In a move to better respond to digital risk resulting from digital transformation and innovation priorities, RSA has updated the RSA Archer and NetWitness Platforms.
Archer is RSA’s governance, risk, and compliance (GRC) platform and includes cyber incident and breach response capabilities. NetWitness is RSA’s threat detection security incident and event management (SIEM) system. To gain a current picture of organizational risk, integration of real-time information about vulnerabilities and controls is required.
In a recent announcement, RSA indicated that it was “investing in both product areas to deliver a unified approach to advanced security operations and integrated risk management ... to better manage digital risk.”
Assessment of business risk in today’s complex architecture of custom and off-the-shelf applications deployed on premises, in a hybrid environment, or in the cloud is more difficult than ever. Layer on top of that the increasing demand to comply with new and evolving security and privacy compliance requirements, the business finds itself challenged to make decisions based on complete information.
Governance, risk, and compliance tools need to evolve to support management’s needs. Their original roots in the compliance space has evolved over time, however, to continue to thrive in the market, they must better reflect current state risk posture and provide additional value. GRC tools must continue to evolve through smart, data-driven integration and become a knowledgebase as well as audit compliance platform.
Source: Governance, Risk and Compliance at SoftwareReviews, Accessed April 5, 2020
By exploiting a five-year-old configuration error, a hacker was able to access Amazon’s S3 cloud storage buckets on which Twilio’s code was loaded. As a result, customers were able to unknowingly download the modified code for twenty-four hours.
Qualys VMDR and Ivanti have announced a new partnership dedicated to improving the detection and patching of vulnerabilities. Announced July 30, the Qualys and Ivanti Partnership have already gone live as an integrated component of the VMDR solution.
IBM is changing the terms of its ubiquitous Passport Advantage agreement to remove entitled discounts on over 5,000 on-premises software products, resulting in an immediate price increase for IBM Software & Support (S&S) across its vast customer landscape.
RiskSense announced on July 13 its new version of the cloud-delivered RiskSense risk management platform. The main draw of the program is its holistic risk calculation across CVEs and CWEs.
Cyberthreats are omnipresent for any enterprise. Monitoring ingress and egress points while still conducting business is a balance security professionals attempt to strike. Couple this with the continued security issues around remote work during the pandemic, and security teams have their hands full.
Navigating the vendor risk management space, particularly in the current environment that consists of a mix of cloud, managed services, and critical supply chain, is key to ensuring that you don’t inadvertently introduce new risks through this dynamic channel.
On May 26, Kenna Security released its new Prioritization to Prediction Benchmark Survey. This free tool provides organizations with the ability to compare their vulnerability management programs to industry averages Kenna Security has compiled over the years.
From employee management through leadership and communication, increased cyber threats, logistics and operations to post-pandemic planning and risk mitigation, the threat landscape has experienced enormous change. These noticeable shifts force us to consider rethinking and retooling how we address risk.
In an interview with Allison Furneaux, VP Marketing at CyberSaint Inc., developers of CyberStrong Integrated Risk Management platform in June 2020, Allison indicated that its focus has been on cybersecurity from the beginning.