KENSINGTON, Md. - Steve Jones wants to know about every single weakness in the credit union computer network, and he wants to know who is going to deal with each vulnerability.
To that end, the CTO at Signal Financial FCU here uses three vulnerability scanners to routinely scan the CU network. "We do vulnerability scanning backwards and forwards," he said. "If one scanner misses something, the other will get it."
To top it off, the $268-million CU hires an external scanning firm to validate the credit union's findings, he said.
Jones also wants his scanning systems to offer comprehensive suggestions about how to handle each vulnerability-but he hasn't yet found a scanner that excels in what's known as "remediation."
"None of our scanners has a good remediation plan," he said. "When the scanners find a vulnerability, you have to go poke through Google to find the patches. A remediation plan could save me a couple of hours of searching for each solution."
Sometimes, Jones finds that the only solution to a vulnerability is to disable or remove the associated network service. "There's just nothing you can do to patch some critical vulnerabilities," he said.
The best of the three network scanners at Signal Financial finds more vulnerabilities than the other scanners, and it also assigns responsibility for fixing a vulnerability to a particular technology team member, based on that person's expertise, Jones continued.
That scanner is the VAM vulnerability management platform, provided by Superior, Colo.-based StillSecure, which Signal Financial started using about one year ago.
"VAM is the best at finding all the vulnerabilities," said Jones. "It finds that extra oddity because the vulnerability signatures are more comprehensive."
VAM automatically scans "anything with an IP address, essentially," for vulnerabilities as identified by the Common Vulnerabilities and Exposures (CVE), he said. CVE is a free dictionary of internationally known weaknesses provided by The MITRE Corp., a not-for-profit organization.
VAM can "manage the complete life cycle of vulnerabilities"-from identifying devices on the network to making sure they are free of known vulnerabilities, explained Alan Shimel, StillSecure chief strategy officer. "VAM proactively hardens your network assets so they are impervious to network attacks."
But the pièce de résistance is the StillSecure Vulnerability Repair Workflow, which assigns vulnerabilities for repair and then notifies Jones of the repair status, according to Jones.
"You can divvy up the repair work among your administrators or engineers in different areas in the network," he said. The technology team at Signal Financial includes Jones; an information services manager; a senior systems engineer; three user-support technicians and soon, a systems engineer.
Jones can set different scanning schedules for any pre-defined groups of devices within the network. "That makes it routine, and saves us from the potential of forgetting to scan a device at any one time," he said.
Such automation would save many a smaller CU, Jones added. "Smaller CUs don't have the resources to address network security. I keep thinking we'll start a CUSO that could go out and help the smaller CUs."
VAM is part of StillSecure's suite of layered, network security products, which also includes Safe Access, a network access control (NAC) solution and Strata Guard, a network-based intrusion detection and prevention system (IDS/IPS). Together, the products "manage network access, find and fix network vulnerabilities, and detect and block network attacks," said Shimel.
Signal Financial currently uses a separate third-party IDS/IPS and relies on its own access lists to control the network-Jones said he isn't "sold" on any NAC solution yet.
Shimel awards a "B" grade overall to CUs for "locking up their networks and security," he said. "But they've made significant progress in the last two to three years. The credit union industry seems very open to outsourcing security, which is a little different from other areas of the financial vertical, where outsourcing a critical, core requirement has not seen widespread adoption."
MORE
Read more about vulnerability management at cujournal.com and search the following bolded terms in the archive:
AFCU Flies Higher After Purging Multiple Systems For 1 App
Why One CU Is Investing In Ways To Automate The Patching Process
Go (con)Figure!
For info on this story:
* www.sfonline.org
* www.stillsecure.com(c) 2008 The Credit Union Journal and SourceMedia, Inc. All Rights Reserved.http://www.cujournal.com/ http://www.sourcemedia.com/










