ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    What do you use for Risk Management?

    IT Discussion
    risk management simplerisk opensource
    8
    29
    2.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • IRJI
      IRJ
      last edited by

      Right now, risk managament is mostly utilized in enterprise space, because enterprise sees value in things that SMB usually don't. Not to mention that in SMB, executives are rarely trained in IT. Generally in SMB even the CIO doesn't have the high level training to understand the process.

      1 Reply Last reply Reply Quote 0
      • IRJI
        IRJ @scottalanmiller
        last edited by IRJ

        @scottalanmiller said in What do you use for Risk Management?:

        Not a bad idea, will have to check out some software for it.

        simplerisk.com

        IRJI 1 Reply Last reply Reply Quote 0
        • IRJI
          IRJ @IRJ
          last edited by

          @IRJ said in What do you use for Risk Management?:

          @scottalanmiller said in What do you use for Risk Management?:

          Not a bad idea, will have to check out some software for it.

          simplerisk.com

          We actually helped with the CentOS documentation. As one of our corporate requirements is to use CentOS or RHEL for all linux installations. Previously, SimpleRisk was only supported on Ubuntu.

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • JaredBuschJ
            JaredBusch @IRJ
            last edited by

            @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

            Their basic hosted cost would be more cost effective for many years.

            NerdyDadN IRJI 3 Replies Last reply Reply Quote 0
            • NerdyDadN
              NerdyDad @JaredBusch
              last edited by

              @JaredBusch said in What do you use for Risk Management?:

              @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

              Their basic hosted cost would be more cost effective for many years.

              Holy cow, is that annually or one-time cost?

              DustinB3403D 1 Reply Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403 @NerdyDad
                last edited by

                @NerdyDad said in What do you use for Risk Management?:

                @JaredBusch said in What do you use for Risk Management?:

                @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

                Their basic hosted cost would be more cost effective for many years.

                Holy cow, is that annually or one-time cost?

                Annually.

                1 Reply Last reply Reply Quote 0
                • DustinB3403D
                  DustinB3403
                  last edited by

                  Is it just me, or are they charging for encryption functionality, which can be setup on your installation when you INSTALL . . . $2k Annually for that is a complete ripoff.

                  SimpleRisk Encrypted Database Extra	
                  
                  Sensitive text is encrypted with a long, random, password prior to being inserted into the SimpleRisk database preventing anyone from being able to view or modify the data without using the SimpleRisk application directly.
                  
                  JaredBuschJ 1 Reply Last reply Reply Quote 0
                  • IRJI
                    IRJ @JaredBusch
                    last edited by

                    @JaredBusch said in What do you use for Risk Management?:

                    @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

                    Their basic hosted cost would be more cost effective for many years.

                    Unfortunately, some of them are necessary for us. Like LDAP integration, email notifications, and team based separation. These are required for me to create proper workflows in an enterprise size environment. There are potentially hundreds of users I need to involve for different pieces of this system.

                    1 Reply Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch @DustinB3403
                      last edited by

                      @DustinB3403 said in What do you use for Risk Management?:

                      Is it just me, or are they charging for encryption functionality, which can be setup on your installation when you INSTALL . . . $2k Annually for that is a complete ripoff.

                      SimpleRisk Encrypted Database Extra	
                      
                      Sensitive text is encrypted with a long, random, password prior to being inserted into the SimpleRisk database preventing anyone from being able to view or modify the data without using the SimpleRisk application directly.
                      

                      No, you have no idea what you are talking about. This is not disk enryption. This is encryption of the data in the database itself.

                      DustinB3403D 1 Reply Last reply Reply Quote 0
                      • IRJI
                        IRJ @JaredBusch
                        last edited by

                        @JaredBusch said in What do you use for Risk Management?:

                        @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

                        Their basic hosted cost would be more cost effective for many years.

                        I agree that the hosted version is much better pricewise and of course that is what is pushed by SimpleRisk. However, it's kind of scary having all your vulnerabilities on your network managed off site by a small company.

