Top 8 Factors to Analyze to Determine the Real Risk of a Vulnerability: CVSS Score Is Only the Beginning

5/1/2018 12:00:00 PM [(UTC-05:00) Eastern Time (US & Canada)] - Can't make the live event? Register anyway to receive a link to the recording.

Show/Hide All Time Zones

All Time Zones

Dateline Standard Time-(UTC-12:00) International Date Line West 5/1/2018 4:00:00 AM
UTC-11-(UTC-11:00) Coordinated Universal Time-11 5/1/2018 5:00:00 AM
Aleutian Standard Time-(UTC-10:00) Aleutian Islands 5/1/2018 7:00:00 AM
Hawaiian Standard Time-(UTC-10:00) Hawaii 5/1/2018 6:00:00 AM
Marquesas Standard Time-(UTC-09:30) Marquesas Islands 5/1/2018 6:30:00 AM
Alaskan Standard Time-(UTC-09:00) Alaska 5/1/2018 8:00:00 AM
UTC-09-(UTC-09:00) Coordinated Universal Time-09 5/1/2018 7:00:00 AM
Pacific Standard Time (Mexico)-(UTC-08:00) Baja California 5/1/2018 9:00:00 AM
UTC-08-(UTC-08:00) Coordinated Universal Time-08 5/1/2018 8:00:00 AM
Pacific Standard Time-(UTC-08:00) Pacific Time (US & Canada) 5/1/2018 9:00:00 AM
US Mountain Standard Time-(UTC-07:00) Arizona 5/1/2018 9:00:00 AM
Mountain Standard Time (Mexico)-(UTC-07:00) Chihuahua, La Paz, Mazatlan 5/1/2018 10:00:00 AM
Mountain Standard Time-(UTC-07:00) Mountain Time (US & Canada) 5/1/2018 10:00:00 AM
Central America Standard Time-(UTC-06:00) Central America 5/1/2018 10:00:00 AM
Central Standard Time-(UTC-06:00) Central Time (US & Canada) 5/1/2018 11:00:00 AM
Easter Island Standard Time-(UTC-06:00) Easter Island 5/1/2018 11:00:00 AM
Central Standard Time (Mexico)-(UTC-06:00) Guadalajara, Mexico City, Monterrey 5/1/2018 11:00:00 AM
Canada Central Standard Time-(UTC-06:00) Saskatchewan 5/1/2018 10:00:00 AM
SA Pacific Standard Time-(UTC-05:00) Bogota, Lima, Quito, Rio Branco 5/1/2018 11:00:00 AM
Eastern Standard Time (Mexico)-(UTC-05:00) Chetumal 5/1/2018 11:00:00 AM
Eastern Standard Time-(UTC-05:00) Eastern Time (US & Canada) 5/1/2018 12:00:00 PM
Haiti Standard Time-(UTC-05:00) Haiti 5/1/2018 12:00:00 PM
Cuba Standard Time-(UTC-05:00) Havana 5/1/2018 12:00:00 PM
US Eastern Standard Time-(UTC-05:00) Indiana (East) 5/1/2018 12:00:00 PM
Turks And Caicos Standard Time-(UTC-05:00) Turks and Caicos 5/1/2018 12:00:00 PM
Paraguay Standard Time-(UTC-04:00) Asuncion 5/1/2018 12:00:00 PM
Atlantic Standard Time-(UTC-04:00) Atlantic Time (Canada) 5/1/2018 1:00:00 PM
Venezuela Standard Time-(UTC-04:00) Caracas 5/1/2018 12:00:00 PM
Central Brazilian Standard Time-(UTC-04:00) Cuiaba 5/1/2018 12:00:00 PM
SA Western Standard Time-(UTC-04:00) Georgetown, La Paz, Manaus, San Juan 5/1/2018 12:00:00 PM
Pacific SA Standard Time-(UTC-04:00) Santiago 5/1/2018 1:00:00 PM
Newfoundland Standard Time-(UTC-03:30) Newfoundland 5/1/2018 1:30:00 PM
Tocantins Standard Time-(UTC-03:00) Araguaina 5/1/2018 1:00:00 PM
E. South America Standard Time-(UTC-03:00) Brasilia 5/1/2018 1:00:00 PM
SA Eastern Standard Time-(UTC-03:00) Cayenne, Fortaleza 5/1/2018 1:00:00 PM
Argentina Standard Time-(UTC-03:00) City of Buenos Aires 5/1/2018 1:00:00 PM
Greenland Standard Time-(UTC-03:00) Greenland 5/1/2018 2:00:00 PM
Montevideo Standard Time-(UTC-03:00) Montevideo 5/1/2018 1:00:00 PM
Magallanes Standard Time-(UTC-03:00) Punta Arenas 5/1/2018 1:00:00 PM
Saint Pierre Standard Time-(UTC-03:00) Saint Pierre and Miquelon 5/1/2018 2:00:00 PM
Bahia Standard Time-(UTC-03:00) Salvador 5/1/2018 1:00:00 PM
