These are tool that are implemented by the information security program to perform automated assessment of organizational standards related to:
- Vulnerability and patch compliance: Validating information system patch levels and vulnerability across the enterprise to include:
- Server and workstation operating systems (Windows, Linux, and so on)
- Network devices (Routers, Switches, and so on)
- Server software applications (Database, email, DNS, and so on)
- Desktop applications (Microsoft Word, Adobe Acrobat, and so on)
- Network and configuration management: Ensuring compliance with organizational change management policies as well as information security baselines:
- Manages the thousands of configuration ...