|
|
|
Project Quant Open Patch Management Metric Model Ready for Download |
Si vous voulez bloquer ce service sur vos fils RSS
Si vous voulez nous contacter ou nous proposer un fil RSS
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Project Quant Open Patch Management Metric Model Ready for Download Par Jeff Jones Security BlogLe [2009-07-28] à 04:23:25
Présentation : model-doc-cover I am extremely excited to announce that Rich Mogull and I believe we are ready to publish two key deliverables for Project Quant today and make them available for download. The first is what I ve referred to in the past as the model, which is the culmination of the first phase of Project Quant. The second is our summary and analysis of the patch management survey results, which I discuss in this other post. Below is an excerpt from the model report executive summary and you can download the full report at http securosis.com research publication project-quant-metrics-model-report . Developing an Open Patch Management Metrics Model This report includes the findings of the Project Quant patch management research project. Project Quant is dedicated to the development of a refined, unbiased patch management metrics model. The goal is to provide organizations with a tool to better understand their patching costs, and to guide improvements through an operational efficiency model capable of capturing accurate and precise performance metrics. It was developed through independent research, community involvement, and an open industry survey. Key Findings There is no public platform-independent, industry-standard patch management process framework. As a result, Project Quant developed a superset framework to encompass most patching activities within any organization, regardless of technology asset under review. It includes ten phases with forty steps. Based on survey responses, organizations are generally mature in managing desktop operating system and server operating system patches, but process maturity quickly falls off for other technologies and platforms. Staff time dedicated to patch management activities represents the majority of patch management costs, and thus the model was designed to focus heavily on granular patching activities. Patching across multiple platforms and business activities is a very complex process, and although the Project Quant model is extremely detailed, most organizations should focus on the key metrics identified through the model. Summary and Next Steps This release includes a detailed patch management process framework and metrics model to enable organizations to quantify and optimize their patch management processes. This is Version 1.0 of the model future work will continue refinement, generate sample use cases, and assess it s functionality in various user environments. The next step is to engage end-user organizations in focused interviews to determine how their processes and maturity align with the model and survey results. The model can then be adapted for use in industry benchmarking.
Les mots clés de la revue de presse pour cet article : patch Les videos sur SecuObs pour les mots clés : patch Les mots clés pour les articles publiés sur SecuObs : patch Les éléments de la revue Twitter pour les mots clé : patch
Les derniers articles du site "Jeff Jones Security Blog" :
- Scott Charney Deconstructing Cyber Threat - Nobody Attacks Thinking About The Apache.org Attacks - sPAM of the Day Auditor Wants to Share 100M of Abandoned MOney - Miami-dade Inmates Hack the Phone System, Charge Calls to Strangers - SDL Awareness and Adoption High Among Security Professionals - Be Safer - Run as Standard User - Computerworld Apple delivers record monster security update - Change Your Tweetdeck Account Password - Profile of A Global Cybercrime Business Innovative Marketing - Woot New Laptop
Menu > Articles de la revue de presse : - l'ensemble [ tous | francophone] - par mots clé [ tous] - par site [ tous] - le tagwall [ voir] - Top bi-hebdo de la revue de presse [ Voir]
Si vous voulez bloquer ce service sur vos fils RSS :
- avec iptables "iptables -A INPUT -s 88.191.75.173 --dport 80 -j DROP"
- avec ipfw et wipfw "ipfw add deny from 88.191.75.173 to any 80"
- Nous contacter par mail
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|