Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

10/8/2019
11:45 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Xacta.io Leverages Security Data at Scale to Actively Manage Cyber-Risk

Telos Corporation delivers next-generation cyber-risk management platform for complex on-premises, hybrid, and cloud-based environments.

ASHBURN, Va., Oct. 08, 2019 (GLOBE NEWSWIRE) -- Telos ® Corporation, a leading provider of cyber, cloud and enterprise security solutions for the world’s most security-conscious organizations, today announced the general availability of Xacta.io™, the next generation cyber risk management platform.

Designed to address the complexity of managing cyber risk and compliance in modern computing environments – from cloud, multi-cloud and on-premises assets – Xacta.io empowers users to maximize the value of security risk and compliance data to derive intelligence required to actively manage cyber risk. Information gathered by Xacta.io can assist in making decisions pertaining to authorization, remediation prioritization, process and status reporting, resource investments, risk avoidance, and more.

“Security risk and compliance remains a hurdle for cloud adoption,” said John B. Wood, chairman and CEO of Telos. “This task is even more difficult for multi-cloud and hybrid environments.  Automation is critical for gathering, organizing, and operationalizing the data needed to continuously manage cyber risk for regulated and non-regulated industries alike. Xacta.io is specifically designed to address these complex use-cases, which will ultimately help accelerate cloud adoption.”  

Built on a microservices-based, environment-agnostic technology stack, Xacta.io is able to ingest and process data on a massive scale.  Third-party security data sources compatible with Xacta.io include security and vulnerability scanners, endpoint agents, and application programming interfaces (APIs) from cloud service providers.

Complementing the ability to ingest enormous amounts of security data is an advanced visualization dashboard that provides compliance scorecards, regulatory reporting, ad-hoc reporting, analytics and decision support.  Xacta 360 users will also benefit from these enhanced visualization and dashboard capabilities.

"Though compliance management remains a core mission, Xacta.io isn’t just for automation of authorization activities,” said Richard Tracy, CSO of Telos. “Xacta.io will offer much more advanced capabilities, leveraging vast amounts of security and compliance data at scale to enable informed decision-making around cyber risk. Ultimately, Xacta.io will become the hub for all things Xacta, as a flexible platform supporting a broad range of modular services and applications that meet our customers’ cybersecurity requirements.”

Xacta.io will soon include integration with the AWS and Azure clouds, with additional services added over time. For more information, please visit: www.telos.com/xacta.

About Telos Corporation
Telos Corporation empowers and protects the world’s most security-conscious organizations with solutions for continuous security assurance of individuals, systems, and information. Telos’ offerings include cybersecurity solutions for IT risk management and information security; cloud security solutions to protect cloud-based assets and enable continuous compliance with industry and government security standards; and enterprise security solutions to ensure that personnel can work and collaborate securely and productively. The company serves military, intelligence and civilian agencies of the federal government, allied nations and commercial organizations around the world.  The company is a recipient of the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Security Service (DSS), awarded to less than .03% of eligible organizations. For more information, visit www.telos.com and follow the company on Twitter @TelosNews

Contact:
Allison Phillipp
Telos Corporation
Email: [email protected]  
Phone: 703.724.3642

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
For Cybersecurity to Be Proactive, Terrains Must Be Mapped
Craig Harber, Chief Technology Officer at Fidelis Cybersecurity,  10/8/2019
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17593
PUBLISHED: 2019-10-14
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
CVE-2019-17594
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-17595
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-14823
PUBLISHED: 2019-10-14
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to...
CVE-2019-17592
PUBLISHED: 2019-10-14
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.