Asset Identification and Profiling – Gaining Visibility

The process for determining and managing the risk of your websites, as well as the data they store and retrieve is a multi-faceted one:

Asset Identification

You must identify all the website assets within your organization.  This is may not be an easy task, particularly within a large organization.  Business units may create new websites without involving the security organization. Company acquisitions and mergers can quickly add large numbers of websites to your roster.  And over time, URLs completely unrelated to the company’s brand are used, so identifying all the relevant websites through host names alone may prove impossible. 

Asset Prioritization – Risk Profiling

Once all your websites are identified, the next step is to categorize how critical each website is to the success of your business, based on several factors:

  • Does the website generate revenue?
  • Does the website store and retrieve regulated data?
  • Does the website contain any company-specific confidential data?

This information is key in determining the overall risk to the organization associated with each website. In turn, the risk determines the amount and timing of the resources that must be allocated toward each websites security.  Other factors may also be considered in terms of determining the overall risk to the organization – for example, when was the website developed and on what platform? If a site was developed many years ago, then it was probably not developed with methodologies in place to prevent current attacks.  In recent years programming platforms have been developed to automatically prevent many common website vulnerabilities.  If a site was not developed on one of these platforms, then there is a greater likelihood that the site may contain more of these types of vulnerabilities.  

Within the year, WhiteHat Security will further assist customers with this process of risk assessment and asset prioritization by providing our own risk profile recommendations.  Of course, customers can manage and adjusted this profile to adhere to their own internal risk management preferences.

“Our high security standards and partnerships with WhiteHat and Imperva ensure the security of our customers’ sensitive data, and really are helping to set the standards for the industry as a whole. Our security is leaps and bounds ahead of on-premise solutions, and it's making the decision to migrate over to cloud solutions even easier for large enterprises.”

Joe White
information security architect
SuccessFactors


 

 

 

 

Website Risk Management  |  Sentinel Services  |  Support Plus  |  Education Services  |  Events & News  |   Resources  |   Partners  |   About WhiteHat
2010 © Copyright  |  WhiteHat Security  |  3003 Bunker Hill Lane, Santa Clara, CA 95054  |  408.343.8300  |  Contact the Webmaster