Archive for 'Bandolier'
Bandolier Audit Files Put Through Their Paces
More exciting news from the Bandolier project… we are wrapping up some extensive collaborative testing with one of our vendor partners. It is the most thorough outside review of the Bandolier audit files to date and we are very pleased with the results. With each development and testing cycle, we are able to apply what [...]
Author: Jason Holcomb
Posted: August 18th, 2008 under Assessment Tools, Bandolier.
Comments: none
Nessus WMI Compliance Checks
Tenable recently announced an additional feature for the Nessus compliance checks — support for WMI (Windows Management Instrumentation). I have used WMI for some scripting in the past and even played with WMIC. Still I wasn’t sure how or if this capability would help with Bandolier so I decided to use the WMI Object Browser [...]
Author: Jason Holcomb
Posted: August 8th, 2008 under Assessment Tools, Bandolier.
Comments: none
Vendor Involvement in Bandolier Audit File Development
Once you’ve done something a few times, you learn what works well and what doesn’t. This is true for a lot of things in life and has certainly proven to be the case for the Bandolier audit file development process. The big lesson learned for Bandolier: vendor participation in the audit file development is extremely [...]
Author: Jason Holcomb
Posted: July 28th, 2008 under Bandolier.
Comments: none
Bandolier Update: Audit Files Now Available in Alpha Versions
The first Bandolier results are out! We are pleased to announce that alpha versions of Bandolier audit files for Siemens Power TG and Telvent OASyS DNA are now available for download. These files, which work with the Nessus vulnerability scanner, will audit and compare your deployments with an optimal security configuration. They are available to [...]
Author: Jason Holcomb
Posted: July 16th, 2008 under Bandolier.
Comments: none
More Nessus News: Tenable Adds Audit Files for AIX
Tenable Network Security, the makers of Nessus, announced today that they have added audit files for AIX. You can read more about it on the Tenable blog. It’s good to see more and more operating systems added to the list. We don’t have any AIX systems slated for Bandolier but I know that it’s out [...]
Author: Jason Holcomb
Posted: July 2nd, 2008 under Assessment Tools, Bandolier.
Comments: none
Nessus DirectFeed Gets a New Name and Goes on Sale
Since we just can’t seem to stop talking about naming issues related to the Bandolier project (Audit File vs. Template, Categories, Severity Ratings), here’s one more: Tenable is changing their Nessus DirectFeed product to ProfessionalFeed. This annual subscription service is a prerequisite for using the Bandolier audit files. Among other things, it also gives you [...]
Author: Jason Holcomb
Posted: June 25th, 2008 under Assessment Tools, Bandolier, Nessus SCADA Plugins, Security Vendor.
Comments: 2
Bandolier: Audit File or Template – What’s in a Name?
One of the fun things about working for Digital Bond is that we get to share some of our back-end conversations and thought processes here on the blog when we feel they will be of benefit. We recently had one of those discussions regarding terminology for the Bandolier project. It started something like this:
Dale: So [...]
Author: Jason Holcomb
Posted: June 23rd, 2008 under Bandolier, DoE Research Project.
Comments: 3
Bandolier and NERC CIP
We’ve talked occasionally about using the Bandolier audit templates to help with various standards compliance efforts. There is now a SCADApedia article that more formally describes how and where Bandolier links to the NERC CIP requirements.
Earlier this week I presented on our DoE projects to the SPP CIPWG, a group particularly concerned with NERC CIP. [...]
Author: Jason Holcomb
Posted: June 19th, 2008 under Bandolier, DoE Research Project.
Comments: none
Bandolier Update: First Set of Audit Templates Revealed
We have been working feverishly on Bandolier for several months now and have blogged about some of the issues and progress along the way. Notably absent, however, has been discussion about which applications we have assessed and which respective audit files are under development. So I am especially pleased to be able to announce the [...]
Author: Jason Holcomb
Posted: June 10th, 2008 under Bandolier.
Comments: 2
Bandolier - - Take 3
There has been some talk on Bandolier on mailing lists and blogs, and it is clear that we have not done a good enough job describing what Bandolier will do and what Bandolier will not do. Actually, a number of these discussions have been helpful in understanding the best way to describe Bandolier to a [...]
Author: Dale Peterson
Posted: June 8th, 2008 under Assessment Tools, Bandolier, Calculating Risk.
Comments: 4