Core
 

CORE INSIGHT ENTERPRISE: SECURITY TESTING AND MEASUREMENT SOLUTION OVERVIEW

The First Continuous, Real-World Security Testing Solution

CORE INSIGHT™ Enterprise is a new security testing and measurement solution that will be available from Core Security Technologies in late 2010. Offered in both appliance and software versions, INSIGHT Enterprise provides continuous, real-world assessments of threats to your critical business assets by identifying weaknesses in IT security systems and pinpointing exploitable vulnerabilities throughout your organization.

With CORE INSIGHT Enterprise, you can:

 

Answer the Question, “Are we more secure than yesterday?”

Business executives, compliance officers, board members and others look to you for practical answers about the effectiveness of your organization’s security controls. By continuously identifying, proving and tracing exposures to explicit business assets, CORE INSIGHT Enterprise enables you to maintain constant awareness of your organization’s real-time security posture. As a result, you’re able to provide definitive answers about business risks, get the resources you need to strengthen defenses, and track changes in your security posture over time.

^ Back to top


Close the Gap Between Security Data and Business Risk

CORE INSIGHT Enterprise automatically searches for exploitable pathways throughout your shifting IT infrastructure to identify key resources that are exposed to cyber criminals. All you need to do is define which assets are important to your organization, such as …

  • Your systems for financial transactions, operations controls, and other mission-critical functions
  • Your databases housing sensitive information such as customer records, financial data, or patient histories
  • Your data types such as credit card numbers, social security numbers, or employee ID numbers

… and INSIGHT replicates real-world attacks that seek to compromise those specific assets. The solution’s dashboards and reports categorize and present test results using terminology that is relevant to your business.

^ Back to top


Proactively Test Your Defenses with Real-World Offense

CORE INSIGHT Enterprise is set apart from other security solutions via its ability to replicate actual attacks against your systems and data – in a safe and controlled manner. It does not scan for potential vulnerabilities, monitor for incidents, or model threats. It proactively uses the same offensive techniques that criminals employ to find and exploit weaknesses that expose critical assets to data breaches.

INSIGHT Enterprise offers real-world security testing and measurement across:

  • Web applications: Replicate SQL injection, cross-site scripting, and remote file inclusion threats.
  • Network systems: Exploit OS, application and services vulnerabilities that allow attackers to compromise and escalate privileges on network systems.
  • End-users and endpoint systems: Test email security awareness and endpoint defenses through phishing attack replication

^ Back to top


Continuously Assess the Security of Large Environments

A fully automated testing and measurement solution, CORE INSIGHT Enterprise enables you to proactively assess the security posture of business assets across large environments without requiring additional headcount. Within a few minutes, a campaign can be configured to continuously identify and exploit chains of vulnerabilities that create pathways to sensitive systems and data.

  • Keep pace with evolving infrastructure through dynamic testing
    Your organization’s security posture is in a state of constant flux as systems are rolled out and updated. INSIGHT Enterprise utilizes a patent-pending attack planning algorithm with GPS-like adaptive intelligence that dynamically learns your environment and adjusts tests to seek new paths to critical assets as systems are added and updated.
  • Delegate assessments throughout the enterprise
    Campaigns can be delegated to IT groups, developers and other departmental staff, enabling them to test pre-defined areas and assets without violating access controls.
  • Stay ahead of new threats
    INSIGHT Enterprise is updated 20-30 times per month with new commercial-grade exploits and other testing

^ Back to top


Optimize Your Security Infrastructure

CORE INSIGHT Enterprise includes a variety of connectors to popular security solutions, including:

  • Network & web vulnerability scanners
    Import scan results and validate them for exploitability
  • Network management systems
    Import network topographies to define assessment surfaces
  • DLP solutions
    Pinpoint data leakage issues during INSIGHT assessments
  • Patch management solutions
    Enable immediate remediation by deploying patching agents when INSIGHT identifies penetration points

^ Back to top

Related Content
Solutions | Products and Services | CoreLabs | News and Events | Partners | Company
Core Security Technologies © 2010 All rights reserved       Disclaimer     Privacy Statement