nCircle Announces SCAP Validation

Wednesday, July 02, 2008



SAN FRANCISCO, CA — nCircle today announced the Security Content Automation Protocol (SCAP) validation of nCircle IP360 and nCircle IP360 Mobile, the world's leading vulnerability and risk management system. As one of the early SCAP-validated solutions on the market, nCircle IP360 provides U.S. Federal agencies with an enterprise class system to support the largest networks, while at the same time delivering SCAP certified vulnerability scanners with the ability to determine the presence of known software flaws by evaluating the target system over the network. SCAP is a protocol using specific standards to enable automated vulnerability management, measurement, and policy compliance evaluation (e.g., FISMA compliance) and is sponsored by the Information Security Automation Program (ISAP), a U.S. government multi-agency initiative to enable automation and standardization of technical security operations.

"nCircle has been a charter member of the committees that created these protocols and we look forward to making SCAP an important open interface in the nCircle product line.” said Tim Keanini, Chief Technology Officer at nCircle. “Like our Common Criteria Certification at EAL Level 3, this represents our commitment to standards enabling government agencies to improve security and achieve compliance at the lowest possible cost."

nCircle delivers a full suite of security and compliance products for vulnerability assessment, risk management, configuration auditing and compliance, and file integrity monitoring. With the first two products certified, nCircle will submit additional solutions for SCAP validation including certification as a Federal Desktop Core Configuration (FDCC) Scanner and as an Authenticated Configuration Scanner, supporting the U.S. Office of Management and Budget (OMB) mandate that all government agencies must meet a core configuration standard for desktop computers. With an objective to improve overall system security and reduce costs though standardization, the OMB mandate is furthering the adoption of SCAP to enable security technologies to read and exchange systems and vulnerability information in a common format providing the foundation for interoperability among security and compliance products, ultimately delivering a more secure environment.
More information about SCAP-validated products can be found at http://nvd.nist.gov/scap.cfm.


About the nCircle Suite of Solutions
nCircle provides the world's most comprehensive suite of solutions for agentless security risk and compliance management. nCircle’s solutions combine the broadest discovery of networked systems and their operating systems, applications, vulnerabilities and configurations with advanced analytics to help enterprises reduce security risk and achieve compliance. nCircle's solutions includes IP360™ for vulnerability and risk management, WebApp360™ for web application vulnerability auditing, Configuration Compliance Manager (CCM)™ for configuration auditing and file integrity monitoring, Certified PCI Scan Service™ for on-demand self-service PCI scanning, and Security Intelligence Hub™ for IT governance, risk and compliance (ITGRC) reporting and analytics.

About nCircle
nCircle is the leading provider of agentless security risk and compliance management solutions. More than 4,000 enterprises, government agencies and service providers around the world rely on nCircle's proactive security solutions to manage and reduce security risk and automate compliance on their networks. nCircle has won numerous awards for growth, innovation, customer satisfaction and technology leadership.  nCircle is headquartered in San Francisco, CA, with regional offices throughout the USA and in London and Toronto. Additional information about nCircle is available at www.ncircle.com.