                        JaredBuschJ 1 Reply Last reply Reply Quote 1
                        • JaredBuschJ
                          JaredBusch @IRJ
                          last edited by

                          @IRJ said in What do you use for Risk Management?:

                          @JaredBusch said in What do you use for Risk Management?:

                          @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

                          Their basic hosted cost would be more cost effective for many years.

                          I agree that the hosted version is much better pricewise and of course that is what is pushed by SimpleRisk. However, it's kind of scary having all your vulnerabilities on your network managed off site by a small company.

                          I totally get that too. I have done software development. I get that it is not cheap. But those prices are just out of line.

                          IRJI 1 Reply Last reply Reply Quote 0
                          • DustinB3403D
                            DustinB3403 @JaredBusch
                            last edited by

                            @JaredBusch said in What do you use for Risk Management?:

                            @DustinB3403 said in What do you use for Risk Management?:

                            Is it just me, or are they charging for encryption functionality, which can be setup on your installation when you INSTALL . . . $2k Annually for that is a complete ripoff.

                            SimpleRisk Encrypted Database Extra	
                            
                            Sensitive text is encrypted with a long, random, password prior to being inserted into the SimpleRisk database preventing anyone from being able to view or modify the data without using the SimpleRisk application directly.
                            

                            No, you have no idea what you are talking about. This is not disk enryption. This is encryption of the data in the database itself.

                            But why not encrypt the entire system, why encrypt the individual records of the database?

                            JaredBuschJ 1 Reply Last reply Reply Quote 0
                            • IRJI
                              IRJ @JaredBusch
                              last edited by

                              @JaredBusch said in What do you use for Risk Management?:

                              @IRJ said in What do you use for Risk Management?:

                              @JaredBusch said in What do you use for Risk Management?:

                              @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

                              Their basic hosted cost would be more cost effective for many years.

                              I agree that the hosted version is much better pricewise and of course that is what is pushed by SimpleRisk. However, it's kind of scary having all your vulnerabilities on your network managed off site by a small company.

                              I totally get that too. I have done software development. I get that it is not cheap. But those prices are just out of line.

                              Agreed. When we talked to the owner back in December about this we made a big stink about the price. Especially when much more robust Risk Management solutions are cheaper than SimpleRisk.

                              These other enterprise solutions are very complicated to implement. It would take a team of people to implement because the system is so complicated because it is actually setup to do calculations. SimpleRisk is simply a place to document risks. There is no need to tie them to values, assets, do calculations like ALE style calculations, etc.

                              Also when you consider you have at least a hundred users extensively using a system, Is $6k really that much? If you use support once or twice you could easily recoup your $6k back in saved time.

                              JaredBuschJ 1 Reply Last reply Reply Quote 1
                              • JaredBuschJ
                                JaredBusch @DustinB3403
                                last edited by JaredBusch

                                @DustinB3403 said in What do you use for Risk Management?:

                                @JaredBusch said in What do you use for Risk Management?:

                                @DustinB3403 said in What do you use for Risk Management?:

                                Is it just me, or are they charging for encryption functionality, which can be setup on your installation when you INSTALL . . . $2k Annually for that is a complete ripoff.

                                SimpleRisk Encrypted Database Extra	
                                
                                Sensitive text is encrypted with a long, random, password prior to being inserted into the SimpleRisk database preventing anyone from being able to view or modify the data without using the SimpleRisk application directly.
                                

                                No, you have no idea what you are talking about. This is not disk enryption. This is encryption of the data in the database itself.

                                But why not encrypt the entire system, why encrypt the individual records of the database?

                                Who said the base system is not encrypted? That still does not provide protection to the data in the database when the system is running.

                                Encrypted disks are not encrypted when the system is booted and logged in.

                                DustinB3403D 1 Reply Last reply Reply Quote 1
                                • DustinB3403D
                                  DustinB3403 @JaredBusch
                                  last edited by

                                  @JaredBusch said in What do you use for Risk Management?:

                                  @DustinB3403 said in What do you use for Risk Management?:

                                  @JaredBusch said in What do you use for Risk Management?:

                                  @DustinB3403 said in What do you use for Risk Management?:

                                  Is it just me, or are they charging for encryption functionality, which can be setup on your installation when you INSTALL . . . $2k Annually for that is a complete ripoff.

