Related Posts
Does Deloitte provide cab facility?
Who has the Descovy business?
Additional Posts in Cyber Security Bowl
Any tips or tricks for CSX certification?
New to Fishbowl?
Download the Fishbowl app to
unlock all discussions on Fishbowl.
unlock all discussions on Fishbowl.



Superb, we have rapid7 and would be looking to move to tenable one. We use Nist CSF and winging it method today lol. We have a risk register tho
Are you already following any specific risk management frameworks?
Also what are you using for vulnerability management? And ballpark annual spend for that / general info security?
We’re not using any crq right now (can’t even get people to identify a critical system) but:
Your existing VM platform may already have this built in or as an add on. You’ll also want a tool that maps to or integrates the RMF you’re using g, at least to get good value. But also they’re not cheap.
We’ve got tenable and I’d looked at tenable one for this. Rapid7 may have it buried in their overall tooling but I can’t find anything by name. Our siem and xdr tooling (elastic, Microsoft ) also has some of this functionality
We’re using top down CRQ tools to quantify value at risk and some risk impact scenarios. The models are based on peer firmographics and historical cyber loss data mostly from insurance. Gives us some good value for board reporting and discussions with cyber insurance providers