RE: Nessus - Information about Policies required.

"H, Karthick" <[email protected]>
Newsgroups gmane.comp.security.nessus.general
Message-ID <B760F60A6C811C4EAD994C57994B218F1F27347CD3@G3W0639.americas.hpqcorp.net>
Hi Ron,
Thanks a lot.

Regards,
Karthick

-----Original Message-----
From: Ron Gula [mailto:[email protected]]
Sent: 26 May 2008 17:53
To: H, Karthick
Cc: Dey, Sutapa; [email protected]
Subject: Re: Nessus - Information about Policies required.

Hello HP,

> 1. Are there any customized industry specific/OS specific/Device Specific Nessus policies already available?
>
>  E.g.: Nessus Policy based on SANS top 20 vulnerabilities, Nessus Policy for Windows 2003 server, Nessus policy for IOS.

There are several answers to this:

- even on a full scan, Nessus automatically tunes itself.
- there are several dozen specific plugin families (such as an Cisco family)
   which make it easy to build polices.
- We've published SANS Top 20 policies at blog.tenablesecurity.com which also
   has lots of Nessus information you should read.

> 2. Is it possible to create Nessus policies, export and save it (Say Policy1.nessus)? If Yes, Can these saved policies be used (deployed) in a Nessus server in another network (Say just by copying the Policy1.nessus and pasting it in some specified location of Nessus server in another network)?

You should read the blog entries on this topic, as well as the papers on
the .nessus report format and usage in the documentation section of the
Nessus web site.

Ron Gula
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.