Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Introduction
Gxgt{"dcvvnggnf"eqoocpfgt"wpfgtuvcpfu"vjg"uvtcvgike"pgeguukv{"qh"tgnkcdng"kpvgnnkigpeg0"Ykppkpi"dcvvngu"
fgrgpfu"qp"ceewtcvg"wpfgtuvcpfkpi"qh"gpgokgu."vjgkt"vcevkeu"cpf"iqcnu."ygkijkpi"tkumu"cickpuv"rqvgpvkcn"
fcocig."cpf"fgrnq{kpi"tguqwtegu"vq"okvkicvg"qt"pgwvtcnk|g"vjtgcvu0"Icvjgtkpi"kphqtocvkqp"ku"lwuv"c"uvctvkpi"
rqkpv="oqtg"korqtvcpvn{."ku"cp{"qh"kv"tgngxcpv"qt"ogcpkpihwnA"Ykvjkp"cnn"vjg"ejcvvgt"cpf"pqkug."ghhgevkxg"
eqoocpfgtu"fkuegtp"vjg"qpg"rgtegpv"qh"wughwn"kpvgnnkigpeg"cpf"hqnnqy"vjtqwij"ykvj"cevkqp0"
Gxgt{"KV"ugewtkv{"rtqhguukqpcn"mpqyu"vjcv"vjg"dcvvng"vq"rtqvgev"KV"tguqwtegu"cpf"fcvc"ku"hwnn{"gpicigf0"Kp"kvu"
2011 Data Breach Investigations Report."Xgtk|qp"uvwfkgf"983"fcvc"eqortqokug"kpekfgpvu"vjcv"qeewttgf"kp"
4232."eqorctgf"vq"lwuv"qxgt";22"vqvcn"dtgcejgu"uvwfkgf"dgvyggp"4226"cpf"422;0"Xgtk|qp"tgrqtvgf"vjcv"qh"
cnn"dtgcejgf"tgeqtfu."72"rgtegpv"kpxqnxgf"uqog"hqto"qh"jcemkpi"cpf"6;"rgtegpv"kpenwfgf"wug"qh"ocnyctg0"
Vjg"qpiqkpi"uvtwiing"vq"rtgxgpv"jcemgtu"htqo"dtgcejkpi"cuugvu"cpf"ocnyctg"htqo"ickpkpi"c"hqqvjqnf"
tgswktgu"c"xwnpgtcdknkv{"ocpcigogpv"uvtcvgi{"vjcv"dgikpu"ykvj"c"eqortgjgpukxg"ogcuwtgogpv"qh"
ugewtkv{"tkum0"Qticpk|cvkqpu"owuv"gzcokpg"vjg"gpvktg"KV"uvcem."kpenwfkpi"vjg"qrgtcvkpi"u{uvgo."pgvyqtm."
crrnkecvkqpu."cpf"fcvcdcugu0"Vjg"e{eng"qh"fkueqxgtkpi"cuugvu."ecrvwtkpi"cpf"rtqeguukpi"xwnpgtcdknkv{"
fcvc."kfgpvkh{kpi"cevwcn"tkumu."vguvkpi"cpf"rtkqtkvk|kpi"okvkicvkqp"vcumu."cpf"xgtkh{kpi"ghhgevkxg"eqpvtqnu"
itqyu"oqtg"eqorngz"ykvj"gxgt{"pgy"vgejpqnqi{"vjcv"cffu"eqpxgpkgpeg"dwv"ownvkrnkgu"tkum"qh"c"dtgcej"
qt"kpekfgpv0"Vjgug"pgy"vgejpqnqikgu"kpenwfg"f{pcoke."xktvwcnk|gf"gpxktqpogpvu"cpf"ugtxkegu"qwvukfg"
vtcfkvkqpcn"rj{ukecn"KV"kphtcuvtwevwtgu."uwej"cu"xktvwcnk|gf."enqwf/dcugf"ugtxkegu"cpf"uqekcn"pgvyqtmkpi0"
Figure 1:"Vjg"Ugewtkv{"Tkum"Kpvgnnkigpeg"e{eng""c"jqnkuvke"crrtqcej"vq"okpkok|kpi"tkum"
Tcrkf9"cfftguugu"vjg"pggf"hqt"f{pcoke."kp/fgrvj"tkum"ocpcigogpv"ykvj"Ugewtkv{"Tkum"Kpvgnnkigpeg."
c"jqnkuvke"crrtqcej"vq"okpkok|kpi"tkum"*Hkiwtg"3+0"Kv"ku"dcugf"qp"c"wpkgf"uqnwvkqp"ugv"vjcv"kpenwfgu"
xwnpgtcdknkv{"ocpcigogpv."rgpgvtcvkqp"vguvkpi."cpf"dguv"rtcevkegu0"Ugewtkv{"Tkum"Kpvgnnkigpeg"jgnru"
qticpk|cvkqpu"fgvgev"xwnpgtcdknkvkgu."rtkqtkvk|g"tkumu."cpf"xcnkfcvg"vjtgcvu"kp"c"enqugf/nqqr"u{uvgo0"
617.247.1717
www.rapid7.com
Dgikppkpi"ykvj"cp"wpfgtuvcpfkpi"qh"vjg"pggf"hqt"ghhgevkxg"tkum"ocpcigogpv"hqnnqygf"d{"c"fgpkvkqp"qh"
vjg"gngogpvu"qh"tkum."vjku"fkuewuukqp"rtgugpvu"vjg"cfxcpvcigu"cpf"uvtcvgike"xcnwg"qh"Tcrkf9"Ugewtkv{"Tkum"
Kpvgnnkigpeg"hqt"{qwt"gpxktqpogpv"cpf"knnwuvtcvgu"kvu"qrgtcvkqp0
Ukvwcvkqp"tgrqtv<"Uvcvg"qh"vjg"Dcvvnggnf