                                  SimpleRisk Encrypted Database Extra	
                                  
                                  Sensitive text is encrypted with a long, random, password prior to being inserted into the SimpleRisk database preventing anyone from being able to view or modify the data without using the SimpleRisk application directly.
                                  

                                  No, you have no idea what you are talking about. This is not disk enryption. This is encryption of the data in the database itself.

                                  But why not encrypt the entire system, why encrypt the individual records of the database?

                                  Who said the base system is not encrypted? That still does not provide protection to the data in the database when the system is running.

                                  Encrypted disks are not encrypted when the system is booted and logged in.

                                  True, so this is encryption while in use? Or are you making the assumption it is?

                                  JaredBuschJ 1 Reply Last reply Reply Quote 0
                                  • MattSpellerM
                                    MattSpeller
                                    last edited by

                                    "What do you use for Risk Management?"

                                    Scotch

                                    1 Reply Last reply Reply Quote 2
                                    • JaredBuschJ
                                      JaredBusch @IRJ
                                      last edited by

                                      @IRJ said in What do you use for Risk Management?:

                                      @JaredBusch said in What do you use for Risk Management?:

                                      @IRJ said in What do you use for Risk Management?:

                                      @JaredBusch said in What do you use for Risk Management?:

                                      @IRJ wow those add ons are not cheap. just reading names they each do not seem like they are worth that cost.

                                      Their basic hosted cost would be more cost effective for many years.

                                      I agree that the hosted version is much better pricewise and of course that is what is pushed by SimpleRisk. However, it's kind of scary having all your vulnerabilities on your network managed off site by a small company.

                                      I totally get that too. I have done software development. I get that it is not cheap. But those prices are just out of line.

                                      Agreed. When we talked to the owner back in December about this we made a big stink about the price. Especially when much more robust Risk Management solutions are cheaper than SimpleRisk.

                                      These other enterprise solutions are very complicated to implement. It would take a team of people to implement because the system is so complicated because it is actually setup to do calculations. SimpleRisk is simply a place to document risks. There is no need to tie them to values, assets, do calculations like ALE style calculations, etc.

                                      Also when you consider you have at least a hundred users extensively using a system, Is $6k really that much? If you use support once or twice you could easily recoup your $6k back in saved time.

                                      Oh I get how it can help. I just think these are a bit steep comparing one method to the other within their own product pricing. I cannot compare to any other products because I do not know any other products.

                                      1 Reply Last reply Reply Quote 1
                                      • JaredBuschJ
                                        JaredBusch @DustinB3403
                                        last edited by

                                        @DustinB3403 said in What do you use for Risk Management?:

                                        @JaredBusch said in What do you use for Risk Management?:

                                        @DustinB3403 said in What do you use for Risk Management?:

                                        @JaredBusch said in What do you use for Risk Management?:

                                        @DustinB3403 said in What do you use for Risk Management?:

                                        Is it just me, or are they charging for encryption functionality, which can be setup on your installation when you INSTALL . . . $2k Annually for that is a complete ripoff.

                                        SimpleRisk Encrypted Database Extra	
                                        
                                        Sensitive text is encrypted with a long, random, password prior to being inserted into the SimpleRisk database preventing anyone from being able to view or modify the data without using the SimpleRisk application directly.
                                        

                                        No, you have no idea what you are talking about. This is not disk enryption. This is encryption of the data in the database itself.

                                        But why not encrypt the entire system, why encrypt the individual records of the database?

                                        Who said the base system is not encrypted? That still does not provide protection to the data in the database when the system is running.

                                        Encrypted disks are not encrypted when the system is booted and logged in.

                                        True, so this is encryption while in use? Or are you making the assumption it is?

                                        Did you even read what you quoted?
                                        Do you understand what a database is?
                                        I am not making an assumption. This is very clear.

                                        1 Reply Last reply Reply Quote 0
                                        • stacksofplatesS
                                          stacksofplates
                                          last edited by

                                          We use the one built into Nessus.

                                          1 Reply Last reply Reply Quote 1
                                          • 1
                                          • 2
                                          • 1 / 2
                                          • First post
                                            Last post