<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tenable.io vs Security Center in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/7674#M144</link>
    <description>&lt;P&gt;I know this thread is a little dated, but I'll give you the rundown of both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, SC is the more mature product. With SecurityCenter, you have over 350 dashboards and reports, dynamic asset lists, automated events, RBAC, etc. It's downfall is that it's an IP-based model, so if you have DHCP or transient assets then SC will think the asset is a different machine every time it changes IP addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tenable.IO will one day have most of the functional parity from SC, but it's not there yet. The big advantage is that it uses an Asset based model instead of IP. Every unique asset gets assigned a GUID so it's tracked as the same asset no matter what changes. Tenable.IO also lets you expand into the Container and WAS markets with it's additional modules. If you are coming from Nessus Pro and don't mind your data being in the cloud, Tenable.IO would be my recommendation. I wouldn't send a SC user to T.IO until it's done some more maturing though.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2018 17:18:15 GMT</pubDate>
    <dc:creator>luckydude</dc:creator>
    <dc:date>2018-02-23T17:18:15Z</dc:date>
    <item>
      <title>Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5081#M138</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I currently use Nessus Pro for vulnerability scanning and management and I'm looking to add additional reporting and tracking of the history of my hosts to the setup. I've noticed that Nessus Pro greatly lacks any form of reporting and dashboard creation. The two solutions to this appear to be Security Center(on-prem) or Tenable.IO Vulnerability Management (cloud).&amp;nbsp;&lt;SPAN&gt;I'm looking to get some opinions from those that use or have looked into using these two products what seem to be the pros and cons&amp;nbsp;of each.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Josh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2018 22:30:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5081#M138</guid>
      <dc:creator>Jbayle1</dc:creator>
      <dc:date>2018-01-08T22:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5088#M139</link>
      <description>Hi Josh, You could look at my company - &lt;A href="https://cavirin.com/" target="_blank"&gt;https://cavirin.com/&lt;/A&gt; We have a strong cloud security, docker security, patch and vulnerability management and DevSecOps. If you are interested, I can get you up to a quick demo. Drop me some detailed information on your requirements at my first name at my company name. Thanks and regards, Pravin Goyal</description>
      <pubDate>Tue, 09 Jan 2018 01:41:32 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5088#M139</guid>
      <dc:creator>praving5</dc:creator>
      <dc:date>2018-01-09T01:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5103#M140</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using Nessus Pro as well and fully agree with you, lacking reporting and snap-ins.&lt;/P&gt;&lt;P&gt;We are looking at moving towards Nessus Manager which have much better reporting and snap-ip.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you need to inspiration, i suggest you to look at the Tenable education site. There are a tons of videos, very well made.&lt;/P&gt;&lt;P&gt;You have video for Nessus pro, manager, Security center and IO ( i think)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Jesper&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jan 2018 14:09:39 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5103#M140</guid>
      <dc:creator>jekat</dc:creator>
      <dc:date>2018-01-09T14:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5106#M141</link>
      <description>Jesper,&lt;BR /&gt;&lt;BR /&gt;Thanks for the tip. I will dig into their education site as part of my research on which tenable product to go with. I have not looked into manager at all so might be worth a look as well.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Josh</description>
      <pubDate>Tue, 09 Jan 2018 14:20:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5106#M141</guid>
      <dc:creator>Jbayle1</dc:creator>
      <dc:date>2018-01-09T14:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5196#M142</link>
      <description>&lt;P&gt;Security Center is the more matured and functional product at this point. IO does look to be the future of their products though as they are pressing hard to convert people to it (and to subscription based liscensing...). We started with SC and recently looked at going IO but from a liscensing an functionality standpoint it wasn’t a good fit for us. I’m sure over more time they will shore up some of the functionality gaps between IO and SC but that may be moot if IO would work for you as is today.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 03:21:45 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5196#M142</guid>
