Educause Security Discussion mailing list archives

Re: Security Remediation Tracking Software


From: "Cap, Brianne" <Brianne.Cap () DEVRY EDU>
Date: Thu, 5 Mar 2020 20:59:08 +0000

I am looking at solutions as well. So far, a product offered by CyGov is the front runner. We’ve also reviewed the 
product offered by KnowBe4, KCM GRC. It was really just a project management platform with some extra features.

Regards,

Brianne Cap | Sr. Program Manager, Information Security
P 630.799.0135 | M 630.881.7518 | E brianne.cap () devry edu
1200 E. Diehl Rd. | Naperville, IL 60563 | devry.edu<http://devry.edu/>

[cid:image003.jpg@01D5F2FD.8D5DF390]


From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Blake Brown
Sent: Thursday, March 5, 2020 1:42 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Security Remediation Tracking Software

Good afternoon,

What software are you using for tracking security audit remediation items. Currently we are spreadsheet based and while 
it works we are running into some challenges using this method. One thought is to build a home grown system using a 
basic web front end / SQL backend but if there is already reasonability priced canned software that can provide this 
functionality we are open to purchasing it.

Our current tracking needs are comprised of items such as Owner, Risk, Host Info, Protocol, Port, Description of issue, 
Possible Solution, Reference Links, Remediated (y/n), Remediation date, Notes, Re-tested by, Re-test pass/fail  and 
Re-test date. We cannot foresee needing anything to elaborate but rather a tool that easy for the responsible party to 
identify the cause, remediate and verify. There should also be a simple reporting function to provide analyst / 
executive reporting.


Thanks,
Blake Brown
Infrastructure Manager



**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://www.educause.edu/community<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cbrianne.cap%40DEVRY.EDU%7C36d6241981b74ba680c108d7c13e9cbc%7Cf979c99c51ab4ff686e035fd2874788f%7C0%7C1%7C637190346993427558&sdata=ZZhseUQvr%2FfNHo%2FHLgROrNwrYwe%2Fbuekc5IS%2FU5WJko%3D&reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Current thread: