Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

10/8/2019
11:45 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Xacta.io Leverages Security Data at Scale to Actively Manage Cyber-Risk

Telos Corporation delivers next-generation cyber-risk management platform for complex on-premises, hybrid, and cloud-based environments.

ASHBURN, Va., Oct. 08, 2019 (GLOBE NEWSWIRE) -- Telos ® Corporation, a leading provider of cyber, cloud and enterprise security solutions for the world’s most security-conscious organizations, today announced the general availability of Xacta.io™, the next generation cyber risk management platform.

Designed to address the complexity of managing cyber risk and compliance in modern computing environments – from cloud, multi-cloud and on-premises assets – Xacta.io empowers users to maximize the value of security risk and compliance data to derive intelligence required to actively manage cyber risk. Information gathered by Xacta.io can assist in making decisions pertaining to authorization, remediation prioritization, process and status reporting, resource investments, risk avoidance, and more.

“Security risk and compliance remains a hurdle for cloud adoption,” said John B. Wood, chairman and CEO of Telos. “This task is even more difficult for multi-cloud and hybrid environments.  Automation is critical for gathering, organizing, and operationalizing the data needed to continuously manage cyber risk for regulated and non-regulated industries alike. Xacta.io is specifically designed to address these complex use-cases, which will ultimately help accelerate cloud adoption.”  

Built on a microservices-based, environment-agnostic technology stack, Xacta.io is able to ingest and process data on a massive scale.  Third-party security data sources compatible with Xacta.io include security and vulnerability scanners, endpoint agents, and application programming interfaces (APIs) from cloud service providers.

Complementing the ability to ingest enormous amounts of security data is an advanced visualization dashboard that provides compliance scorecards, regulatory reporting, ad-hoc reporting, analytics and decision support.  Xacta 360 users will also benefit from these enhanced visualization and dashboard capabilities.

"Though compliance management remains a core mission, Xacta.io isn’t just for automation of authorization activities,” said Richard Tracy, CSO of Telos. “Xacta.io will offer much more advanced capabilities, leveraging vast amounts of security and compliance data at scale to enable informed decision-making around cyber risk. Ultimately, Xacta.io will become the hub for all things Xacta, as a flexible platform supporting a broad range of modular services and applications that meet our customers’ cybersecurity requirements.”

Xacta.io will soon include integration with the AWS and Azure clouds, with additional services added over time. For more information, please visit: www.telos.com/xacta.

About Telos Corporation
Telos Corporation empowers and protects the world’s most security-conscious organizations with solutions for continuous security assurance of individuals, systems, and information. Telos’ offerings include cybersecurity solutions for IT risk management and information security; cloud security solutions to protect cloud-based assets and enable continuous compliance with industry and government security standards; and enterprise security solutions to ensure that personnel can work and collaborate securely and productively. The company serves military, intelligence and civilian agencies of the federal government, allied nations and commercial organizations around the world.  The company is a recipient of the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Security Service (DSS), awarded to less than .03% of eligible organizations. For more information, visit www.telos.com and follow the company on Twitter @TelosNews

Contact:
Allison Phillipp
Telos Corporation
Email: [email protected]  
Phone: 703.724.3642

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Human Nature vs. AI: A False Dichotomy?
John McClurg, Sr. VP & CISO, BlackBerry,  11/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: -when I told you that our cyber-defense was from another age
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-3350
PUBLISHED: 2019-11-19
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
CVE-2011-3352
PUBLISHED: 2019-11-19
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context ...
CVE-2011-3349
PUBLISHED: 2019-11-19
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.
CVE-2019-10080
PUBLISHED: 2019-11-19
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI ...
CVE-2019-10083
PUBLISHED: 2019-11-19
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.