Features
Supports both agent-based scanning and scanning via agency-managed Nessus Scanner/Local Scanner (credentialed and non-credentialed).
Provides basic web application scanning capabilities, such as testing HTTP methods and attempting HTTP Parameter Pollution.
Offers scanning aligned with CIS benchmarks, allowing agencies to check against their security hardening baselines and improve security posture against misconfigurations or as part of the System Security Acceptance Test prior to commissioning.
Features various dashboards for:
- Monitoring vulnerabilities in Production and UAT systems separately.
- Identifying patch and configuration vulnerabilities.
- Providing an overview of systems' compliance with IM8 policies on vulnerability tracking and aging.
- Summarising OS and application vulnerabilities by application systems.
Reports vulnerabilities across Operating Systems (OS), Application Software installed on servers, and Network Devices.
Capable of scanning both Internet and Intranet systems across the Whole-of-Government Government Enterprise Network and Cloud Hosting Environments.