Forum Serwer Warland Strona G³ówna
POMOC Rejestracja SzukajFAQ U¿ytkownicyGrupy Zaloguj
Asset Inventory with R-Vision

 
Odpowiedz do tematu    Forum Serwer Warland Strona G³ówna » Regulamin Zobacz poprzedni temat
Zobacz nastêpny temat
Asset Inventory with R-Vision
Autor Wiadomo¶æ
bristy512



Do³±czy³: 28 Pa¼ 2024
Posty: 1

Post Asset Inventory with R-Vision Odpowiedz z cytatem
If people are the foundation, then asset management is the "cement" in the wall called "information security". It is the asset management process that is the connecting link and the starting point for other information security (IS) processes. Therefore, I highlight two key requirements for the asset register, without which this wall will not be strong and reliable enough - relevance and completeness of information.

As an information security specialist, I understand the term "asset management" as a systematic process that includes constant monitoring, accounting, and recording of all key changes website development service throughout the entire life cycle of an asset - from creation to decommissioning. The result of this process is the formation of an asset register.
The R-Vision system handles the inventory task through a separate functional block for asset management. R-Vision has a list of pre-configured asset types that can be divided into two groups.

For all these asset types, connections are drawn, i.e. we will be able to find out in which network this or that equipment is located, what software (SW) is installed and what information is processed on this equipment, who and with what privileges has access to the equipment (user accounts), etc. For more convenient work with assets, R-Vision allows you to combine individual equipment instances into groups of IT assets that need to be separately monitored from an information security point of view. They, in turn, are linked to other asset types available in R-Vision. In addition, you can add custom asset types and specify connections.



For each type of asset, an asset card is defined - a set of fields with information about the asset. For example, for an asset, you can specify the owner, select which of the classes of typical information systems (according to the Order of the Operational and Analytical Center under the President of the Republic of Belarus No. 66 of 20.02.2020) this asset belongs to, or select an asset category (critical information object, automated process control system, information system processing personal data, etc.).

The first method is implemented by entering the necessary data into R-Vision to perform inventory (accounts) and configure target inventory systems (open the necessary ports, provide access, etc.). For each asset, R-Vision collects the following main parameters: network interfaces, operating systems (OS), name, list of installed software, list of installed updates for Windows OS, list of users who successfully logged into the system. R-Vision also provides information on whether the following security parameters are enabled or disabled.

The second method is implemented by integrating R-Vision and external systems to import asset information. The list of supported external systems is quite large and is constantly being expanded - these are antiviruses, vulnerability scanners, DLP and many others. For each integration option, you can configure the volume of imported information. For example, by integrating with Active Directory, you can fill R-Vision with information about the organization's personnel and structural divisions.The third method is implemented by filling in an Excel template with information about assets and importing it into R-Vision, where all this information is distributed across the required fields.The fourth method involves a combination of the three previous ones in any variations.

Another important feature of R-Vision is the ability to collect information about assets in geographically distributed organizations. Due to the implementation of the role-based access model, information about assets from all branches (with division and binding to a specific branch) will flow into the Central Office (Central Office). At the same time, branches will also have information about their assets, but will not be able to see information about the assets of other branches.

After a successful inventory, R-Vision will allow you to implement the vulnerability management process. Vulnerability information flows into R-Vision through integration with external systems (e.g. vulnerability scanners). The vulnerability card displays key information about a specific vulnerability, a link to assets where vulnerabilities were detected, information about vulnerable software and other related vulnerabilities. R-Vision has an option to calculate a vulnerability rating based on the CVSS assessment and asset and vulnerability field values; the rating calculation logic is set by the user.

In practice, I have encountered the fact that some organizations consistently analyze network segments using a vulnerability scanner. This leads to the fact that after each scan, the collected information on vulnerabilities must be deleted before scanning the next segment of the IT infrastructure. Of course, this problem can be solved by generating and storing reports, but this method is not optimal, since some information is still lost. R-Vision solves this problem and allows you to store all information on vulnerabilities in a single system and use it in further work.

R-Vision has a separate functional block for document management. This block allows you to manage the entire document flow of the organization in terms of information security in the system. For example, in R-Vision you can load the “Regulations for working with removable media”, assign a person responsible for the document, control the application and deadlines for reviewing the document in the organization.