Cvvcemu"ctg"uoctvgt."upgcmkgt."cpf"gcukgt"vq"rgtrgvtcvg"vjcp"
gxgt0"Vjg"Xgtk|qp"tgrqtv"hqwpf"vjcv";8"rgtegpv"qh"dtgcejgu"
ygtg"cxqkfcdng"vjtqwij"ukorng"qt"kpvgtogfkcvg"eqpvtqnu."vjcv"
72"rgtegpv"qh"tgeqtfu"dtgcejgf"wugf"uqog"hqto"qh"jcemkpi."cpf"
6;"rgtegpv"qh"tgeqtfu"dtgcejgf"kpeqtrqtcvgf"wug"qh"ocnyctg0"
Kpekfgpvu"kpxguvkicvgf"fwtkpi"4232"rtgugpvgf"vjg"nctiguv"
ecugnqcf"gxgt="kv"ycu"cnuq"gzvtgogn{"fkxgtug"kp"vjg"vjtgcv"
cigpvu."vjtgcv"cevkqpu."chhgevgf"cuugvu."cpf"ugewtkv{"cvvtkdwvgu"
kpxqnxgf0
Ugewtkv{"rtqhguukqpcnu"uvtwiing"vq"tgfweg"tkum"ykvj"nkokvgf"uvchh"
cpf"dwfigv0"Vq"cejkgxg"ghhgevkxg"tkum"ocpcigogpv."vjg{"owuv" Figure 1<"Xgtk|qp"4233"Fcvc"Dtgcej"
Kpxguvkicvkqp"Tgrqtv"*'"ejcpig"htqo"4232"
cdcpfqp"vjg"nkokvcvkqpu"cpf"gzrgpug"qh"vtcfkvkqpcn."tgcevkxg"
tgrqtv+
crrtqcejgu"kp"hcxqt"qh"c"rtqcevkxg."fcvc/ftkxgp"kpxguvogpv"
oqfgn0"Vjg{"owuv"qxgteqog"ugxgtcn"ejcnngpigu<"kpvgtrtgvkpi"
ocuukxg"coqwpvu"qh"fcvc."oqpkvqtkpi"f{pcoke"cuugvu."kpeqtrqtcvkpi"dqvj"eqornkcpeg"cpf"ugewtkv{"kpvq"dguv"
rtcevkegu."oqxkpi"dg{qpf"vtcfkvkqpcn"uecp/cpf/rcvej"crrtqcejgu"vq"korngogpv"ugewtkv{"dguv"rtcevkeg"
rtqitcou."cpf"vtwuvkpi"eqpxgpvkqpcn"rtkqtkvk|cvkqp"ogvjqfu"dg{qpf"vjgkt"ueqrg0"
Fcvc"vjtqwij"c"tg"jqug."Oquv"ugewtkv{"rqnkekgu"cfftguu"uqog"hqto"qh"xwnpgtcdknkv{"ocpcigogpv0"Ugewtkv{"
rtqhguukqpcnu"fgrgpf"wrqp"ceewtcvg"cuuguuogpvu"vq"fgvgtokpg"yjgvjgt"kpvgtxgpvkqp"ku"pgeguuct{"cpf"korngogpv"
rtqrgt"uvgru"hqt"okvkicvkqp"qt"tgogfkcvkqp0"Vjgtg"ku"pq"rtqdngo"qdvckpkpi"fcvc<"ugewtkv{"fgxkegu"cpf"uecppgtu"
igpgtcvg"vgtcd{vgu"qh"kv0"Vjg"ejcnngpig"ku"kpvgtrtgvkpi"fcvc<"kfgpvkh{kpi"vjqug"urgeke"xwnpgtcdknkvkgu"vjcv"vtwn{"
tgrtgugpv"c"engct"cpf"rtgugpv"tkum"vq"ugewtkv{0"
Ugewtkv{"qrgtcvqtu"pggf"uqnwvkqpu"vjcv"jgnr"vjgo"fkuvkpiwkuj"vjg"fcpigt"ukipcnu"htqo"vjg"pqkug0"Hqt"
gzcorng."c"okuukqp/etkvkecn"Ygd"ugtxgt"oc{"jcxg"vgp"mpqyp"xwnpgtcdknkvkgu."dwv"yjkej"qh"vjqug"vgp"rtgugpv"
igpwkpg"tkumA"Xwnpgtcdknkv{"ocpcigogpv"uqnwvkqpu"ujqwnf"kfgpvkh{"cpf"fkuokuu"ugxgp"qh"vjqug"cvvcemu"cu"
pqkug"cpf"ci"vjg"qvjgt"vjtgg"cu"ukipcnu"vjcv"tgswktg"vjgkt"cvvgpvkqp0
F{pcoke"cuugvu."uvcvke"vqqnu."Xktvwcnk|cvkqp"ku"tg/fgpkpi"jqy"KV"qrgtcvkqpu"dwknf"cpf"fgnkxgt"ugtxkegu."dwv"
xwnpgtcdknkv{"uecppgtu"jcxg"pqv"mgrv"wr0"Vtcfkvkqpcn"uecppgtu"rtqxkfg"c"upcrujqv"vjcv"iqgu"qduqngvg"ykvjkp"jqwtu"qt"
okpwvgu"ykvjkp"c"xktvwcnk|gf"gpxktqpogpv"yjgtg"XOu"iq"qpnkpg"cpf"qhkpg"qt"ejcpig"jquvu"cnn"fc{"nqpi0"Xktvwcnk|gf"
gpxktqpogpvucpf"vjg"tkumu"vjg{"rtgugpvctg"eqpuvcpvn{"ejcpikpi."cpf"uecppgtu"pggf"c"eqpvkpwqwu"fkueqxgt{"hgcvwtg"
vjcv"vtcemu"vjgug"ejcpigu"cu"vjg{"qeewt0"
Eqornkcpeg"fqgu"pqv"gswcn"ugewtkv{."Cpqvjgt"ejcnngpig"ku"vjg"rgtegrvkqp"vjcv"cvvckpkpi"eqornkcpeg"*g0i0."REK."
