« If security is control, how can you be secure and not in control? | Main | Is your data safer with a 3rd party then you? »

June 21, 2006

Its time to get real about agentless NAC and Nessus

I have been reading a lot lately about companies that tout the benefits of agentless NAC and their unique (even patent pending) approach to it.  Lets be really clear here.  If you are using Nessus for NAC scanning, you are using the wrong tool, at the wrong time, for the wrong job.  On top of this, you may be subjecting yourself to significant liability for improper use of licensed software.  If you don't believe me about the potential legal liabilities, ask Ron Gula, the CEO of Tenable Network Security

What really gets me ranting though, are companies that know full well their use of Nessus is most likely illegal. So what do they do?  They hide the fact they are using Nessus under the covers and now make their customers potential co-conspirators in this improper use. They put out slick marketing and file, probably impossible to obtain final approval, patent filings. I am further amazed that supposedly legitimate journalists and test lab reviewers write about companies using this software with this improper use of Nessus and don't bother to do their homework and make sure they are not also encouraging their customers to potentially take on this liability.

I am really sick of the smoke and mirrors game being used to confuse customers about what they are getting and how it is getting done.  If you are looking at either NAC solutions or vulnerability management, you should point blank ask your potential vendors, do they use Nessus and if they do how are they doing it legally.  If you have any question on what to ask for, write me, I would be happy to help.  I have spent a lot of time researching the licensing issues here.  On another day, I will write about why Nessus is the wrong tool, at the wrong time, for the wrong job in NAC

Authors note: In the interest of fair disclosure, let mention that our VAM, vulnerability management product, does use Nessus. Not for NAC obviously though.  In another article I will explain how we use Nessus legally.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d8352ebadf53ef

Listed below are links to weblogs that reference Its time to get real about agentless NAC and Nessus:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005