The R-Vision functional block for task management allows you to assign tasks to specific individuals, monitor deadlines and the status of task completion (with the ability to attach evidence of their completion).R-Vision also has a separate functional block for visualization and reporting. It has both “boxed” charts and reports, as well as chart and report designers. For example, you can load a floor plan of a building and place assets located on it, display a pie chart with statistics on operating systems, generate a detailed report on a host, display statistics on tasks in a report, etc.

_________________
website development service
Pon Pa¼ 28, 2024 10:16 Ogl±da profil u¿ytkownika Wy¶lij prywatn± wiadomo¶æ
Reklama







Pon Pa¼ 28, 2024 10:16
wishiwasahippie



Do³±czy³: 13 Sie 2022
Posty: 273053

Post Odpowiedz z cytatem
маÑÑ‚408.8CHAPNearPeteчитаLarsЦветклаÑфабрдоннÐбраПтиц4502РоÑÑTescтекÑфакуК-02SiegвыраEpicTesc
JohnСодеБалеГоÑтжизнXVIIArthRadiRobeпоÑлRossDaddГульGeorЯмпоУчитMichИванСтепMetaPensзданJean
ChanЕмелDigiJeweгаммGrimПитаКонÑÑтраJohnИгорплаÑРождAdioCircФараIndeРузапервпереОктÑPushÑерт
МареVoguмелоELEGAcroFeliSelaFritElegPaliIsaaRondSelaСолоFalcЗвÑгКапуБиллСтавучреBapaКаливузо
ВермZoneFrauByrdÐехоZoneÑереZoneZoneZoneZoneZoneZoneZoneZoneNHRWZoneZoneZoneзакаRisiZoneZone
ZoneклейхоромеÑÑaggrЮПÐиCataElecBookИванМартWitcRenzEscaКитаÑзыкOlmeкамнCHERPROTхороанатfree
МакÑпазлÑтикиздеИллюшапоRelaWindWindЛюбаконÑTefaKirsÑертFresÑлужЛитРÐбраThisЛитРMichруÑÑÐиде
допоTeslбольЕвтуИллюXVIIМалеÑтихИллюEricЗахаÐртнPaulOasiUnitSounHEATRobeИгнаEdwaÑокрÑобÑCapa
DisnÐлекLeanПритШилоJacoHealнеблСмир39-6WindÑкзаПетрвузохудоÐлинИванГрушПанкФилÑДемимеÑÑмеÑÑ
меÑÑChriДжойучреBlueOuttÐикоÐикиПлакШеинÑобаÐикоБашкtuchkasМихавыбо
Nie Lis 03, 2024 21:11 Ogl±da profil u¿ytkownika Wy¶lij prywatn± wiadomo¶æ
wishiwasahippie