JKRCC."PGTE."HFEE+"tgfwegu"tkum"vq"ceegrvcdng"ngxgnu0"C"dtgcej"qh"cp"cuugv"wptgncvgf"vq"eqornkcpeg"ecp"ngcf"vq"vjg"
eqortqokug"qh"cuugvu"fggogf"eqornkcpv0"Qticpk|cvkqpu"urgpf"dknnkqpu"qh"fqnnctu"qp"ugewtkv{"uqnwvkqpu"vq"cfftguu"
eqornkcpeg."dwv"oquv"qh"vjgo"fq"pqv"hqewu"qp"fgrnq{kpi"vjqug"uqnwvkqpu"hqt"oczkowo"dgpgv"dg{qpf"eqornkcpeg0"
Tkum"tgfwevkqp"gpeqorcuugu"oqtg"vjcp"uecp/cpf/rcvej0 Ocp{"gpvgtrtkugu"vtwuv"vjcv"uecp/cpf/rcvej"ogvjqfu"
mggr"vjgo"ugewtg0"Rcvejkpi"kpjgtgpvn{"mggru"jcemgtu"cjgcf."dgecwug"xgpfqtu"v{rkecnn{"kuuwg"rcvejgu"kp"tgurqpug"
617.247.1717
www.rapid7.com
vq"jcemkpi"kpekfgpvu0"Yjkng"rcvejkpi"tgockpu"cp"korqtvcpv"ugewtkv{"uvgr."ugewtkv{"rtqhguukqpcnu"pggf"c"xctkgv{"qh"
rtqcevkxg"uqnwvkqpu"cpf"dguv"rtcevkegu"vq"rwv"vjgo"cjgcf"qh"jcemgtu"cpf"ocnyctg0"
Eqpxgpvkqpcn"tkum"rtkqtkvk|cvkqp"fqgupv"vgnn"{qw"gpqwij."Hqt"gzcorng."ocp{"gpvgtrtkugu"tgn{"uqngn{"qp"EXUU"ueqtgu"
vq"fgpg"vjtgujqnfu"hqt"okvkicvkqp0"Vjgug"dcug"EXUU"ogvtkeu"ogcuwtg"qpn{"vjg"rqvgpvkcn"tkum"*nkmgnkjqqf"rnwu"korcev+"
qh"c"ikxgp"xwnpgtcdknkv{."pqv"tgswktkpi"vgorqtcn"qt"gpxktqpogpvcn"ogvtkeu"vq"ecnewncvg"kvu"ueqtg0"Cu"uwej."dcug"ogvtkeu"
EXUU"ueqtgu"fq"pqv"eqpukfgt"vjg"yjqng"eqpvgzv"qh"vjg"kfgpvkgf"xwnpgtcdknkv{"vq"vjg"qticpk|cvkqp0"Eqpukfgt"vyq"
xwnpgtcdknkvkgu<"qpg"ykvj"c"dcug"ogvtke"EXUU"ueqtg"qh";"vjcv"ku"pqv"gzrnqkvcdng."xgtuwu"qpg"ykvj"c"EXUU"ueqtg"qh"7"vjcv"
ku"gzrnqkvcdng0"C"EXUU"ueqtg"qh";"oc{"rtqorv"c"pgvyqtm"qrgtcvkqpu"ocpcigt"vq"rtkqtkvk|g"vjg"z"qh"vjcv"xwnpgtcdknkv{"
qxgt"vjg"xwnpgtcdknkv{"ykvj"c"ueqtg"qh"70"Jqygxgt."yjgp"vjg"nqecn"gpxktqpogpv"ku"vcmgp"kpvq"eqpukfgtcvkqp."cpf"kv"
dgeqogu"mpqyp"vjcv"vjg"jkijgt"EXUU"ueqtgf"xwnpgtcdknkv{"ku"pqv"gzrnqkvcdng."yjkng"vjg"nqygt"xwnpgtcdknkv{"ku."vjgp"kv"
dgeqogu"qdxkqwu"vjcv"vjg"gzrnqkvcdng"xwnpgtcdknkv{"ujqwnf"vcmg"rtkqtkv{0"
Hqt"gzcorng<"OU32/244<"Xwnpgtcdknkv{"kp"XDUetkrv"Uetkrvkpi"Gpikpg"Eqwnf"Cnnqy"Tgoqvg"Eqfg"Gzgewvkqp"
jcu"c"EXUU"ueqtg"qh"9080"Vjku"ueqtg"ku"fgegrvkxgn{"nqy."dgecwug"vjku"rctvkewnct"xwnpgtcdknkv{"ku"gzrnqkvcdng"
d{"c"ocnyctg"mkv0"Tcrkf9"Ogvcurnqkv"uqhvyctg"ecp"gzrnqkv"kv0"Vjg"cevwcn"tkum"cuuqekcvgf"ykvj"vjku"rctvkewnct"
xwnpgtcdknkv{"ku"itgcvgt"vjcp"kvu"EXUU"ueqtg"kpfkecvgu"cpf"vjg"Tcrkf9"Tgcn"Tkum"ueqtg"qh":89"*qwv"qh"c"vqvcn"qh"
3222+"oqtg"ceewtcvgn{"tggevu"vjg"ugxgtkv{"qh"vjku"rctvkewnct"xwnpgtcdknkv{0"
Elements of Risk
Vjg"dcvvnggnf"eqoocpfgt"tgnkgu"wrqp"wughwn"kpvgnnkigpeg"vq"jgnr"fgvgtokpg"vjg"oquv"ghhgevkxg"yc{"vq"
fgrnq{"cuugvu"cpf"hqtegu0"Vjg"eqoocpfgt"pggfu"vq"wpfgtuvcpf"vjg"cfxcpvcigu"cpf"nkokvcvkqpu"cuuqekcvgf"
ykvj"vgttckp<"fgugtv"qt"hqtguv."oqwpvckpu"qt"rnckpu="yjgtg"vjg"gpgo{"ku"oquv"nkmgn{"vq"cvvcem<"d{"ckt."ycvgt."
qt"ncpf."cetquu"c"gnf"qt"dtkfig="yjcv"vjg"gpgo{"ycpvu"vq"ceeqornkuj<"dnqy"wr"vjg"dtkfig"qt"etquu"kv"cpf"
dnqy"wr"c"owpkvkqpu"fgrqv="rtgfkev"vjg"eqpugswgpegu"qh"c"rqvgpvkcn"gpgo{"kpewtukqp="cpf"yjcv"vq"fq"vq"
ykp"vjg"dcvvng0"
Qp"vjg"KV"dcvvnggnf."ugewtkv{"rtqhguukqpcnu"pggf"vq"ogcuwtg"vjg"nkmgnkjqqf"vjcv"c"ikxgp"xwnpgtcdknkv{"
yknn"dg"gzrnqkvgf"cpf"vjg"rqvgpvkcn"korcev"uwej"cp"gzrnqkv"yqwnf"ecwug0"Kv"ku"vjg"ugewtkv{"rtqhguukqpcnu"
okuukqp"vq"kfgpvkh{"vjg"etkvkecn"xwnpgtcdknkvkgu."swcpvkh{"wpceegrvcdng"tkum"ngxgnu."cpf"vjgp"fgekfg"yjcv."kh"
cp{vjkpi."vq"fq0"Kv"ku"kortcevkecn."cpf"wppgeguuct{."vq"cvvgorv"vq"tgogfkcvg"gxgt{"xwnpgtcdknkv{"nkuvgf"qp"c"
uecp"tgrqtv0"Oquv"xwnpgtcdknkvkgu"rtgugpv"nqy"tkum"hqt"xctkqwu"tgcuqpu0"Rgtjcru"vjg"cuugv"ku"pqp/etkvkecn."qt"kv"
