Vulnerabilities / Threats

1/22/2018
12:55 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Tripwire Debuts Cybersecurity Suite for Protecting Industrial Control Systems (ICS)

Tripwire ICS Cyber Resiliency Suite comes with ICS configuration and vulnerability assessment for enhanced availability

PORTLAND, Ore. – January 22, 2018 –Tripwire, Inc., a leading global provider of security and compliance solutions for enterprises and industrial organizations, today announced the debut of Tripwire ICS Cyber Resiliency Suite. This cybersecurity solution reduces the cyber risk for operational technology (OT) environments in industries such as utilities and manufacturing to drive availability, safety and resilience.

The Tripwire ICS Cyber Resiliency Suite provides secure configuration management (SCM), vulnerability management (VM) and log management (LM) capabilities purpose-built for industrial use cases. It offers the industry no-touch security configuration and vulnerability assessment capabilities that can operate within ICS levels without disrupting controller function, and can monitor a full range of ICS devices and system manufacturers. With Tripwire’s ICS Cyber Resiliency Suite, users can easily prove compliance by checking configurations against established industry standards and best practices.

“When it comes to critical infrastructure, cyber threats can lead not only to data and financial loss, but also to severe physical consequences like operational shutdown and physical harm," said Tim Erlin, vice president of product management and strategy at Tripwire. "We developed the Tripwire ICS Cyber Resiliency Suite to help operators build stronger security and resilience in their operating environments while also supporting requirements for production availability and operational excellence. These solutions provide operators with a comprehensive approach for maintaining secure and compliant postures across multiple ICS layers, components and suppliers."

The suite's full complement of security capabilities gives customers the flexibility to choose what meets their specific needs, including:

  • Asset discovery - physical and virtual.
  • Continuous change monitoring and incident detection.
  • Device and system log data collection and event correlation.
  • A no-touch approach security assessment for ICS and industrial devices.
  • Configuration assessment and hardening.
  • Built-in industrial best practices standards and guidance.
  • Vulnerability assessment.
  • Industrial dashboards and reporting.
  • Integrations with leading factory automation systems for workflow efficiency.

With the Tripwire ICS Cyber Resiliency Suite, industrial operators can gain a better understanding of their cyber risks as well as the insight needed to minimize and effectively monitor their attack surface. Because this cybersecurity solution can be integrated with a wide variety of systems, both the workload and complexity of managing ICS security, resilience and regulatory compliance are reduced.

For more information, please visit: https://www.tripwire.com/solutions/industrial-control-systems/Tripwire-ICS-Cyber-Resiliency-Suite

About Tripwire

 

Tripwire is a leading provider of integrity assurance solutions that improve security, compliance and IT operations in enterprises, industrial organizations, service providers and government agencies. Tripwire solutions are based on high-fidelity asset visibility and deep endpoint intelligence combined with business context; together, these solutions integrate and automate security and IT operations. Tripwire’s enterprise-class portfolio includes file integrity monitoring, configuration management, asset discovery, vulnerability management and log collection that supports all widely used industry-standard frameworks.

 

Learn more at www.tripwire.com, get security news, trends and insights at www.tripwire.com/blog, or follow us on Twitter @TripwireInc

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
6 Ways Greed Has a Negative Effect on Cybersecurity
Joshua Goldfarb, Co-founder & Chief Product Officer, IDRRA ,  6/11/2018
Weaponizing IPv6 to Bypass IPv4 Security
John Anderson, Principal Security Consultant, Trustwave Spiderlabs,  6/12/2018
'Shift Left' & the Connected Car
Rohit Sethi, COO of Security Compass,  6/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12026
PUBLISHED: 2018-06-17
During the spawning of a malicious Passenger-managed application, SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows such applications to replace key files or directories in the spawning communication directory with symlinks. This then could result in arbitrary reads and writes, which in tur...
CVE-2018-12027
PUBLISHED: 2018-06-17
An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation: given a Passenger-spawned application process that reports that it listens on a certain Unix domain socket, if any of the parent directories of said ...
CVE-2018-12028
PUBLISHED: 2018-06-17
An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, to report an arbitrary different PID back to Passenger's process manager. If the malicious application then generates an e...
CVE-2018-12029
PUBLISHED: 2018-06-17
A race condition in the nginx module in Phusion Passenger 3.x through 5.x before 5.3.2 allows local escalation of privileges when a non-standard passenger_instance_registry_dir with insufficiently strict permissions is configured. Replacing a file with a symlink after the file was created, but befor...
CVE-2018-12071
PUBLISHED: 2018-06-17
A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.