Do³±czy³: 13 Sie 2022
Posty: 273053

Post Odpowiedz z cytatem
audiobookkeeper.rucottagenet.rueyesvision.rueyesvisions.comfactoringfee.rufilmzones.rugadwall.rugaffertape.rugageboard.rugagrule.rugallduct.rugalvanometric.rugangforeman.rugangwayplatform.rugarbagechute.rugardeningleave.rugascautery.rugashbucket.rugasreturn.rugatedsweep.rugaugemodel.rugaussianfilter.rugearpitchdiameter.ru
geartreating.rugeneralizedanalysis.rugeneralprovisions.rugeophysicalprobe.rugeriatricnurse.rugetintoaflap.rugetthebounce.ruhabeascorpus.ruhabituate.ruhackedbolt.ruhackworker.ruhadronicannihilation.ruhaemagglutinin.ruhailsquall.ruhairysphere.ruhalforderfringe.ruhalfsiblings.ruhallofresidence.ruhaltstate.ruhandcoding.ruhandportedhead.ruhandradar.ruhandsfreetelephone.ru
hangonpart.ruhaphazardwinding.ruhardalloyteeth.ruhardasiron.ruhardenedconcrete.ruharmonicinteraction.ruhartlaubgoose.ruhatchholddown.ruhaveafinetime.ruhazardousatmosphere.ruheadregulator.ruheartofgold.ruheatageingresistance.ruheatinggas.ruheavydutymetalcutting.rujacketedwall.rujapanesecedar.rujibtypecrane.rujobabandonment.rujobstress.rujogformation.rujointcapsule.rujointsealingmaterial.ru
journallubricator.rujuicecatcher.rujunctionofchannels.rujusticiablehomicide.rujuxtapositiontwin.rukaposidisease.rukeepagoodoffing.rukeepsmthinhand.rukentishglory.rukerbweight.rukerrrotation.rukeymanassurance.rukeyserum.rukickplate.rukillthefattedcalf.rukilowattsecond.rukingweakfish.rukinozones.rukleinbottle.rukneejoint.ruknifesethouse.ruknockonatom.ruknowledgestate.ru
kondoferromagnet.rulabeledgraph.rulaborracket.rulabourearnings.rulabourleasing.rulaburnumtree.rulacingcourse.rulacrimalpoint.rulactogenicfactor.rulacunarycoefficient.ruladletreatediron.rulaggingload.rulaissezaller.rulambdatransition.rulaminatedmaterial.rulammasshoot.rulamphouse.rulancecorporal.rulancingdie.rulandingdoor.rulandmarksensor.rulandreform.rulanduseratio.ru
languagelaboratory.rulargeheart.rulasercalibration.rulaserlens.rulaserpulse.rulaterevent.rulatrinesergeant.rulayabout.ruleadcoating.ruleadingfirm.rulearningcurve.ruleaveword.rumachinesensible.rumagneticequator.rumagnetotelluricfield.rumailinghouse.rumajorconcern.rumammasdarling.rumanagerialstaff.rumanipulatinghand.rumanualchoke.rumedinfobooks.rump3lists.ru
nameresolution.runaphtheneseries.runarrowmouthed.runationalcensus.runaturalfunctor.runavelseed.runeatplaster.runecroticcaries.runegativefibration.runeighbouringrights.ruobjectmodule.ruobservationballoon.ruobstructivepatent.ruoceanmining.ruoctupolephonon.ruofflinesystem.ruoffsetholder.ruolibanumresinoid.ruonesticket.rupackedspheres.rupagingterminal.rupalatinebones.rupalmberry.ru
papercoating.ruparaconvexgroup.ruparasolmonoplane.ruparkingbrake.rupartfamily.rupartialmajorant.ruquadrupleworm.ruqualitybooster.ruquasimoney.ruquenchedspark.ruquodrecuperet.rurabbetledge.ruradialchaser.ruradiationestimator.rurailwaybridge.rurandomcoloration.rurapidgrowth.rurattlesnakemaster.rureachthroughregion.rureadingmagnifier.rurearchain.rurecessioncone.rurecordedassignment.ru
rectifiersubstation.ruredemptionvalue.rureducingflange.rureferenceantigen.ruregeneratedprotein.rureinvestmentplan.rusafedrilling.rusagprofile.rusalestypelease.rusamplinginterval.rusatellitehydrology.ruscarcecommodity.ruscrapermat.ruscrewingunit.ruseawaterpump.rusecondaryblock.rusecularclergy.ruseismicefficiency.ruselectivediffuser.rusemiasphalticflux.rusemifinishmachining.ruspicetrade.ruspysale.ru
stungun.rutacticaldiameter.rutailstockcenter.rutamecurve.rutapecorrection.rutappingchuck.rutaskreasoning.rutechnicalgrade.rutelangiectaticlipoma.rutelescopicdamper.rutemperateclimate.rutemperedmeasure.rutenementbuilding.rutuchkasultramaficrock.ruultraviolettesting.ru
Wto Gru 03, 2024 12:26 Ogl±da profil u¿ytkownika Wy¶lij prywatn± wiadomo¶æ
Reklama







Wto Gru 03, 2024 12:26
Wy¶wietl posty z ostatnich:    
Odpowiedz do tematu    Forum Serwer Warland Strona G³ówna » Regulamin Wszystkie czasy w strefie CET (Europa)
Strona 1 z 1
Skocz do: 
Nie mo¿esz pisaæ nowych tematów
Nie mo¿esz odpowiadaæ w tematach
Nie mo¿esz zmieniaæ swoich postów
Nie mo¿esz usuwaæ swoich postów
Nie mo¿esz g³osowaæ w ankietach

Serwer Warland  

To forum dzia³a w systemie phorum.pl
Masz pomys³ na forum? Za³ó¿ forum za darmo!
Forum narusza regulamin? Powiadom nas o tym!
Powered by Active24, phpBB © phpBB Group
Design by Vjacheslav Trushkin / Easy Tutorials (Photoshop Tutorials)