On vulnerability, root cause, white-listing and compliance
ID: b494d90b-7189-582c-a630-977520e7749f
STIX ID: report--b494d90b-7189-582c-a630-977520e7749f
Feed Name: SensePost Blog
This piece argues for shifting vulnerability management from blacklist-based detection to whitelist/baseline-driven approaches, focusing on root-cause identification (such as patch management issues) and compliance benchmarking (e.g., via Nessus) to reduce false positives and improve efficiency. It proposes continuously updated secure OS baselines for comparison across environments, while acknowledging difficulties in areas without clear baselines, like web servers and web applications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
