Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

10/8/2019
11:45 AM
Dark Reading
Dark Reading
Products and Releases
50%
50%

Xacta.io Leverages Security Data at Scale to Actively Manage Cyber-Risk

Telos Corporation delivers next-generation cyber-risk management platform for complex on-premises, hybrid, and cloud-based environments.

ASHBURN, Va., Oct. 08, 2019 (GLOBE NEWSWIRE) -- Telos ® Corporation, a leading provider of cyber, cloud and enterprise security solutions for the world’s most security-conscious organizations, today announced the general availability of Xacta.io™, the next generation cyber risk management platform.

Designed to address the complexity of managing cyber risk and compliance in modern computing environments – from cloud, multi-cloud and on-premises assets – Xacta.io empowers users to maximize the value of security risk and compliance data to derive intelligence required to actively manage cyber risk. Information gathered by Xacta.io can assist in making decisions pertaining to authorization, remediation prioritization, process and status reporting, resource investments, risk avoidance, and more.

“Security risk and compliance remains a hurdle for cloud adoption,” said John B. Wood, chairman and CEO of Telos. “This task is even more difficult for multi-cloud and hybrid environments.  Automation is critical for gathering, organizing, and operationalizing the data needed to continuously manage cyber risk for regulated and non-regulated industries alike. Xacta.io is specifically designed to address these complex use-cases, which will ultimately help accelerate cloud adoption.”  

Built on a microservices-based, environment-agnostic technology stack, Xacta.io is able to ingest and process data on a massive scale.  Third-party security data sources compatible with Xacta.io include security and vulnerability scanners, endpoint agents, and application programming interfaces (APIs) from cloud service providers.

Complementing the ability to ingest enormous amounts of security data is an advanced visualization dashboard that provides compliance scorecards, regulatory reporting, ad-hoc reporting, analytics and decision support.  Xacta 360 users will also benefit from these enhanced visualization and dashboard capabilities.

"Though compliance management remains a core mission, Xacta.io isn’t just for automation of authorization activities,” said Richard Tracy, CSO of Telos. “Xacta.io will offer much more advanced capabilities, leveraging vast amounts of security and compliance data at scale to enable informed decision-making around cyber risk. Ultimately, Xacta.io will become the hub for all things Xacta, as a flexible platform supporting a broad range of modular services and applications that meet our customers’ cybersecurity requirements.”

Xacta.io will soon include integration with the AWS and Azure clouds, with additional services added over time. For more information, please visit: www.telos.com/xacta.

About Telos Corporation
Telos Corporation empowers and protects the world’s most security-conscious organizations with solutions for continuous security assurance of individuals, systems, and information. Telos’ offerings include cybersecurity solutions for IT risk management and information security; cloud security solutions to protect cloud-based assets and enable continuous compliance with industry and government security standards; and enterprise security solutions to ensure that personnel can work and collaborate securely and productively. The company serves military, intelligence and civilian agencies of the federal government, allied nations and commercial organizations around the world.  The company is a recipient of the prestigious James S. Cogswell Outstanding Industrial Security Achievement Award from the Defense Security Service (DSS), awarded to less than .03% of eligible organizations. For more information, visit www.telos.com and follow the company on Twitter @TelosNews

Contact:
Allison Phillipp
Telos Corporation
Email: [email protected]  
Phone: 703.724.3642

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 5/22/2020
How an Industry Consortium Can Reinvent Security Solution Testing
Henry Harrison, Co-founder & Chief Technology Officer, Garrison,  5/21/2020
Is Zero Trust the Best Answer to the COVID-19 Lockdown?
Dan Blum, Cybersecurity & Risk Management Strategist,  5/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13458
PUBLISHED: 2020-05-25
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
CVE-2020-13459
PUBLISHED: 2020-05-25
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
CVE-2020-13442
PUBLISHED: 2020-05-25
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
CVE-2020-5537
PUBLISHED: 2020-05-25
Cybozu Desktop for Windows 2.0.23 to 2.2.40 allows remote code execution via unspecified vectors.
CVE-2020-13438
PUBLISHED: 2020-05-24
ffjpeg through 2020-02-24 has an invalid read in jfif_encode in jfif.c.