UTC-02-(UTC-02:00) Coordinated Universal Time-02 5/1/2018 2:00:00 PM
Mid-Atlantic Standard Time-(UTC-02:00) Mid-Atlantic - Old 5/1/2018 3:00:00 PM
Azores Standard Time-(UTC-01:00) Azores 5/1/2018 4:00:00 PM
Cape Verde Standard Time-(UTC-01:00) Cabo Verde Is. 5/1/2018 3:00:00 PM
UTC-(UTC) Coordinated Universal Time 5/1/2018 4:00:00 PM
Morocco Standard Time-(UTC+00:00) Casablanca 5/1/2018 5:00:00 PM
GMT Standard Time-(UTC+00:00) Dublin, Edinburgh, Lisbon, London 5/1/2018 5:00:00 PM
Greenwich Standard Time-(UTC+00:00) Monrovia, Reykjavik 5/1/2018 4:00:00 PM
W. Europe Standard Time-(UTC+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna 5/1/2018 6:00:00 PM
Central Europe Standard Time-(UTC+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague 5/1/2018 6:00:00 PM
Romance Standard Time-(UTC+01:00) Brussels, Copenhagen, Madrid, Paris 5/1/2018 6:00:00 PM
Central European Standard Time-(UTC+01:00) Sarajevo, Skopje, Warsaw, Zagreb 5/1/2018 6:00:00 PM
W. Central Africa Standard Time-(UTC+01:00) West Central Africa 5/1/2018 5:00:00 PM
Jordan Standard Time-(UTC+02:00) Amman 5/1/2018 7:00:00 PM
GTB Standard Time-(UTC+02:00) Athens, Bucharest 5/1/2018 7:00:00 PM
Middle East Standard Time-(UTC+02:00) Beirut 5/1/2018 7:00:00 PM
Egypt Standard Time-(UTC+02:00) Cairo 5/1/2018 6:00:00 PM
E. Europe Standard Time-(UTC+02:00) Chisinau 5/1/2018 7:00:00 PM
Syria Standard Time-(UTC+02:00) Damascus 5/1/2018 7:00:00 PM
West Bank Standard Time-(UTC+02:00) Gaza, Hebron 5/1/2018 7:00:00 PM
South Africa Standard Time-(UTC+02:00) Harare, Pretoria 5/1/2018 6:00:00 PM
FLE Standard Time-(UTC+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius 5/1/2018 7:00:00 PM
Israel Standard Time-(UTC+02:00) Jerusalem 5/1/2018 7:00:00 PM
Kaliningrad Standard Time-(UTC+02:00) Kaliningrad 5/1/2018 6:00:00 PM
Sudan Standard Time-(UTC+02:00) Khartoum 5/1/2018 6:00:00 PM
Libya Standard Time-(UTC+02:00) Tripoli 5/1/2018 6:00:00 PM
Namibia Standard Time-(UTC+02:00) Windhoek 5/1/2018 6:00:00 PM
Arabic Standard Time-(UTC+03:00) Baghdad 5/1/2018 7:00:00 PM
Turkey Standard Time-(UTC+03:00) Istanbul 5/1/2018 7:00:00 PM
Arab Standard Time-(UTC+03:00) Kuwait, Riyadh 5/1/2018 7:00:00 PM
Belarus Standard Time-(UTC+03:00) Minsk 5/1/2018 7:00:00 PM
Russian Standard Time-(UTC+03:00) Moscow, St. Petersburg, Volgograd 5/1/2018 7:00:00 PM
E. Africa Standard Time-(UTC+03:00) Nairobi 5/1/2018 7:00:00 PM
Iran Standard Time-(UTC+03:30) Tehran 5/1/2018 8:30:00 PM
Arabian Standard Time-(UTC+04:00) Abu Dhabi, Muscat 5/1/2018 8:00:00 PM
Astrakhan Standard Time-(UTC+04:00) Astrakhan, Ulyanovsk 5/1/2018 8:00:00 PM
Azerbaijan Standard Time-(UTC+04:00) Baku 5/1/2018 8:00:00 PM
Russia Time Zone 3-(UTC+04:00) Izhevsk, Samara 5/1/2018 8:00:00 PM
Mauritius Standard Time-(UTC+04:00) Port Louis 5/1/2018 8:00:00 PM
Saratov Standard Time-(UTC+04:00) Saratov 5/1/2018 8:00:00 PM
Georgian Standard Time-(UTC+04:00) Tbilisi 5/1/2018 8:00:00 PM
Caucasus Standard Time-(UTC+04:00) Yerevan 5/1/2018 8:00:00 PM
Afghanistan Standard Time-(UTC+04:30) Kabul 5/1/2018 8:30:00 PM
West Asia Standard Time-(UTC+05:00) Ashgabat, Tashkent 5/1/2018 9:00:00 PM
Ekaterinburg Standard Time-(UTC+05:00) Ekaterinburg 5/1/2018 9:00:00 PM
Pakistan Standard Time-(UTC+05:00) Islamabad, Karachi 5/1/2018 9:00:00 PM
India Standard Time-(UTC+05:30) Chennai, Kolkata, Mumbai, New Delhi 5/1/2018 9:30:00 PM
Sri Lanka Standard Time-(UTC+05:30) Sri Jayawardenepura 5/1/2018 9:30:00 PM
Nepal Standard Time-(UTC+05:45) Kathmandu 5/1/2018 9:45:00 PM
Central Asia Standard Time-(UTC+06:00) Astana 5/1/2018 10:00:00 PM
Bangladesh Standard Time-(UTC+06:00) Dhaka 5/1/2018 10:00:00 PM
Omsk Standard Time-(UTC+06:00) Omsk 5/1/2018 10:00:00 PM
Myanmar Standard Time-(UTC+06:30) Yangon (Rangoon) 5/1/2018 10:30:00 PM
SE Asia Standard Time-(UTC+07:00) Bangkok, Hanoi, Jakarta 5/1/2018 11:00:00 PM
Altai Standard Time-(UTC+07:00) Barnaul, Gorno-Altaysk 5/1/2018 11:00:00 PM
W. Mongolia Standard Time-(UTC+07:00) Hovd 5/1/2018 11:00:00 PM
North Asia Standard Time-(UTC+07:00) Krasnoyarsk 5/1/2018 11:00:00 PM
N. Central Asia Standard Time-(UTC+07:00) Novosibirsk 5/1/2018 11:00:00 PM
Tomsk Standard Time-(UTC+07:00) Tomsk 5/1/2018 11:00:00 PM
China Standard Time-(UTC+08:00) Beijing, Chongqing, Hong Kong, Urumqi 5/2/2018 12:00:00 AM
North Asia East Standard Time-(UTC+08:00) Irkutsk 5/2/2018 12:00:00 AM
Singapore Standard Time-(UTC+08:00) Kuala Lumpur, Singapore 5/2/2018 12:00:00 AM
W. Australia Standard Time-(UTC+08:00) Perth 5/2/2018 12:00:00 AM
Taipei Standard Time-(UTC+08:00) Taipei 5/2/2018 12:00:00 AM
Ulaanbaatar Standard Time-(UTC+08:00) Ulaanbaatar 5/2/2018 12:00:00 AM
North Korea Standard Time-(UTC+08:30) Pyongyang 5/2/2018 12:30:00 AM
Aus Central W. Standard Time-(UTC+08:45) Eucla 5/2/2018 12:45:00 AM
Transbaikal Standard Time-(UTC+09:00) Chita 5/2/2018 1:00:00 AM
Tokyo Standard Time-(UTC+09:00) Osaka, Sapporo, Tokyo 5/2/2018 1:00:00 AM
Korea Standard Time-(UTC+09:00) Seoul 5/2/2018 1:00:00 AM
Yakutsk Standard Time-(UTC+09:00) Yakutsk 5/2/2018 1:00:00 AM
Cen. Australia Standard Time-(UTC+09:30) Adelaide 5/2/2018 1:30:00 AM
AUS Central Standard Time-(UTC+09:30) Darwin 5/2/2018 1:30:00 AM
E. Australia Standard Time-(UTC+10:00) Brisbane 5/2/2018 2:00:00 AM
AUS Eastern Standard Time-(UTC+10:00) Canberra, Melbourne, Sydney 5/2/2018 2:00:00 AM
West Pacific Standard Time-(UTC+10:00) Guam, Port Moresby 5/2/2018 2:00:00 AM
Tasmania Standard Time-(UTC+10:00) Hobart 5/2/2018 2:00:00 AM
Vladivostok Standard Time-(UTC+10:00) Vladivostok 5/2/2018 2:00:00 AM
Lord Howe Standard Time-(UTC+10:30) Lord Howe Island 5/2/2018 2:30:00 AM
Bougainville Standard Time-(UTC+11:00) Bougainville Island 5/2/2018 3:00:00 AM
Russia Time Zone 10-(UTC+11:00) Chokurdakh 5/2/2018 3:00:00 AM
Magadan Standard Time-(UTC+11:00) Magadan 5/2/2018 3:00:00 AM
Norfolk Standard Time-(UTC+11:00) Norfolk Island 5/2/2018 3:00:00 AM
Sakhalin Standard Time-(UTC+11:00) Sakhalin 5/2/2018 3:00:00 AM
Central Pacific Standard Time-(UTC+11:00) Solomon Is., New Caledonia 5/2/2018 3:00:00 AM
Russia Time Zone 11-(UTC+12:00) Anadyr, Petropavlovsk-Kamchatsky 5/2/2018 4:00:00 AM
New Zealand Standard Time-(UTC+12:00) Auckland, Wellington 5/2/2018 4:00:00 AM
UTC+12-(UTC+12:00) Coordinated Universal Time+12 5/2/2018 4:00:00 AM
Fiji Standard Time-(UTC+12:00) Fiji 5/2/2018 4:00:00 AM
Kamchatka Standard Time-(UTC+12:00) Petropavlovsk-Kamchatsky - Old 5/2/2018 5:00:00 AM
Chatham Islands Standard Time-(UTC+12:45) Chatham Islands 5/2/2018 4:45:00 AM
UTC+13-(UTC+13:00) Coordinated Universal Time+13 5/2/2018 5:00:00 AM
Tonga Standard Time-(UTC+13:00) Nuku'alofa 5/2/2018 5:00:00 AM
Samoa Standard Time-(UTC+13:00) Samoa 5/2/2018 5:00:00 AM
Line Islands Standard Time-(UTC+14:00) Kiritimati Island 5/2/2018 6:00:00 AM

Webinar Registration

So many vulnerabilities – so little time. When you run a vulnerability scanner against your environment you’re guaranteed to get more work than you can accomplish. That’s nothing new in security. There’s always more alerts and anomalies on your SIEM dashboard than you can investigate. There’s always more security technologies than you can implement. 

In each case it’s the same answer – triage. Work on the biggest risks. Prioritize. And measure your efforts vs performance over time so that you can refine your process. Here’s a great example of how NOT to evaluate your work: “We remediated 12,822 vulnerabilities last month.” That’s a big number but what if that was just the “Allow anonymous SID/Name translation is not set to Disabled" on 12k workstations? Whereas your credit card authorization gateway server has an unpatched buffer overflow vulnerability exposed to your entire global network including business partner networks? By the numbers it’s 1 vulnerability compared to 12,000. But in terms of real risk it’s totally reversed.

So, your criterial for prioritizing vulnerabilities is perhaps more important than any other aspect of your vulnerability management process.

In this real training for free event we will focus on how to determine the real risk of each discovered vulnerabilities so that you can:

  • Fix the risks that matter most first
  • Produce a more accurate portrayal of risk posture
  • Provide more accurate reporting to management in terms of
    • Current risk posture
    • Value/performance of remediation efforts
    • Risk reduction/increase overtime

Here are some of the vulnerability risk factors we will delve into:

  • Vulnerability age
    • When discovered?
    • When exploit details published?
    • How long patch available?
    • When first used in attacks?
  • How difficult to exploit?
    • Proof-of-concept code available?
    • Shrink-wrapped tools available?
  • What are the pre-requisites?
  • Actively being used in attacks?
    • Targeted or widespread?

And it’s not all about the vulnerability; it’s equally about the system in question

  • How critical is the asset?
    • Type of information
    • Part of critical infrastructure
    • Critical business process
  • How do the pre-requisites of the vulnerability compare to the system’s configuration, role network exposure, attack surface?
  • Systems that can access critical systems

Finally, time is of the essence. Vulnerabilities change over time. They may begin with a vendor releasing a patch without any exploit details being public and no known attacks. Then it commonly progresses to the security researchers who discovered the vulnerability releasing exploit details once a patch is available. Then pen-testing and hacker tools begin to appear that exploit the vulnerability. Each of these events increases the exploitability of the vulnerability and hence it’s general risk.

Justin Prince and Nathan Palanov from our sponsor, Rapid 7, will finish up this session by showing you how InsightVM takes into account all these factors to help you divide and conquer the vulnerabilities on your network in the most efficient way possible while focusing on the real risk.

Please join us for this real training for free session.

First Name:   
Last Name:   
Work Email:  
Phone:  
Job Title:  
Organization:  
Country:    
State:  
 

Your information will be shared with the sponsor.


 

 

Additional Resources