Skip to content

Commit 5831a63

Browse files
authored
Update vulnerability-management.md
1 parent 81e1c07 commit 5831a63

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

docs/baselines/vulnerability-management.md

+2
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,8 @@ The links embedded in the checklist below are to recommended approaches that can
1111
- [ ] Automate asset discovery
1212
- [ ] Validate internet-facing asset ownership and daily discovery with the WA SOC.
1313
- [ ] Implement fortnightly [asset fingerprinting and discovery](https://www.runzero.com/docs/discovering-assets/) across all network connected devices. Use an approach like [fragile device scans](../guidelines/runzero-ot.md) for scanning Operational Technology (OT) or across fragile networks.
14+
- [IVRE (GPL-3.0 license, self-hosted)](https://ivre.rocks) or [runZero](https://www.runzero.com) are high performance asset discovery and fingerprinting platforms that can scan the full IPv4 address space on a weekly basis.
15+
- The [WA Government Vulnerability Scanning Platform](https://www.wa.gov.au/organisation/department-of-the-premier-and-cabinet/vulnerability-scanning-service) has [Discovery Scans](https://www.wa.gov.au/organisation/department-of-the-premier-and-cabinet/vulnerability-scanning-service) available however these need scoping to subnets for performance.
1416
- [ ] Implement daily active [Web](https://www.tenable.com/products/tenable-io/web-application-scanning) & [Basic Network Scans](https://docs.tenable.com/nessus/Content/ScanAndPolicyTemplates.htm#Scanner_Templates) across internet-facing assets
1517
- [ ] Implement Cloud Security Posture Management (CSPM) to inventory and assess all public cloud resources (example controls to assess: [Microsoft cloud security benchmark (v1)](https://learn.microsoft.com/en-us/security/benchmark/azure/overview) ).
1618
- [ ] [Tenable CSPM](https://docs.tenable.com/cloud-security/Content/About/AboutTenablecs.htm) supports AWS, Microsoft Azure, and GCP

0 commit comments

Comments
 (0)