ku"pqv"gzrnqkvcdng"d{"c"ocnyctg"mkv."qt"eqorgpucvkpi"eqpvtqnu."uwej"cu"c"tgycnn."rtqvgev"kv0"
Ugewtkv{"rtqhguukqpcnu"ogcuwtg"tkumu"wukpi"hqwt"rctcogvgtu<"Gzrquwtg."Nkmgnkjqqf."Korcev."cpf"Okvkicvkqp"
*ugg"Hkiwtg"4"dgnqy+0"C"eqodkpcvkqp"qh"cwvqocvgf"cpf"gzrgtv"tkum"kpvgnnkigpeg"ogvjqfu"swcnkgu"cpf"
swcpvkgu"cevwcn"tkum0"Cwvqocvgf"tkum"kpvgnnkigpeg"ku"xwnpgtcdknkv{"uecppkpi"ykvj"c"uqnwvkqp"uwej"cu"Tcrkf9"
Pgzrqug0"Gzrgtv"tkum"kpvgnnkigpeg"ku"rgpgvtcvkqp"vguvkpi"ykvj"c"uqnwvkqp"uwej"cu"Tcrkf9"Ogvcurnqkv0"Vjg"
fgrvj"cpf"dtgcfvj"qh"vjgug"ogvjqfu"fgvgtokpgu"vjg"uweeguu"qh"vjg"tkum"cuuguuogpv"cpf"okvkicvkqp"rtqeguu0"
Hqnnqykpi"ku"c"ejctv"qh"swguvkqpu"cuuqekcvgf"ykvj"gcej"rctcogvgt."hqnnqygf"d{"c"nkuv"qh"ecrcdknkvkgu"vjcv"yknn"
uwrrqtv"ugewtkv{"rtqhguukqpcnu"kp"vjgkt"swguv"vq"cpuygt"vjqug"urgeke"swguvkqpu0
617.247.1717
www.rapid7.com
Figure 2:"Ceewtcvg"tkum"ogcuwtgogpv"tgswktgu"dqvj"cwvqocvgf"cpf"gzrgtv"tkum"kpvgnnkigpeg0
Risk Exposure
Gzrquwtg"fgvgtokpgu"yjgtg"cp"cvvcem"okijv"qeewt0
" Jcxg"K"kfgpvkgf"cnn"rqvgpvkcn"tkum"gzrquwtg"cetquu"o{"gpxktqpogpvA
617.247.1717
www.rapid7.com
Risk Likelihood
Nkmgnkjqqf"cuuguugu"yjgvjgt"cp"kfgpvkgf"xwnpgtcdknkv{"rtgugpvu"cp"cevwcn"fcpigt."ceeqwpvkpi"hqt"vjg"
eqorngzkv{"qh"cevwcnn{"gzrnqkvkpi"c"ikxgp"xwnpgtcdknkv{"*ceeguu"eqorngzkv{+."vjg"fkhewnv{"kp"tgcejkpi"vjg"
urgeke"xwnpgtcdknkv{"*ceeguu"xgevqt+."cpf"cwvjgpvkecvkqp"tgswktgogpvu"pggfgf"vq"gzrnqkv"vjg"xwnpgtcdknkv{0
" Ku"vjgtg"c"engct"rcvj"vq"vjg"cuugvu"kp"swguvkqpA
" Ctg"vjg"xwnpgtcdknkvkgu"gzrnqkvcdngA
" Yjcv"ku"vjg"ngxgn"qh"cwvjgpvkecvkqp"tgswktgf"kp"qtfgt"vq"gzrnqkv"c"ikxgp"xwnpgtcdknkv{A
" Tkum"ueqtkpi"fgvgtokpcvkqp"dcugf"qp"
xwnpgtcdknkv{"cig."gzkuvgpeg"qh"mpqyp"gzrnqkvu"
cpf"ocnyctg"mkvu"kpvgitcvgf"ykvj"EXUU"ogvtkeu
" Cuuguu"vjg"ngxgn"qh"cwvjgpvkecvkqp"tgswktgf"
vq"uweeguuhwnn{"gzrnqkv"vjku"xwnpgtcdknkv{
Risk Impact
Korcev"ogcuwtgu"vjg"eqpugswgpegu"qh"c"ugewtkv{"kpekfgpv"tguwnvkpi"htqo"gzrnqkvcvkqp"qh"c"xwnpgtcdknkv{0"Kv"
eqpukfgtu"cuugv"qt"fcvc"eqpfgpvkcnkv{."kpvgitkv{."cpf"cxckncdknkv{0
" Jqy"dwukpguu/etkvkecn"ctg"vjg"cuugvu"cv"tkumA"
" Yjcv"fcvc"qt"kphqtocvkqp"fqgu"cp"cvvcemgt"ickp"ceeguu"vq"yjgp"c"xwnpgtcdknkv{"ku"gzrnqkvgfA
" Yjcv"ctg"vjg"eqpugswgpegu"kh"cp"kpekfgpv"qeewtuA
" Xwnpgtcdknkv{"ejckpkpi<"cuuguukpi"vjg"
tkrrng/chhgev"qh"cp"gzrnqkvgf"xwnpgtcdknkv{
Risk Mitigation
Chvgt"fgvgtokpkpi"yjcv"Tgcn"Tkumu"ctg"rtgugpv"kp"{qwt"gpxktqpogpv."{qw"yknn"ycpv"vq"fgvgtokpg"yjcv"
okvkicvkqp"cpf"tgogfkcvkqp"ghhqtvu"{qw"ycpv"vq"vcmg0"
Tkum"okvkicvkqp"vcmgu"uvgru"vq"rtgxgpv"qt"cnnc{"ugewtkv{"kpekfgpvu0
617.247.1717
www.rapid7.com
" Yjcv"cevkqpu"ujqwnf"K"vcmgA"Ujqwnf"K"tgogfkcvg."okvkicvg."fghgt."vtcpuhgt."qt"ceegrv"vjku"tkumA
" Yjgp"fq"K"pggf"vq"vcmg"vjku"cevkqpA
" Yjcv"ku"o{"ceegrvcdng"ngxgn"qh"tkumA"Cpf."co"K"cffkpi"kp"cp{"pgy"tkum"ykvj"o{"rtqrqugf"uqnwvkqpA
" Kpvgitcvkqp"ykvj"dguv/qh/dtggf"rgpgvtcvkqp"
vguvkpi"cpf"okvkicvkqp"u{uvgou
" Okvkicvkqp"xgtkecvkqp
Cuuguukpi"vjg"Dcvvnggnf<"Ugewtkv{"Tkum"Kpvgnnkigpeg
Eqodkpkpi"xwnpgtcdknkv{"ocpcigogpv."rgpgvtcvkqp"vguvkpi."cpf"dguv"rtcevkegu."Tcrkf9"Ugewtkv{"Tkum"Kpvgnnkigpeg"
tg/fgpgu"cpf"kortqxgu"tkum"ocpcigogpv0"Ugewtkv{"Tkum"Kpvgnnkigpeg"fgnkxgtu"vjg"eqodkpcvkqp"qh"swcnkvcvkxg"cpf"
swcpvkvcvkxg"tkum"cpcn{uku"vjcv"ugewtkv{"rtqhguukqpcnu"pggf"vq"vcemng"vjg"ownvk/hcegvgf"ejcnngpigu"qh"cejkgxkpi"wughwn"
kphqtocvkqp"cdqwv"tkum0"Kv"ogcuwtgu"eqpvgzvwcn"tkum."rtqxkfgu"uvgr/d{/uvgr"okvkicvkqp"kpuvtwevkqpu."cpf"gpcdngu"tcrkf."
