Castleforce IT Security Team

Lumension IT Secured Success Optimised

Vulnerability Scan

Rapid Detection of Vulnerabilities and Complete Asset Discovery

Lumension Scan is a complete stand-alone network-based scanning solution that performs a comprehensive assessment of all the devices connected to your network, both managed and unmanaged. Once all assets are identified Lumension Scan detects weaknesses on these devices before they can be exploited.

Enquire about this product

5 Virusn5 Spywaren5 Spamn5 Web/IMn5 IPS/Patch Mgmtn5 Data/System Mgmtn


How Lumension Patch and Remediation Works

How Lumension Scan Works

1. Discover : Gain complete visibility of your heterogeneous network environment. Proactively discover all of your IT assets, both managed and unmanaged, through in-depth scans and flexible grouping and classification options.

2. Assess: Proactively identify known issues before they can be exploited. Perform a deep analysis and thorough OS, application, and security configuration vulnerability assessments.

3. Prioritize: Threats and indentify risk mitigation to aid in the remediation process.

4. Report: Gain a holistic view your environmental risk. Access a full range of operational and management reports that consolidate discovery, assessment, and remediation information on a single management console.

Lumension Vulnerability Scan Key Features

Complete Asset Discovery

  • Automated discovery of all network devices (i.e. servers, desktop computers, laptops, routers, printers, switches, wireless access points, etc.), major Operating Systems and infrastructure.

Comprehensive Vulnerability Coverage

  • Over 4000 vulnerability audits with wide support across major OS platforms (Windows, Linux, MacOS, Sun Solaris, HP, etc.), POSIX and infrastructure devices.
  • Vulnerability audits include security configurations, OS and application vulnerabilities, null passwords, patch-level related vulnerabilities, known hacking tools, malware, common worms, and P2P software checks.

Adaptive and Targeted Scanning

  • The most accurate vulnerability assessment scan using flexible network-based scanning techniques
  • Various access-levels including credentialed- and null-based
  • Performs ad hoc scans that can target one or many machines, Active directory, IP ranges, OUs, specific vulnerabilities, etc.

Customizable Vulnerability Set

  • Define the scope of vulnerabilities to include in your scan
  • Offers a predefined list including CVE, Bugtraq, SANS, MS Advisory, NVD.

Role-based Administration and Control

  • Enables distributed management of scan activity by user roles.
  • Delegates remediation and reporting activities to improve productivity while maintaining security.

Distributed Discovery and Assessment

  • Effectively scan & assess even complex and geographically distributed network environments across the WAN.

Automated and Template-based Scanning

  • Schedule and automate recurring scan tasks to run on a daily, weekly or monthly basis.

Consolidated Vulnerability Library

  • Extensive vulnerability database with informational resources and remediation recommendations
  • Provides details of identified vulnerabilities, cross-mapping identifiers, and impact to the organization, description of attack, options to fix, and additional references for further investigation.

Risk-Based Prioritization

  • All scanned systems are evaluated and prioritized according to asset value and vulnerability criticalities using straight-forward equations.
  • All systems are listed by risk severity (High, Medium, Low, Warning and Information).

Comprehensive Reporting

  • Ability to create and export numerous high-level or detailed reports of all scan data.
  • Documents changes and demonstrates progress toward audit and compliance requirements with enterprise and local reporting of asset inventory, network or agent-based scans, vulnerability remediation and much more.

Non-Disruptive Scanning

  • Designed to safely scan for vulnerabilities using standard networking protocols with minimum impact to your network.
  • Never employs malicious vulnerability attacks.

Supports Heterogeneous Platforms and Applications

  • MAC OS, Linux, Unix, Windows, and infrastructure devices.
  • Vulnerability audits include security configurations, OS and application vulnerabilities, null passwords, patch-level related vulnerabilities, known hacking tools, malware, missing patches, out-of-date antivirus signatures, worms, Trojans, and more.

Highly Scalable

  • Modular components can be installed on the same or separate systems and scaled-up as needed.
  • Multiple instances of the scan engine can be deployed across the enterprise, controlled remotely or locally.
  • As the number of systems on the network increase so can the number of engines performing the scans.

Common Criteria EAL2 Certified

  • The Common Criteria Evaluation and Certification Scheme (CCS) Certification Body has asserted that Lumension Scan complies with all the specified security requirements.


Contact Lumension Partner

Lumension Scan Vulnerability Assessment Datasheet

Lumension-VMS-vs-Microsoft-WSUS


Lumension Product Line Support Offerings Datasheet

Castleforce also assists in providing the following services for Lumension.

  • WebEx demonstration
  • Installation and workshop
  • Professional consultancy


Compliance Standards

Castleforce can help you reach PCI DSS

Requirement 5: Use and regularly update anti-virus software

Castleforce can help you reach GCSx CoCo

GCSX No 13 Protective Monitoring

Castleforce can help you reach ISO27001

A.10.10 Monitoring

A.12.6 Technical Vulnerability Management