CIOview Delivers SecurityNOW!: Provides Financial Transparency for IT Security
Increases Security Auditor Productivity 90%
Maynard, MA -- CIOview, the leading provider of IT financial software, announced availability of SecurityNOW! SX, a free software package that lets organizations complete a comprehensive IT security self-assessment in 30 minutes or less.
SecurityNOW! is designed for the security novice and expert alike to:
- Rapidly identify key security vulnerabilities and assign a financial cost to each
- Forecast how their security environment will change over time
- Evaluate various loss control policies and their effectiveness at reducing risk
- Calculate the Return On Security Investment (ROSI) for 100s of possible strategies
Part and parcel of SecurityNOW! is a risk quantification using the commonly accepted framework, Risk Assessment Value (RAV). RAV allows organizations to compare their security between departments and over time. In fact, RAV is increasingly the most common security measure demanded by regulatory bodies. According to Pete Herzog, Managing Director of the Institute for Security and Open Methodologies (ISECOM), "This is the first time that a software product has embodied an international security assessment methodology along with a rapid method to determine the financial implications of IT security. Organizations now can have their cake and eat it too -- a practical, easy-to-use metrics software package based on a recognized methodology that's also free."
Utilizes ISECOM's Global Security Standard
CIOview's SecurityNOW! has been given ISECOM's Seal of Approval for bringing financial transparency to the world of IT security. SecurityNOW! takes ISECOM's internationally-accepted security methodology and transforms it into a world-class, easy-to-use software package. The software embodies the six capabilities described by ISECOM as the key to making security transparent:
- Accelerated - 30 minutes or less to complete
- Accessible - 5 MB of industry benchmark data
- Objective - a consistent, open methodology
- Customized - quantifies risk based on a user's responses
- Forward-looking - forecasts risk over time
- Graphical - charts compare security to financial costs, tying the two together
Two Versions: Professional reduces time to deliver audit results by 90%
SecurityNOW! is available in two versions: SX and Professional. SecurityNOW! SX is a complete security analysis software system based on the OSSTMM, and is available at no charge at the CIOview web site as well as Security Partner sites.
Security professionals and auditors will benefit from SecurityNOW! Professional. The Professional edition provides a variety of automation features that reduces the time to deliver a set of audit results from 30 days to 3 days. Built upon the foundation of the SX version, SecurityNOW! Professional adds the following capabilities:
- Validated data can be imported from a number of network port and vulnerability detection scans;
- Verified data from OSSTMM or similar security audits can be directly entered;
- A financial and business case for security spending as well as a certified audit report can be published with one mouse click;
- All business case reports can be electronically shared with collaborators and coworkers using the free SecurityNOW! SX version.
Endorsed by Worldwide Security Partners
SecurityNOW! is endorsed by a variety of worldwide Security Partners, who have made the software available via their web sites, including:
- ISECOM (www.isecom.org): an open-source collaborative community dedicated to providing practical security awareness, research, certification and business integrity.
- Above Security (www.abovesecurity.com): specializes in mitigating computer risk and offers complete 24/7 managed monitoring and strategic information security services.
- CISSP Open Study Guides (www.cccure.org): is a web portal dedicated to helping security professional reach their CISSP or SSCP certification.
- Fullerton Infosec (www.fullertoninfosec.com) is a full service security-consulting firm specializing in OSSTMM security testing as well as various forms of security education.
- GCP Global (www.gcpglobal.com) is dedicated to protecting the information assets of private and public organizations against attacks committed by competitors, hackers, industrial spies, employees, and others.
Pricing and Availability
SecurityNOW! SX and SecurityNOW! Professional are both generally available. SecurityNOW! SX may be downloaded without cost at www.cioview.com as well as at the web sites of SecurityNOW! partners listed above. SecurityNOW! Professional edition is priced at $3,999 for a 12-month license, and may be purchased through CIOview's web site.
About CIOview
CIOview is the industry standard provider of software products that configure, cost and compare technology solutions, so that IT professionals make better purchasing decisions. Use by more than 80% of Fortune 100 companies, CIOview is the standard for comparing value of IT solutions.
About ISECOM
ISECOM is an open-source collaborative community dedicated to providing practical security awareness, research, certification and business integrity. ISECOM oversees the development of the OSSTMM, an international standard methodology and best practices for security assessment. The OSSTMM is the most widely adopted approach worldwide to assessing the security of a company's computer systems.
CIOview® and ROInow!® are registered trademarks, and TCOnow! is a trademark, of CIOview Corp.
|