Educause Security Discussion mailing list archives

Re: GreenBone vs Tenable


From: Kristen Dietiker <kdietiker () SCU EDU>
Date: Wed, 18 Sep 2019 16:59:49 -0700

We've been unhappy with Rapid7's InsightVM because of false positives
related to backporting on linux machines. We're currently doing trials of
both Tenable SC and Kenna Security's threat intelligence platform. Kenna
Security doesn't have a scanner so we're evaluating it with Nessus with
good results.

*Kristen Dietiker*
Chief Information Security Officer
Santa Clara University
(408) 554-5554
_______________________________________________________________
Duo 2-Factor Authentication is coming! Learn more at https://www.scu.edu/duo


On Wed, Sep 18, 2019 at 2:52 PM Barton, Robert W. <bartonrt () lewisu edu>
wrote:

Afternoon,



Rapid7 is on my radar as well, but the GreenBone product is a real
question mark; they seem to be larger in Germany.



Robert W. Barton

Executive Director of Information Security and Policy

Lewis University

One University Parkway

Romeoville, IL  60446-2200

815-836-5663



*From:* The EDUCAUSE Security Community Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> *On Behalf Of *Pete, Andrew
*Sent:* Wednesday, September 18, 2019 4:47 PM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* Re: [SECURITY] GreenBone vs Tenable



Hi Robert,



I don’t have any experience with Greenbone but I’ve had expose to some of
Tenable’s products as well as Rapid 7’s InsightVM.  I did a bake off in
spring 2018 between Tenable’s Security Center, Tenable.io and InsightVM to
determine which product fit our needs the best.  I found that Tenable’s
products can be sluggish and cumbersome to use at times compared to
InsightVM.  InsightVM was a more stable platform and had a number of
features that Tenable’s rpoducts did not.  One of those features that I
really like is InsightVM provides recommended remediation steps for most
vulnerabilities which can really help when delegating remediation efforts
to other teams/individuals.  In the end we ended up moving forward with
InsightVM.



I’m sure that the Tenable products have changed in the year and a half
since I tried them out so the information I am giving you may not be
entirely accurate anymore.  I will add that in my last job, I worked as a
professional services engineer and did a tenable deployment for a customer
near the end of 2015.  At the time, I found that the Tenable products were
sluggish and cumbersome as well so there is a bit of a track record there.



Both Tenable and InsightVM should be more than happy to set you up with
evaluations.  I would recommend that you do some trials and evaluate the
products against your needs.





*Andrew Pete*

*Information Security Architect*



*New England Institute of Technology*

One New England Tech Boulevard

East Greenwich, RI 02818-1205

401-780-4460 (Direct)

apete () neit edu



*[image: NEIT_Full_Stack_H_White_BG_PNG1]*









*From:* The EDUCAUSE Security Community Group Listserv <
SECURITY () LISTSERV EDUCAUSE EDU> *On Behalf Of *Barton, Robert W.
*Sent:* Wednesday, September 18, 2019 5:17 PM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* [SECURITY] GreenBone vs Tenable



*This message originated outside of New England Institute of Technology.
Use caution when opening attachments, clicking links or responding to
requests for information.*

Afternoon,



Does anybody have any experience with NNT/GreenBone?  I’m seeing a large
price difference between them an Tenable (with Tenable being the big boy).
I’m starting an investigation into vulnerability management, so ideas or
options are welcome.



Robert W. Barton

Executive Director of Information Security and Policy

Lewis University

One University Parkway

Romeoville, IL  60446-2200

815-836-5663



This message (including any attachments) is intended only for the use of
the individual or entity to which it is addressed and may contain
information that is non-public, proprietary, privileged, confidential, and
exempt from disclosure under applicable law or may constitute as attorney
work product. If you are not the intended recipient, you are hereby
notified that any use, dissemination, distribution, or copying of this
communication is strictly prohibited. If you have received this
communication in error, notify us immediately by telephone at
(815)-836-5950 and (i) destroy this message if a facsimile or (ii) delete
this message immediately if this is an electronic communication. Thank you.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFAg&c=iVyFbx9TtkoGWXYs40w9MA&r=TRbysQ0U6LHo9ajQhKsO87oExl4CHXZjx_jkLW_P6NA&m=gMLOCUsuI9BxYb3pnNarxtkv-62VFkqQ08A8HTv_hNQ&s=VAjEOfqDzfYh48SB12VMgbtJ3ITeRmWZBJq3pzdv4nM&e=>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFAg&c=iVyFbx9TtkoGWXYs40w9MA&r=TRbysQ0U6LHo9ajQhKsO87oExl4CHXZjx_jkLW_P6NA&m=gMLOCUsuI9BxYb3pnNarxtkv-62VFkqQ08A8HTv_hNQ&s=VAjEOfqDzfYh48SB12VMgbtJ3ITeRmWZBJq3pzdv4nM&e=>

This message (including any attachments) is intended only for the use of
the individual or entity to which it is addressed and may contain
information that is non-public, proprietary, privileged, confidential, and
exempt from disclosure under applicable law or may constitute as attorney
work product. If you are not the intended recipient, you are hereby
notified that any use, dissemination, distribution, or copying of this
communication is strictly prohibited. If you have received this
communication in error, notify us immediately by telephone at
(815)-836-5950 and (i) destroy this message if a facsimile or (ii) delete
this message immediately if this is an electronic communication. Thank you.

**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://www.educause.edu/community
<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.educause.edu_community&d=DwMFAg&c=iVyFbx9TtkoGWXYs40w9MA&r=TRbysQ0U6LHo9ajQhKsO87oExl4CHXZjx_jkLW_P6NA&m=gMLOCUsuI9BxYb3pnNarxtkv-62VFkqQ08A8HTv_hNQ&s=VAjEOfqDzfYh48SB12VMgbtJ3ITeRmWZBJq3pzdv4nM&e=>


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community


Current thread: