Security scan results may provide with a false sense of security
Security scanning results will show what only those results where security scanning host had access to.
For example a system maybe running a vulnerable version of mail software, but access to mail protocols is prevented at the firewall level.
Security scanning results in such a case will result in “all clear”, where in reality there is a problem.
Security scanning hosts will need to have proper access to network or hosts that they scan.
If network is segmented into several subnetworks, and these subnetworks limit network traffic, then consider implementing a security scan per network segment, or work with your network administrators to allow unrestricted network traffic from security scanning host.
Comments
Post a Comment