课程: ISC2 Certified Information Systems Security Professional (CISSP) (2024) Cert Prep

免费学习该课程!

今天就开通帐号,24,600 门业界名师课程任您挑!

Identify scan targets

Identify scan targets

- [Instructor] As you get a vulnerability management program underway, your first step is to develop requirements for that program. You'll think through whether the program is based upon a general desire to improve security, a response to regulatory requirements, or a reaction to corporate policy. Once you've done that, your next step is to turn those general requirements into a list of the specific systems and networks that you want to scan. In order to create this list, you need to have an asset inventory that you can trust. If your organization practices good asset management already, you may find that you already have this inventory ready to draw into your vulnerability management program. You might find that your organization's configuration management tools already have a complete inventory of systems and devices on your network, and in the best case, that the inventory is kept up to date with information from regular network discovery scans. However, if you don't have this…

内容