vtwuvyqtvj{"xgtkecvkqp0"
Ugewtkv{"Tkum"Kpvgnnkigpeg"igpgtcvgu"c"Tgcn"Tkum"ueqtg0"C"Tgcn"Tkum"ueqtg"cflwuvu"c"EXUU"xcnwg"dcugf"qp"eqpvgzvwcn"
gngogpvu"vjcv"cpcn{|g"gcej"tkum"gngogpv"ugrctcvgn{."hqt"vjg"tuv"vkog"kpeqtrqtcvkpi"dqvj"vgorqtcn"cpf"iqxgtpcpeg"
rctcogvgtu0"Vjku"rtqxkfgu"itgcvgt"kpukijv"kpvq"qxgtcnn"tkum"rquvwtg"cpf"ftkxgu"oqtg"ghekgpv"tkum"tgfwevkqp"rtcevkegu0
Figure 3<"Ecnewncvkpi"Tgcn"Tkum"wvknk|gu"dqvj"uvcpfctf"cpf"gpxktqpogpvcn"ogvtkeu"hqt"eqpvgzvwcn"kpukijv"
Vgorqtcn"rctcogvgtu"ygkij"vjg"cig"qh"c"xwnpgtcdknkv{"cickpuv"vjg"nkmgnkjqqf"vjcv"c"jcemgt"vqqn"qt"ocnyctg"gzkuvu"
vq"gzrnqkv"kv0"Vjg"vgorqtcn"ueqtg"kpetgcugu"qxgt"vkog."dtkpikpi"xwnpgtcdknkvkgu"vq"vjg"cvvgpvkqp"qh"ugewtkv{"ocpcigtu"
dghqtg"cp"kpekfgpv"qeewtu0
Hqt"gzcorng."vjg"Vtql1Rtqvwz/Igp"cvvcem"kp"422;"gzrnqkvgf"OU28/24:."c"uggokpin{"kppqewqwu"xwnpgtcdknkv{"kp"
Oketquqhv"RqygtRqkpv"rcvejgf"kp"Lwpg"42280"Vjg"tkukpi"vgorqtcn"ueqtg"yqwnf"jcxg"ciigf"vjcv"xwnpgtcdknkv{."gpcdnkpi"
tgogfkcvkqp"dghqtg"vjg"cvvcem"eqoogpegf0
Iqxgtpcpeg"rctcogvgtu"hqnnqy"kpvgtpcn"rqnkekgu"vjcv"swcnkh{"vjg"etkvkecnkv{"qh"cuugvu."tckukpi"qt"nqygtkpi"
tkum"ueqtgu"ceeqtfkpin{"cpf"guvcdnkujkpi"yjgtg"eqorgpucvkpi"eqpvtqnu"ujqwnf"dg"rwv"kp"rnceg0"
Hqt"gzcorng."c"eqorcp{"jcu"c"rtqrtkgvct{"uqhvyctg"crrnkecvkqp"vjcv"twpu"qp"c"4225"xgtukqp"qh"Oketquqhv"
Ykpfqyu"PV0"Rcvejkpi"vjg"ugtxgt"yqwnf"ecwug"vjg"crrnkecvkqp"vq"etcuj0"Vjg"eqorcp{"ku"wpyknnkpi"vq"kpxguv"
oknnkqpu"qh"fqnnctu"kp"cp"crrnkecvkqp"writcfg"ykvj"okpkocn"dwukpguu"xcnwg0"Vjg"ugewtkv{"vgco"korngogpvu"
eqorgpucvkpi"eqpvtqnu"uwej"cu"cp"kpvtwukqp"rtqvgevkqp"u{uvgo"cpf"c"fgfkecvgf"tgycnn."vguvu"vjg"
617.247.1717
www.rapid7.com
ghhgevkxgpguu"qh"vjgug"ogcuwtgu."cpf"kh"uweeguuhwn."ngu"cp"gzenwukqp"hqt"vjku"urgeke"xwnpgtcdknkv{0"Vjku"
iqxgtpcpeg"rtqeguu"tgfwegu"vjg"Tgcn"Tkum"ueqtg"d{"kpenwfkpi"vjg"xwnpgtcdknkv{"gzegrvkqp"rwv"kp"rnceg"kp"
tgurqpug"vq"vjg"qnf"QU"xgtukqp0""
Figure 4<"Enqugf/nqqr"Ugewtkv{"Tkum"Kpvgnnkigpeg"htqo"Tcrkf9
617.247.1717
www.rapid7.com
Dgpgvu"qh"Ugewtkv{"Tkum"Kpvgnnkigpeg
Vjg"dgpgvu"qh"korngogpvkpi"c"Ugewtkv{"Tkum"Kpvgnnkigpeg"uvtcvgi{"kpenwfg<
Kortqxg"dwukpguu"fgekukqp/ocmkpi"vjtqwij"dgvvgt"kpukijv0"Jkij/swcnkv{"tkum"kpvgnnkigpeg"jgnru"ugewtkv{"
rtqhguukqpcnu"kortqxg"qrgtcvkqpcn"rtcevkegu"cpf"vgejpqnqi{"kpxguvogpv0"Hqt"gzcorng."ugtxgt"ocpcigtu"ecp"
yqtm"ykvj"vjg"ugewtkv{"ocpcigt"vq"vguv"cpf"jctfgp"ugtxgtu"cpf"xktvwcn"ocejkpgu"dghqtg"vjg{"iq"qpnkpg0""
Dwukpguu"kpvgnnkigpeg="ugewtkv{"kphqtocvkqp"cpf"gxgpv"ocpcigogpv="cpf"iqxgtpcpeg."tkum/ocpcigogpv"
cpf"eqornkcpeg"vqqnu"ecp"wug"ugewtkv{"tkum"kphqtocvkqp"vq"fgvgtokpg"vjg"uweeguu"qh"tkum/ocpcigogpv"cpf"
eqornkcpeg/ocpcigogpv"rtcevkegu"cpf"yjgvjgt"c"tkum"tgswktgu"hwtvjgt"okvkicvkqp0"
Etgcvg"qrgtcvkqpcn"ghekgpekgu"ykvj"tgrgcvcdng"dguv"rtcevkegu0"Pgzrqug"tgrqtvu"jgnr"ugewtkv{"ocpcigtu"
fgnkxgt"engct."eqttgev."rtguetkrvkxg"cfxkeg"vq"ugtxgt"cpf"pgvyqtm"cfokpkuvtcvqtu"vcumgf"ykvj"okvkicvkqp"
cpf"tgogfkcvkqp0"Ogvcurnqkv"jgnru"ugewtkv{"rtqhguukqpcnu"xcnkfcvg"xwnpgtcdknkvkgu"cpf"xgtkh{"vjcv"okvkicvkqp"
uvgru"rtqxkfg"rtqvgevkqp0"Vjku"enqugf/nqqr"u{uvgo"ku"oqtg"ghhgevkxg"vjcp"vjg"gpfnguu"uecp/cpf/rcvej"
