BMC and Qualys have launched what they say is the first solution to tie vulnerability information to automated remediation actions. This dramatically reduces the window of vulnerability while simultaneously improving IT operational performance.
While data breaches can be catastrophic, most are preventable, as 80 percent of exploits utilise vulnerabilities with known fixes. One of the causes of successful attacks is the misalignment of objectives between the security team, responsible for identifying vulnerabilities, and the IT operations team, responsible for implementing the changes to the systems. This misalignment is the SecOps gap.
“Given the number of information security vulnerabilities that exist in the world today, security and IT operations can benefit tremendously from tighter collaboration and more efficient workflow,” said Michael Allen, information security officer at Morningstar, Inc. “With Intelligent Compliance, we now have an integrated solution to automate our information security processes, greatly reducing time and cost.”
The joint solution, Intelligent Compliance, addresses the gap through a combination of security and compliance audit data from Qualys Vulnerability Management (VM) with the associated action from BMC BladeLogic Server Automation to remediate the vulnerability. Specifically, it helps:
Reduce the Window of Exposure to Vulnerabilities – accelerate remediation of vulnerabilities through automatiom
Avoid Downtime – make remediation actions predictable and safe, minimising both planned and unplanned outages
Increase Speed and Frequency of Audits – run automated audits as frequently as needed, or even on-demand, without impacting other operational activities
Stay Compliant with Industry Regulations – take advantage of pre-built audit and remediation content for common policies
Lower the Cost of Audit and Remediation – automate actions that were previously manual
“The SecOps gap is a significant problem, undermining companies’ efforts to keep their customer information and intellectual property safe and secure,” said Phil Harris, CTO and president of Cloud and Data Center Automation at BMC. “The BladeLogic suite has always been a great way to remediate vulnerabilities and compliance issues quickly and safely, but now we are excited to combine that with Qualys’ extremely detailed vulnerability scanning data.”
“Reducing the window of exposure to vulnerabilities on critical systems is a fundamental proactive measure to deflect cyber attacks,” said Philippe Courtot, chairman, and CEO of Qualys, Inc. “Together with BMC, we can now offer the ability to not only identify threats in real time, but to significantly accelerate remediation while greatly reducing the time and cost required to conduct audits.”