×
×
×
×

Vulnerability Management

Endpoint Central provides a comprehensive framework to mitigate different kinds of security threats that can affect the functionality of your systems.

Perform Vulnerability Detection and Remediation

Vulnerability Assessment and Prioritization

Endpoint Central facilitates continuous scanning of vulnerabilities for both OS and third-party applications across all managed computers in your network. You can access and prioritize the discovered vulnerabilities based on Exploit Status, Patch Availability, CVSS scores, Severity Levels, and published and discovered dates.

Vulnerability Remediation

After assessing and prioritizing the vulnerabilities, it is crucial to remediate them by deploying the appropriate patches — either manually or through automated patch deployment tasks using the Patch Management feature. Timely patching plays a vital role in closing security gaps, preventing exploitation, and ensuring that known vulnerabilities do not become entry points for attackers.

Zero-day Vulnerability Mitigation

The proactive diagnosis of zero-day vulnerabilities helps you discover gaps or flaws in applications or operating systems. These zero-day vulnerabilities are displayed in a separate view for your immediate attention. You can also remediate them directly from this view.

Monitor Compliance and Implement Network Access Controls

System and Web Server Hardening

The security configurations feature of Endpoint Central is based on over 200+ rules from CIS and STIG benchmarks. You can identify security misconfigurations present across managed systems and web server misconfigurations across managed servers, and view the resolution steps to fix each issue.

CIS Compliance Checks

Some enterprises follow benchmarking guidelines set by CIS for providing certifications after security audits. Endpoint Central provides compliance checks by auditing endpoints based on 90+ policies framed by CIS, and then gives a detailed report on how well these compliance guidelines are met. If any rules fail to comply, manual resolutions are also provided.

Note
Endpoint Central is a certified CIS vendor and has been awarded CIS Security Software Certification for CIS Benchmark(s).

Network Access Control (NAC) using System Quarantine Policy

Endpoint Central's system quarantine policy helps organizations implement Network Access Control (NAC) and proactively manage system compliance, reduce vulnerabilities, and enhance overall security posture by isolating non-compliant systems based on defined rules.

Perform Audits and Comprehensive Reporting

High-risk Software Audit

You can identify and monitor end-of-life software, which poses significant security risks due to lack of vendor support. Endpoint Central also detects high-risk applications like remote desktop sharing and peer-to-peer software, which can expose firewall ports, enable unverified file sharing, and increase the risk of malware or data breaches. These applications can be uninstalled if unnecessary or added to an exception list if deemed essential for business operations.

Port Audit

Every application or service uses a port to communicate over a network. With continuous port audits, you can monitor active ports, identify what is listening on them, and detect exposed or unintended ports.

Generate and Schedule Reports

You can generate and schedule detailed reports about all vulnerability management processes to ensure adherence to standards. These reports, categorized as Executive and Pre-defined, provide detailed insights into system patching, aiding in vulnerability identification and addressing network security and compliance concerns.

Additional Resources

To learn more about Comprehensive Coverage, refer to this page.

If you have any further questions, refer to the Frequently Asked Questions section.

Related