      <dc:creator>Clayjk</dc:creator>
      <dc:date>2018-01-12T03:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5222#M143</link>
      <description>&lt;P&gt;Yeah I think we are leaning towards Tenable.IO over Security Center.&amp;nbsp; SC does&amp;nbsp;appear to be&amp;nbsp;more&amp;nbsp;feature filled then IO.&amp;nbsp;We are looking into pricing for both right now to see where they stack up. That and a good POC will validate that IO can meet the reporting requirements we are looking for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Josh&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2018 15:46:24 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/5222#M143</guid>
      <dc:creator>Jbayle1</dc:creator>
      <dc:date>2018-01-12T15:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/7674#M144</link>
      <description>&lt;P&gt;I know this thread is a little dated, but I'll give you the rundown of both.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, SC is the more mature product. With SecurityCenter, you have over 350 dashboards and reports, dynamic asset lists, automated events, RBAC, etc. It's downfall is that it's an IP-based model, so if you have DHCP or transient assets then SC will think the asset is a different machine every time it changes IP addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tenable.IO will one day have most of the functional parity from SC, but it's not there yet. The big advantage is that it uses an Asset based model instead of IP. Every unique asset gets assigned a GUID so it's tracked as the same asset no matter what changes. Tenable.IO also lets you expand into the Container and WAS markets with it's additional modules. If you are coming from Nessus Pro and don't mind your data being in the cloud, Tenable.IO would be my recommendation. I wouldn't send a SC user to T.IO until it's done some more maturing though.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 17:18:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/7674#M144</guid>
      <dc:creator>luckydude</dc:creator>
      <dc:date>2018-02-23T17:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/7680#M145</link>
      <description>&lt;P&gt;Much appreciated feed back from everyone in this thread. Just to close the loop we did end up going with Security Center over IO specifically because the product is more mature and fits the needs (and cost) we were looking for. After speaking with the rep. it should be semi easy to migrate into IO once it gains more features but SC solved our use cases quite well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Josh&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 22:18:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/7680#M145</guid>
      <dc:creator>Jbayle1</dc:creator>
      <dc:date>2018-02-23T22:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/7856#M146</link>
      <description>&lt;P&gt;Agreed Pro feels stripped down since the last maybe two major releases only to expose the flaws in both Pro and .IO in general.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind, if not watch a video or two, creating a scanning and reporting routine is first divided into two phases: Object creation and reporting. No longer a one step configuration as happened in the past. The latest reporting is truly worth the effort and cost if your so inclined but setup may take longer than initially expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did break one process with Golden Gate in the&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 22:11:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/7856#M146</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2018-02-26T22:11:40Z</dc:date>
    </item>
    <item>
      <title>Launching Network Vulnerability Analyzer, a tool for analyzing Nessus scan files.</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14509#M452</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="twitter_profile_image.png" style="width: 200px;"&gt;&lt;img src="https://community.isc2.org/t5/image/serverpage/image-id/2699iB223EE908CFF91B8/image-size/small?v=v2&amp;amp;px=200" role="button" title="twitter_profile_image.png" alt="twitter_profile_image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Network Vulnerability Analyzer (NVA) allows users of the Nessus scanner to combine multiple .nessus files into Composite Scans.&lt;/P&gt;&lt;P&gt;Scans can be composed of .nessus files that are produced from multiple scanner runs.&lt;BR /&gt;Fulfilling the needs of an organization to run scans on numerous devices can be very time consuming.