Optimize Your Security Operations with InsightVM's Goals & SLAs | xxxOptimize Your Security Operations with InsightVM's Goals & SLAs – xxx
菜单

Optimize Your Security Operations with InsightVM's Goals & SLAs

十月 13, 2018 - MorningStar

Quick Cookie Notification

This site uses cookies, including for analytics, personalization, and advertising purposes. For more information or to change your cookie settings, click here.

If you continue to browse this site without changing your cookie settings, you agree to this use.


View Cookie Policy for full details

Optimize Your Security Operations with InsightVM's Goals & SLAs

  • Blog Home
  • How to Use InsightVM’s Goals & SLAs Feature to Define Important Metrics and Optimize Your Security Operations

Rapid7 Blog

How to Use InsightVM’s Goals & SLAs Feature to Define Important Metrics and Optimize Your Security Operations

Oct 30, 2018 3 min read

POST STATS:

SHARE

Optimize Your Security Operations with InsightVM's Goals & SLAs
Optimize Your Security Operations with InsightVM's Goals & SLAs
Optimize Your Security Operations with InsightVM's Goals & SLAs

 

Effective security metrics are frequently used to drive security performance improvements and overall risk reduction. However, they’re often not relevant to the business, as well as difficult to quantify and communicate. Rapid7 InsightVM’s new Goals & SLAs feature helps security teams define relevant and meaningful metrics so they’re able to set goals against them, track individual and team progress, and receive alerts when goals are achieved or missed.

The Goals & SLAs feature allows security teams to know what they should focus on and what they need to do to achieve their goals. It also enables better communication with others in the company in a way they can understand. Specifically, email notifications can automatically be sent for any changes in goal status, so you can avoid manual tracking efforts. And, if you add your goal to your dashboard, it will display graphically so you can see progress at a glance.

Start optimizing your security operations practice with a free trial of InsightVM today.

Get Started

Metric types

InsightVM offers three types of metrics to be tracked:

1. Time-bound goal

A time-bound goal lets you specify metrics for assets and vulnerabilities and assign a target date so you can track your progress as your deadline approaches. As an example, you can create a time-bound goal to remove 100% of Windows 7 desktops across the entire organization by Jan. 14, 2020. Time-bound goals have static scope, which means the scope of assets or vulnerabilities will be defined at the time of the goal creation and will not change, even if there are new assets or vulnerabilities found later on.

2. Continuous goal

A continuous goal lets you monitor progress or criteria without a time limit, such as a rule or key performance indicator. For example, if you want all your external-facing assets to have a closed SSH port, you can track this with a continuous goal. These have dynamic scope, which means any new asset or vulnerability discovered will be part of the metric.

3. SLA

A service-level agreement (SLA) goal—which will be released within the next several months—lets you track overall remediation of certain policies over a dynamic timespan. For example, you could set out to remediate 100% of critical vulnerabilities in production environments within three days of discovery, or remediate 75% of Windows Servers within 15 days of asset discovery date. SLAs also have dynamic scope.

How to create goals in InsightVM

Let’s take a look at the following use case: Your organization would like to limit the risk score for assets identified as high-risk. Let’s say your target is ensuring more than 80% of your assets have a risk score of less than 10,000. This is a continuous goal you can define in InsightVM with the new feature.

Now, let’s go through the screens to show you how you can set up the metric and view your progress afterward:

  1. After logging in to InsightVM (if you’re not an InsightVM customer you can get a full-featured trial here), click on the “Goals & SLAs” icon on the left navigation bar.

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. Click on “+ New Goal,” which will open up the wizard to walk you through the next steps.

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. In this scenario, select “Continuous” as the goal type, then click on “Continue.”

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. This is where you define the scope for the assets and vulnerabilities. In this example, our asset filter is: asset.tags IN [ "high risk" ]. Click here for more information on how to create filter queries in InsightVM.

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. Next, specify the criteria. This is where you actually define the metric. In our example, here is how we fill out the fields:

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. Next, you will give a name to your goal, then select on which dashboard(s) you would like a card for the goal.

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. Once you save the goal, it will appear on the listing page, which is where you see all of your goals and their statuses.

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. Clicking on any of the goals takes you to the details page for that particular goal.

Optimize Your Security Operations with InsightVM's Goals & SLAs

  1. Finally, here is how your dashboard card will look after the goal creation:

Optimize Your Security Operations with InsightVM's Goals & SLAs

Alternatively, you can add a new Goal Card to any of your dashboards by clicking on the “+ Add Card” button on the dashboard and selecting the appropriate goal card.

Optimize Your Security Operations with InsightVM's Goals & SLAs

After the blank card is added to your dashboard, you will select which goal should appear in it as follows:

Optimize Your Security Operations with InsightVM's Goals & SLAs

With the next version update of this new feature, we will also enable email notifications when your goals change status or when they are complete (if they are time-bound). Here is an example of an email notification:

Optimize Your Security Operations with InsightVM's Goals & SLAs

Once you identify the metrics that are important for your your organization’s security practices, InsightVM makes keeping track of your progress against those metrics both easy and painless. This is yet another way we help teams optimize their security operations and focus on risks that matter.

Start optimizing your security operations practice with a free trial of InsightVM today.

Get Started

POST STATS

POST TAGS

SHARING IS CARING

Optimize Your Security Operations with InsightVM's Goals & SLAs
Optimize Your Security Operations with InsightVM's Goals & SLAs
Optimize Your Security Operations with InsightVM's Goals & SLAs

Optimize Your Security Operations with InsightVM's Goals & SLAs

AUTHOR

Bulut Ersavas

Bulut Ersavas is a senior manager at Rapid7 responsible for the product management of the company's flagship vulnerability management products.

View Bulut Ersavas’s Posts

Want more? Don’t miss these posts

Shoring Up the Defenses Together: 2018Q2 and Q3 Wrap-Up

Today (October 29, 2018) we are sharing several vulnerabilities that have been fixed in Rapid7 products and supporting services.…

Read More

Whiteboard Wednesday: Common Vulnerabilities as Personified by Halloween Costumes

As a security professional, you don’t need a haunted house to feel spooked this Halloween—just start exploring your environment in search of vulnerabilities.…

Read More

Featured Research

National Exposure Index 2018

The National Exposure Index is an exploration of data derived from Project Sonar, Rapid7’s security research project that gains insights into global exposure to common vulnerabilities through internet-wide surveys.

Learn More

Toolkit

Make Your SIEM Project a Success with Rapid7

In this toolkit, get access to Gartner’s report “Overcoming Common Causes for SIEM Solution Deployment Failures,” which details why organizations are struggling to unify their data and find answers from it. Also get the Rapid7 companion guide with helpful recommendations on approaching your SIEM needs.

Download Now

Featured Research

Quarterly Threat Report

Rapid7’s Quarterly Threat Report leverages intelligence from our extensive network—including the Insight platform, managed detection and response engagements, Project Sonar, Heisenberg Cloud, and the Metasploit community—to put today’s shifting threat landscape into perspective. It gives you a clear picture of the threats that you face within your unique industry, and how those threats change throughout the year.

Learn More

Blog Feed

Optimize Your Security Operations with InsightVM's Goals & SLAs


Notice: Undefined variable: canUpdate in /var/www/html/wordpress/wp-content/plugins/wp-autopost-pro/wp-autopost-function.php on line 51