e{eng"vjcv"qhvgp"rnciwgu"pgvyqtm"cfokpkuvtcvqtu"wukpi"qvjgt"xwnpgtcdknkv{"uecppkpi"uqnwvkqpu."cnnqykpi"vjgo"
vq"oggv"vjg"pggfu"qh"vjg"ugewtkv{"vgco"cnqpi"ykvj"vjgkt"qvjgt"KV"kphtcuvtwevwtg"tgurqpukdknkvkgu0"
Kpeqtrqtcvgu"eqornkcpeg"tgswktgogpvu0"Ugewtkv{"Tkum"Kpvgnnkigpeg"jgnru"ugewtkv{"ocpcigtu"xkgy"
eqornkcpeg"cu"qpg"curgev"qh"c"ugewtkv{"rtcevkeg."pqv"vjg"gpf"iqcn0"Gpnctikpi"vjg"rgturgevkxg"qh"yjcv"pggfu"
ugewtkpi"cnuq"ngcfu"vq"eqornkcpeg0
Ogcuwtcdn{"tgfweg"tkum"ngxgn"qxgt"vkog0"Yjgp"Ugewtkv{"Tkum"Kpvgnnkigpeg"ku"vjg"dcuku"qh"tgiwnct"
xwnpgtcdknkv{"ocpcigogpv"qrgtcvkqpu."qticpk|cvkqpu"ecp"uwduvcpvkcnn{"tgfweg"vjgkt"qxgtcnn"tkum"rquvwtg"
qxgt"vkog0"Wukpi"cp"kvgtcvkxg"crrtqcej"vq"eqpvkpwqwun{"kfgpvkh{"vjg"jkijguv"tkumu"cnqpiukfg"tkum"vtgpfkpi"hqt"
etkvkecn"cuugvu."qticpk|cvkqpu"ecp"guvcdnkuj"dguv"rtcevkegu"hqt"tkum"tgfwevkqp0"
Tgfweg"ukipcn/vq/pqkug"tcvkq."Ykvj"Tgcn"Tkum"ueqtkpi."Pgzrqug"cpf"Ogvcurnqkv"rtqxkfg"tgnkcdng"kpvgnnkigpeg"
vjcv"swcpvkgu"vjg"etkvkecnkv{"qh"c"ikxgp"tkum"cpf"uwrrqtvu"vjtgujqnf/dcugf"ocpcigogpv"fgekukqpu"vq"equv/
ghhgevkxgn{"tgfweg"tkum"cpf"uvtgpivjgp"ugewtkv{"rquvwtgu0"
Kortqxg"gzkuvkpi"kpxguvogpvu"kp"vjktf"rctv{"ugewtkv{"uqnwvkqpu0"Dqvj"Pgzrqug"cpf"Ogvcurnqkv"
ctg"guugpvkcn"kpvgnnkigpeg"u{uvgou"vjcv"hggf"fcvc"kpvq"vjktf/rctv{"u{uvgou"uwej"cu"Iqxgtpcpeg."Tkum"
Ocpcigogpv"("Eqornkcpeg"uqnwvkqpu"*ITE+."ugewtkv{"kphqtocvkqp"cpf"gxgpv"ocpcigogpv"*UKGO+"cpf"
kpvtwukqp"rtgxgpvkqp"u{uvgo"*KRU+"uqnwvkqpu."uwej"cu"Uqwtegtg."ocmkpi"vjqug"vqqnu"oqtg"ghhgevkxg0"Hqt"
gzcorng."Tcrkf9"xwnpgtcdknkv{"fcvc"ecp"dg"korqtvgf"kpvq"vjg"} IWg W"7WaW W"1W W "*jvvr<11yyy0
uqwtegtg0eqo1ugewtkv{/vgejpqnqikgu1e{dgt/ugewtkv{/rtqfwevu15f/u{uvgo1egpvtcnk|gf/ocpcigogpv+0"Vjg"
xwnpgtcdknkv{"fcvc"cffu"vq"xkukdknkv{"icvjgtgf"d{"} IWg W"yd#"*jvvr<11yyy0uqwtegtg0eqo1rtqfwevu15F1
tpc+0"Cv"vjg"ucog"vkog."cfokpkuvtcvqtu"ecp"wug"Ogvcurnqkv"vq"xgtkh{"eqttgev"eqpiwtcvkqp"qh"vjktf/rctv{"
u{uvgou."uwej"cu"vguvkpi"vjg"ghhgevkxgpguu"qh"c"ikxgp"okvkicvkpi"eqpvtqn0
617.247.1717
www.rapid7.com
Vjg"cngtv"ku"wugf"vq"vtkiigt"c"uwurgpukqp"qh"vjg"pgy"XO"wpvkn"vjg"ugewtkv{"ocpcigt"ecp"xgtkh{"kvu"ugewtkv{"
rquvwtg0"Wukpi"Pgzrqug."vjg"qrgtcvqt"uecpu"vjg"XO"cpf"fgvgtokpgu"vjcv"vjg"kocig"ku"xg"rcvejgu"dgjkpf0"
C"etkvkecn"xwnpgtcdknkv{."OU28/293."ykvj"c"Tgcn"Tkum"ueqtg"qh";3:"cpf"c"EXUU"xcnwg"qh"908"ku"rtgugpv"vjcv"
c"jcemgt"eqwnf"gzrnqkv"cpf"cnnqy"tgoqvg"eqfg"gzgewvkqp"ykvjkp"vjg"rtkxcvg"enqwf0"Vjg"jkijgt"Tgcn"Tkum"
ueqtg"ku"c"tguwnv"qh"kvu"eqpukfgtcvkqp"qh"vjg"gpxktqpogpvcn"ogvtkeu"cuuqekcvgf"ykvj"OU28/293<"vjg"cig"qh"
vjg"xwnpgtcdknkv{"*7"{gctu"ukpeg"kv"ycu"kfgpvkgf+"cpf"vjg"hcev"vjcv"mpqyp"gzrnqkvu"gzkuvu"hqt"vjku"urgeke"
xwnpgtcdknkv{0"
Pgzrqug"tgeqoogpfu"tgogfkcvkqp"uvgru"hqt"rcvejkpi"vjg"XO0"Vjg"ugewtkv{"ocpcigt"hqtyctfu"vjku"
kphqtocvkqp"vq"vjg"ugtxgt"cfokpkuvtcvqt."ciikpi"kv"hqt"koogfkcvg"cvvgpvkqp0"Vjg"ugtxgt"cfokpkuvtcvqt"
rcvejgu"vjg"qtkikpcn"XO"kp"Pgy"[qtm"cpf"tgrqtvu"vcum"eqorngvkqp"vq"vjg"ugewtkv{"ocpcigt0"Wukpi"Ogvcurnqkv"
Rtq."vjg"ugewtkv{"ocpcigt"xgtkgu"vjcv"vjg"rcvejgu"ctg"ghhgevkxg"hqt"uvqrrkpi"cp"cvvcem0"Jg"ugpfu"cp"gockn"
vq"vjg"tgrtgugpvcvkxg"kp"Rctku"kpfkecvkpi"vjcv"ujg"ecp"wug"vjg"wrfcvgf"crrngv0"