&lt;BR /&gt;Composite Scans allow an organization to scan subsets of all their devices and start the analysis immediately, while the rest of the devices continue to be scanned.&lt;BR /&gt;Each .nessus file produced by scanning a subset of devices can be later added to the Composite Scan.&lt;/P&gt;&lt;P&gt;NVA allows individual Composite Scans to be analyzed and compared.&lt;BR /&gt;Scan comparison allows an organization to determine and prove whether security measures are implemented promptly and efficiently, resulting in reducing the number of vulnerabilities.&lt;/P&gt;&lt;P&gt;Reports can be analyzed in tabular and graphic format and can also be exported to various file formats (.xls, .csv, .xml) for further analysis.&lt;/P&gt;&lt;P&gt;To get a quick idea of whether the NVA would benefit your company's needs, create a Demo Account.&lt;BR /&gt;This gives you 15 days to play around with the tool and get familiar with its capabilities.&lt;BR /&gt;Demo Accounts provide example Composite Scans, Scan Comparisons, and an Admin and non-Admin user.&lt;BR /&gt;Demo Accounts are Read-Only.&lt;/P&gt;&lt;P&gt;The content of the .nessuss files are encrypted on load, and resides encrypted in our DB which is running in the Amazon Cloud.&lt;/P&gt;&lt;P&gt;Licensing is based on the number of users that can access NVA at the same time.&lt;BR /&gt;There is no limit on the number of devices being scanned.&lt;/P&gt;&lt;P&gt;Monthly and Yearly Subscriptions are available.&lt;/P&gt;&lt;P&gt;Subscription can be canceled at any time and a prorated refund will be issued for the unused portion.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 15:57:31 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14509#M452</guid>
      <dc:creator>NVAnalyzer</dc:creator>
      <dc:date>2018-09-08T15:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14510#M453</link>
      <description>&lt;P&gt;Check &lt;A href="https://nvanalyzer.com" target="_blank"&gt;https://nvanalyzer.com&lt;/A&gt; for a tool that allows combining Nessus scan files into logical scans, analyzing and comparing them.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 15:58:28 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14510#M453</guid>
      <dc:creator>NVAnalyzer</dc:creator>
      <dc:date>2018-09-08T15:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14890#M477</link>
      <description>&lt;P&gt;Hi,&amp;nbsp; just thought I would add my experience.&amp;nbsp; We started life with Openvas and then added a Nessus Pro when our pen testers started giviing us reports from a Nessus scan.&amp;nbsp; We were using Nessus pro for approx 6 months and exporting the results into Excel with resonable success.&amp;nbsp; We then started to look at Security Center but were guided down the IO route as we were looking at a Siem solution to run alongisde.&amp;nbsp; Tenable IO is a great product and easy to use, you can make API calls into the backend to export results into a SIEM, you can also do the normal export into Excel.&amp;nbsp; The reporting in TIO is ok, I still think it needs work as a lot of the reports are fixed and it lacks the ability to create fully custom reports.&amp;nbsp; I would say you would be best to sign up for a free trial to have a look through the TIO reporting options.&amp;nbsp; Happy to take any futher questions if I can help.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Sep 2018 11:19:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14890#M477</guid>
      <dc:creator>robinfoprotech</dc:creator>
      <dc:date>2018-09-24T11:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable.io vs Security Center</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14981#M481</link>
      <description>&lt;P&gt;It could be worth your time to take a look at &lt;SPAN&gt;VulnWhisperer&amp;nbsp; (&lt;/SPAN&gt;&lt;A href="https://github.com/austin-taylor/VulnWhisperer" target="_blank"&gt;https://github.com/austin-taylor/VulnWhisperer&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It can integrate with various scanners like Nessus, OpenVAS and Qualys. So you can have multiple scanners and view the results in the same interface. The big use case I can see that you can purchase a&amp;nbsp;certified scanner for your internet facing IP addresses while using OpenVAS for your internal environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that I have not personally tried it yet but I do know the underlying stack it uses (The Elastic Stack) and the reporting and data mining features are solid. Also I am in no way connected to that project, just find the approach to be good.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 12:29:00 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Tenable-io-vs-Security-Center/m-p/14981#M481</guid>
      <dc:creator>Elvar</dc:creator>
      <dc:date>2018-09-26T12:29:00Z</dc:date>
    </item>
  </channel>
</rss>

