Security Basics mailing list archives

Risk Tracking Software


From: Peter Milleson <pitr256 () gmail com>
Date: Thu, 17 May 2012 12:07:34 -0500

Hi all,

Anyone know of a good risk/vulnerability tracking software preferably
open source? Most of the security related tracking software is geared
more towards incident handling like RTIR, AIRT, etc. I'm looking for a
way to track vulnerabilities/exploits as they are announced sort of
like Mitre/CVE or NVD but less geared towards tracking every
vulnerability and more towards specific ones I'm interested in.

Here's basically the outline of some of the things I'd like to track
with this software:

Vuln Name:
CVE:
Product:
Description:
Affected Versions: N/A
Patched Version: N/A
Supporting intel:
Impact:
RISK (= threat X vuln X impact) value: xx/125:
Threat (1 to 5):
Vuln (1 to 5):
Impact (1 to 5):
Num of hosts affected:

If there isn't any software doing something like this, I might try
modifying some other incident tracking software to do it.

Any tips or pointers would be greatly appreciated.

Thanks in advanced.

Peter

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: