments, including basic port scanners, network and OS vulnerability assessment tools -- even complex Web application penetration testing programs. If you need to perform a security vulnerability assessment or plan to outsource one, it pays to know which security tools work best for particular tasks and to take the time to choose the right tool.

Basic port scanners that I find very useful are Foundstone's SuperScan and Fyodor's nmap. These scanners can be used for initial reconnaissance probing to map out a network and to gather information on live systems and services that are running on the network. SuperScan 4.0 even offers up some more advanced Windows enumeration features that can prove beneficial for further poking and prodding.

Security vulnerability assessment (VA) tools are available as freeware, open source or commercial products. These tools not only have features to map out the network, but they go deeper to see what's actually running and to identify known and potential vulnerabilities. The security tool spectrum is broad. Solutions range from ASP-based tools such as Qualys' QualysGuard, other commercial GUI-based tools such as Application Security's AppDetective and Elcomsoft's Proactive Windows Security Explorer that are very simple to configure and operate, to tools that require more technical knowledge to use such as the GUI-based Nessus and the command-line based Nikto.

With so many options, it's h



ard to decide what's best for your specific environment. Your goal is to avoid devoting endless, non-productive hours trying to figure out how to use a complex "free" utility that in the end offers limited value or using a simple GUI-based tool that doesn't offer quite the "functionality" that the marketing folks want you to believe. So, here are several steps to help you pick the proper security assessment tool:

A lot of effort goes into testing for security vulnerabilities. If you find the right security tools, you and your team members can work smarter not harder when performing ongoing security tests. It's important to budget time for learning new tools as well as money for initial purchases and ongoing maintenance costs for the commercial tools. By selecting the right tools to maximize your time and money, you can increase your chances of working more effectively to find more security vulnerabilities, gain ongoing support for information security and set up an environment that makes your job a little easier. We could all use some of that.

About the author
Kevin Beaver is the founder and principal consultant of the information security services firm Principle Logic, LLC based in Atlanta, Ga., where he specializes in information security assessments and incident response. He has more than 16 years of experience in IT and is the author of several books on information security including the new title Hacking For Dummies by Wiley Publishing. Kevin can be reached at kbeaver@principlelogic.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Risk Management Strategies,   Application and Platform Security,   Enterprise Vulnerability Management,   Vulnerability Risk Assessment,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Risk Management Strategies
Cloud computing security: Choosing a VPN type to connect to the cloud
Cloud computing security: Routing and DNS security threats
Cloud computing security model overview: Network infrastructure issues
How to align an information security framework to your business model
When to use open source security tools over commercial products
Vulnerability test methods for application security assessments
Security book chapter: Applied Security Visualization
The 100-day plan: Achieving success as a new security manager
Recovering stolen laptops one step at a time
How to get information security buy-in from the executive team

Vulnerability Risk Assessment
Are Web application penetration tests still important?
McAfee to acquire Solidcore Systems for whitelisting
The Pipe Dream of No More Free Bugs
Vulnerability test methods for application security assessments
Free HP SWFScan tool detects Adobe Flash flaws
PCI QSA assurance program penalizes assessors
Information security book excerpts and reviews
New York drafts language demanding secure code
Security experts identify 25 dangerous coding errors
Microsoft Windows XML flaw exploits test desktop antimalware
Vulnerability Risk Assessment Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
gray hat  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts