Vulnerability Management | Rapid7

Carnegie Mellon University Selects Rapid7’s NeXpose for its Broad Asset Protection and Centralized Risk Monitoring, Ensuring Campus-wide Security

NeXpose Meets Leading Technology School’s Requirements for Vulnerability Scanning, Co-Development and Higher Education Experience

Boston - May 8, 2007 - Rapid7 today announced that Carnegie Mellon University, a global research university recognized for its unparalleled technology programs, has selected the NeXpose award-winning vulnerability management solution for securing its campus-wide systems and networks. NeXpose will enable Carnegie Mellon to perform extensive scanning, conduct more centralized monitoring and effect root cause analysis.

"As we tested NeXpose, we found that the product’s evolution mapped to our needs, which we attribute to Rapid7's responsiveness to our input as well as its experience in the higher education industry," stated Mary Ann Blair, director of information security at Carnegie Mellon. "NeXpose offers exactly what we sought in terms of feature sets, such as support for Linux, a secure Web interface and the ability to create and export customized reports. NeXpose became even more attractive with the introduction of its PCI compliance capabilities."

The NeXpose features Carnegie Mellon found most prominent are its open API architecture, its asset groupings and the access controls with those assets.

"With the open API, we will have the ability to write our own software to manipulate NeXpose and create, for example, auto provisioning accounts and access controls," stated Jason Carr, security engineer at Carnegie Mellon. "The asset groups with access control will enable us to allow many users to view their machines and reports without having access to other machines they don't own."

Carnegie Mellon has a history of valuing collaborative teamwork, and for that reason the degree of partnership formed with Rapid7 has made an impression.

"We had the option of building our own vulnerability scanning system, but the opportunity to partner is much more important and mutually beneficial," stated Blair. "Rapid7's ability to listen and work with us was a differentiator. The company brings not only an understanding of our organization and a commitment to network security, but with the integration of NeXpose with our environment, we will now possess a world-class vulnerability detection system."

Based in Pittsburgh with locations in Silicon Valley, CA and around the world, Carnegie Mellon and its Software Engineering Institute are the home of the CERT® Coordination Center, which researches and reports on security vulnerabilities on the Internet and in networked systems. CERT's 2006 presentation, "Vulnerability Discovery: Bridging the Gap Between Analysis and Engineering," advocates a proactive rather than a reactive approach to vulnerability detection to achieve confidence in networked systems.

About Carnegie Mellon University

Carnegie Mellon is a private research university with a distinctive mix of programs in engineering, computer science, robotics, business, public policy, fine arts and the humanities. More than 10,000 undergraduate and graduate students receive an education characterized by its focus on creating and implementing solutions for real problems, interdisciplinary collaboration, and innovation. A small student-to-faculty ratio provides an opportunity for close interaction between students and professors. While technology is pervasive on its 144-acre campus, Carnegie Mellon is also distinctive among leading research universities for the world-renowned programs in its College of Fine Arts. For more, see www.cmu.edu.

About NeXpose

Rapid7 NeXpose is the broadest and deepest vulnerability management system on the market, providing comprehensive, high performance coverage of networks, databases, operating systems, and Web applications. Only NeXpose provides browser-based Web application vulnerability scanning of Web 2.0 applications and secures the complete Web application - from browser to server. NeXpose detects more vulnerabilities than traditional Web scanners by using Web Application Pass-Through Scanning, a unique capability for exploring how one vulnerability can lead to another.

NeXpose delivers extensive reports assessing risks and proposing streamlined remediation plans to optimize security and compliance with governmental regulations and corporate security policies. Rapid7 is an Approved Scanning Vendor (ASV) by the Payment Card Industry (PCI) Security Standards Council, certifying NeXpose to support retail operations in achieving PCI compliance.

About Rapid7

Rapid7 is a leader in vulnerability management and compliance, delivering a single unified solution across an organization’s entire infrastructure.  Rapid7 NeXpose helps security professionals to reduce their attack surface by providing actionable insights into the real threats from vulnerabilities across their entire IT infrastructure.  Rapid7 NeXpose is the only solution that provides in-depth coverage of vital Web and database systems in addition to networked devices, servers, and operating systems. The NeXpose A.I. and Reporting Engines synthesize large quantities of raw data to provide direct insight into the vulnerabilities that represent the most risk to the business.  From this insight the product delivers a set of prioritized remediation recommendations that help security professionals get protection fast. Organizations, including Black & Decker, Trader Joe’s, Florida State University, the New York Times, and the City of Philadelphia, continually rely on Rapid7 products and services to mitigate risk and remain compliant.