this post was submitted on 07 Apr 2024
6 points (100.0% liked)
cybersecurity
3030 readers
2 users here now
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Enjoy!
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I've used it at a couple places. It's pretty good. It's best at checking the box on an audit to say you have a vulnerability management program.
If you want real coverage, you should also be actively involved in what's in your company's environment, and how security updates (for external software) and vulnerabilities (for internal) are handled. That is, do you have people looking for vulnerabilities, e.g. with fuzzing?
For Windows environments, you should additionally look at bloodhound and pingcastle.
Thanks,. I'll check into those two