News
4/10/2014
08:00 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Tripwire Donates $11.75M Cybersecurity Service to Penn State

Gift is a cloud-based risk and analytics cybersecurity service to the Center for Cyber Security, Information Privacy and Trust.

PORTLAND, OREGON April 10, 2014 Tripwire, Inc., a leading global provider of risk-based security and compliance management solutions, today announced a gift of a  cloud-based risk and analytics cybersecurity service to the Center for Cyber Security, Information Privacy and Trust at Penn State’s College of Information Sciences and Technology

The non-exclusive license grant provides a license to Tripwire® Benchmark, a cloud-based risk and analytics cybersecurity service. Penn State has valued the technology at $11.75 million, and it is the single largest contribution the College of IST has received to date.

“This very significant gift provides unique opportunities for the College of IST for research, education and outreach,” said Dr. David Hall, dean of the College of Information Sciences and Technology. “Our research in cyber security, big data analytics and discovery, and human-computer interaction match very well with Tripwire’s evolving database and toolkit. We will be able to use this gift in classroom exercises and in the curricula for our undergraduate Security and Risk Analysis (SRA) major and graduate program in Cyber Security and Information Assurance. We are very thankful for Tripwire’s generosity and will display the gift prominently in the IST Building’s new laboratory.”   

Tripwire selected Penn State for this donation to further the education of future cybersecurity leaders as well as develop a community of experts that share information and analytics unavailable from other sources. The free service will help address the serious economic and national security issues presented by cybersecurity risks. 

“We’re excited about our partnership with Penn State’s College of IST,” said Rod Murchison, vice president of product management for Tripwire and Penn State alumnus. “Our goal is to support their renowned security and risk analysis program and help mold the next generation of cybersecurity leaders. In addition, this donation has the potential to have an enduring and positive impact on today’s cybersecurity professionals by providing the kind of industry analytics necessary to maximize the value of existing security investments.”

The growing national focus on information assurance and cybersecurity and a worldwide shortage of information security experts has organizations of every size looking for objective, transparent analytics that can accurately assess risk and maximize the effectiveness of security and compliance investments.  The new Penn State service is designed to deliver security performance metrics, scorecards and analytics that help organizations worldwide do the following:

· Build risk-based security and compliance management programs based on objective, fact-based metrics.

· Prove that existing security investments and resources are protecting the organization as well as identify areas of weakness that need additional investment.

· Benchmark security performance against internal goals and industry peers.

· Trend risk-based security performance metrics over time.

The grant will also be used by Penn State for additional cybersecurity research and the development of new metrics.

Penn State's College of IST is a leader in cybersecurity risk analysis and has been designated a National Center of Academic Excellence in Information Assurance Education by the National Security Agency and the Department of Homeland Security. The unique, interdisciplinary security and risk analysis programs at Penn State are designed to teach students how to secure systems, evaluate and measure risk, and ensure proper levels of privacy protection.

The free Penn State security analytics cloud service is available today to any organization that would like to measure the effectiveness of their IT security investments. For more information and access to security and risk metrics, scorecards, and benchmarks please visit https://benchmark.ist.psu.edu/.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1414
Published: 2015-02-27
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory.

CVE-2015-2072
Published: 2015-02-27
Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/templates/trace/hanaTraceDetailService.xsjs or...

CVE-2015-2075
Published: 2015-02-27
SAP BussinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.

CVE-2015-2076
Published: 2015-02-27
The Auditing service in SAP BussinessObjects Edge 4.0 allows remote attackers to obtains sensitive information by reading an audit event, aka SAP Note 2011395.

CVE-2015-2101
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in the Navigate bar in the Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.