Wug"Ecug<"Ocnyctg"Gzrnqkv
Cp"gockn"ykvj"cp"Gzegn"cvvcejogpv"ku"fgnkxgtgf"vq"vjg"eqtrqtcvg"ugtxgt0"Gornq{ggu"mpqy"pqv"vq"qrgp"ngu"
htqo"wpvtwuvgf"uqwtegu."dwv"vjku"gockn"nqqmu"nkmg"kv"ecog"htqo"vjg"tgekrkgpvu"eqnngig"dwff{0
Vjg"Gzegn"cvvcejogpv"eqpvckpu"c"ocetq"vjcv"eqpvckpu"ocnyctg"vjcv"gzrnqkvu"c"mpqyp"xwnpgtcdknkv{"kp"
Ykpfqyu"vq"rtqrcicvg"kvugnh"cpf"ugv"wr"c"dqv"pgvyqtm0"Vjg"xwnpgtcdknkv{"gzrnqkvgf"kp"vjku"cvvcem."OU28/
236."jcu"c"Tgcn"Tkum"ueqtg"qh"982."dgecwug"cp{"mkf"ykvj"c"eqorwvgt"ecp"ygcrqpk|g"cp"Gzegn"ng"wukpi"
c"ocnyctg"mkv0"Vjg"dcug"ogvtke"EXUU"ueqtg"qh"703"hqt"vjku"urgeke"xwnpgtcdknkv{"yqwnf"pqv"ci"vjg"fcpigt"
ykvjkp"vjku"gpxktqpogpv."dwv"vjg"Tcrkf9"Tgcn"Tkum"ueqtg"kfgpvkgu"vjg"ocnyctg"mkvu"vjcv"jcxg"dggp"mpqyp"
vq"gzrnqkv"vjku"xwnpgtcdknkv{."eqodkpgu"kv"ykvj"qvjgt"mpqyp"gzrnqkvu"hqt"vjku"xwnpgtcdknkv{."cpf"kpetgogpvu"
vjg"ueqtg"crrtqrtkcvgn{0"
Lwuv"ncuv"yggm."vjg"ugewtkv{"ocpcigt"wugf"Ogvcurnqkv"vq"ugpf"c"ocnkekqwu"gockn"cpf"xgtkh{"vjcv"cpvkxktwu"
uqhvyctg"qp"vjg"gockn"ugtxgt"fgvgevu"vjku"ocetq"cpf"fgngvgu"kv"dghqtg"fgnkxgtkpi"vjg"oguucig"vq"vjg"
wugt0"Mpqykpi"vjcv"eqorgpucvkpi"eqpvtqnu"ctg"kp"rnceg."vjg"ugewtkv{"ocpcigt"wugf"Ogvcurnqkv"vq"octm"vjg"
Ykpfqyu"xwnpgtcdknkv{"cu"ceegrvcdng"ykvjkp"Pgzrqug0
617.247.1717
www.rapid7.com
Kpvgnnkigpeg"jgnru"qticpk|cvkqpu"korngogpv"qrgtcvkqpcn"dguv"rtcevkegu"kp"enqugf/nqqr"xwnpgtcdknkv{"
ocpcigogpv."dwknf"rtqfwevkxg"tgncvkqpujkru"ykvj"KV"qrgtcvkqpu."cpf"cejkgxg"ogcuwtcdng"ftqru"kp"tkum"
gzrquwtg"qxgt"vjg"ujqtvguv"rgtkqf"qh"vkog0"
KFE"citggu<"Tcrkf9u"ngcfgtujkr"cpf"uvtqpi"itqyvj"kpfkecvg"vjcv"kv"ku"qp"uqnkf"itqwpf."cpf"kv"ecp"oggv"
vjg"tgswktgogpvu"vq"uweeggf"kp"kvu"octmgvu0"Tcrkf9"jcu"etkvkecn"cyctgpguu"qh"octmgv"hqtegu"cpf"xgpfqt"
eqorgvkvkxg"rqukvkqpkpi"cpf"ku"hqewugf"qp"ngxgtcikpi"kvu"uvtgpivju"vq"kpetgcug"kvu"ujctg0"Vjg"qxgtctejkpi"
uvtcvgi{"vjcv"egpvgtu"ctqwpf"eqpxgtigf"xwnpgtcdknkv{"ocpcigogpv"cpf"rgpgvtcvkqp"vguvkpi."eqpvgzv/tkej"
ugewtkv{"kpvgnnkigpeg."cpf"vguvkpi"qh"ugewtkv{"eqpvtqnu"qwvukfg"qh"rcvej"fkuvtkdwvkqp"etgcvgu"c"eqorgnnkpi"
uvtcvgi{"vjcv"jcu"vjg"rqvgpvkcn"vq"tgfgpg"Tcrkf9u"ugiogpv03
About Rapid7
Tcrkf9"ku"c"ngcfkpi"rtqxkfgt"qh"KV"ugewtkv{"tkum"ocpcigogpv"uqhvyctg0"Kvu"kpvgitcvgf"vulnerability management"cpf"
penetration testing"rtqfwevu."Pgzrqug"cpf"Ogvcurnqkv."cpf"mobile risk management"uqnwvkqp."Oqdknkuchg."gpcdng"
fghgpfgtu"vq"ickp"eqpvgzvwcn"xkukdknkv{"cpf"ocpcig"vjg"tkum"cuuqekcvgf"ykvj"vjg"KV"gpxktqpogpv."wugtu"cpf"vjtgcvu"
tgngxcpv"vq"vjgkt"qticpk|cvkqp0"Tcrkf9u"ukorng"cpf"kppqxcvkxg"uqnwvkqpu"ctg"wugf"d{"oqtg"vjcp"4.222"gpvgtrtkugu"cpf"
iqxgtpogpv"cigpekgu"kp"oqtg"vjcp"87"eqwpvtkgu."yjkng"vjg"Eqorcp{u"htgg"rtqfwevu"ctg"fqypnqcfgf"oqtg"vjcp"qpg"
oknnkqp"vkogu"rgt"{gct"cpf"gpjcpegf"d{"oqtg"vjcp"397.222"ogodgtu"qh"kvu"qrgp"uqwteg"ugewtkv{"eqoowpkv{0"Tcrkf9"
jcu"dggp"tgeqipk|gf"cu"qpg"qh"vjg"hcuvguv"itqykpi"ugewtkv{"eqorcpkgu"d{"Kpe0"Ocic|kpg"cpf"cu"c"Vqr"Rnceg"vq"Yqtm"
d{"vjg"Dquvqp"Inqdg0"Kvu"rtqfwevu"ctg"vqr"tcvgf"d{"Ictvpgt."Hqttguvgt"cpf"UE"Ocic|kpg0"Vjg"Eqorcp{"ku"dcemgf"d{"
Dckp"Ecrkvcn"cpf"Vgejpqnqi{"Etquuqxgt"Xgpvwtgu0"Hqt"oqtg"kphqtocvkqp"cdqwv"Tcrkf9."rngcug"xkukv"http://www.rapid7.
com0
3"
"KFE<"Ejctngu"Nkgdgtv."Ejctngu"L0"Mqnqfi{."cpf"Ejtkuvkcp"C0"Ejtkuvkcpugp."Tcrkf9"Rtkxcvg"Xgpfqt"Ycvejnkuv"Rtqng<"Ugewtkv{"Tkum"
Kpvgnnkigpeg."Lwn{"4233
617.247.1717
www.rapid7.com
Product Brief
Overview
Data breaches are growing at an alarming rate. Your attack surface is
constantly changing, the adversary is becoming more nimble than your
security teams, and your board wants to know what you are doing about it.
Nexpose gives you the confidence you need to understand your attack
surface, focus on what matters, and create better security outcomes.
68K
163K
123015
| Rapid7.com
Prioritize What
Matters Most
Its impossible to remediate every risk.
With Nexpose, the highest risks are
prioritized using threat intelligence
aligned with whats important to your
business. Focusing your remediation
efforts on taking the most impactful
actions will allow you to reduce the
most risk with the least amount of
effort and keep your IT team focused.
| Rapid7.com
Meet Vulnerability
Management Compliance
Requirements
Nexpose enables organizations to stay
compliant with PCI DSS, NERC CIP,
FISMA (USGCB/FDCC), HIPAA/
HITECH, Top 20 CSC, DISA STIGS, and
CIS standards for risk, vulnerability,
and configuration management.
Unlike other solutions that may
burden the network with multiple
scans, Nexposes fast, unified security
and compliance assessment improves
the performance of your security
program by giving you a complete risk
and compliance posture.
Learn more about Nexpose and
supporting services at:
www.rapid7.com/products/nexpose
Rapid7 Nexpose
Ultimate wowed us
with its incredibly
easy setup. This,
combined with its
advanced scanning
and Metasploit
integration, make it
an incredibly powerful
tool for prioritizing
vulnerability patching.
To top it all off,
Nexpose Ultimate
comes at an attractive
price point.
-SC Magazine
Product:
Rapid7 Nexpose
Website:
http://www.rapid7.com
Price
Starts at $22,500.
RATING BREAKDOWN
Features:
Ease of Use:
Performance:
Documentation:
Support:
Value for Money:
Overall Rating:
QUICK READ
Strengths: Quality and history of the companys knowledge base.
Weaknesses: Did not see an automated ticket-escalation feature.
Verdict: Outstanding product.
Nexpose assists clients through the entire vulnerability management lifecycle - from discovery, vulnerability
detection, risk classification, impact analysis, reporting, vulnerability verification and risk mitigation.
Organizations can use the Nexpose toolset to gain insight into their security posture and IT environment.
Nexpose's intuitive graphical user interface (GUI) makes it easy for clients to run scans for known
vulnerabilities on their network. Users also can configure the product to scan their websites and servers for web
application vulnerabilities to determine their overall level of policy compliance in one unified product and scan
of their network. Nexpose presently has more than 97,000 checks and 34,000 vulnerabilities. It includes
metadata around each of the discovered vulnerabilities on the network. The solution data allows users to view
standard metrics to see which common vulnerabilities and exposures (CVE) and common configuration
enumeration (CCE) identifiers, common vulnerability scoring system (CVSS) risk scores, and others, such as
information assurance vulnerability management (IAVM), to use when researching a discovered vulnerability.
Rapid7 enhances the public metrics with information about any known malware and exploits associated with a
vulnerability, as well as detailed remediation information that allows users to fully comprehend the tasks and
time required to remediate the vulnerability. Users can use the integration between Nexpose and Metasploit to
verify vulnerabilities, determining not only that the vulnerability exists on the system, but also that it can be
exploited by an attacker.
We were impressed with the quality of the vulnerability scanner. The number of discovered vulnerabilities was
extremely high. Validation of the vulnerabilities was excellent. The remediation recommendations were clear
and, by taking advantage of the long history of the product's vulnerability/exploit engine, went well beyond just
reciting CVE information. It then delivered clear remediation recommendations. Overall, the performance of the
system was strong.
Documentation included an intuitive "help" function. The company's website provides the typical assistance
documentation, such as a searchable knowledge base and a FAQ. Other documentation includes Rapid7
Community, Rapid7 Self-Help, a knowledge base and more.
The company's support structure is fairly complicated. Telephone and email aid is offered to all customers of
Rapid7 as a component of their license fee and each annual renewal. Clients who have purchased Nexpose
Enterprise also benefit from a dedicated account manager, who schedules regular check-ins, offers industry
insights, can organize professional or technical training, and can help resolve any problems. Support offers 24/7
incident response times, 24-hour vulnerability service level agreements (SLAs), and reliable testing guarantees.
Rapid7 offers 5/24 support and 2/24 support for issues that are considered critical. It operates on a support
model that escalates critical issues for all customers. Other levels of help include: eSupport software releases,
updates, fixes, and telephone support (Monday to Friday, 8 a.m. to 8 p.m. EST).
Overall, the value for the cost is good.