Signed in as:
filler@godaddy.com
Signed in as:
filler@godaddy.com
You or your clients invested in Skybox security. We assess whether the expected return on investment is achieved.
This area of the assessment looks at how the Skybox analysis results, reports and metrics are used in your organisation to drive the company’s cyber security and other processes.
Our technical assessment service looks at how the operating system and Skybox application are installed, managed, secured and backed up.
We check the operating systems of Skybox servers and collectors are managed correctly and are up to date. We will also check the security access for the IT staff managing the Skybox servers.
We check the process, technology and people controls related to the monitoring of the availability of your Skybox application. This includes Disk space, CPU usage, memory usage, network capacity and database IOPS for both Skybox servers and collectors, and integration with other key systems (such as DNS, email, Internet access). We will advise the customer of any sizing issues and optimisations.If Skybox is configured in High-availability state (HA), we also check that its health and recovery process is related to any high-availability issues.
We will check the number of objects in the model, compared them to purchased licenses, and produce an analysis of optimal licenses needed for the current use cases.
We assess your processes to keep Skybox applications up to date – both on server and client sides. This includes an assessment of how the company monitors for available Skybox application updates and initiates an update process.
The key areas we check:
We assess your ability to restore Skybox service within acceptable RTO with agreed RPO and accompanied documentation.
This part of the assessment looks at data quality processes in Skybox, model validation, collection tasks and processes to ensure timely resolution of any application and data issues. Where a CMDB is in place, we also assess reconciliation processes between the CMDB and Skybox database.
The key success criteria in any Skybox deployment where a network model is licensed (NA and/or VM modules) is a fully network validated Skybox model. We will assess the current network validation status as well as processes pertaining to keeping the model validated. Some aspects we look at:
A visual representation of the Skybox model using network maps presents an advantageous feature. We will assess the map maintenance process in Skybox.
The key areas we assess are:
For Skybox to deliver the business value, it needs assets to be enriched with CMDB metadata. As part of this assessment, we review frequency, scope of imports and follow up correlation of CMDB metadata to Skybox.
This includes technology and process review, especially to ensure that the CMDB data is imported correctly and delivers business value.
The quality of the network model is directly dependent on collections of configurations from all L3 network devices. We will assess your processes to ensure that network devices, that build network model, are properly on/off-boarded. This is especially important for devices being on-boarded, i.e. new L3 devices taken from provision state to production state in CMDB.
Grouping of assets to business asset groups allows for multiple viewpoints on the vulnerability data, aiding stakeholder reporting. We will assess your Business Asset Grouping structure and associated processes to keep the structure up to date and relevant.
Where FA and NA licenses have been purchased, we will assess policies and zones, as well as associated processes to keep these up to date.
The policies are of type:
As part of this assessment, we will review processes to ensure tasks are maintained and monitored correctly, as well as current setup of tasks and tasks sequences. The process review will cover:
Usually, Skybox is setup and configured as part of the project phase, and this includes the right access roles and users. Our review will ensure that organisational changes are correctly reflected in the Skybox user access control design.
This area of the assessment looks at how the Skybox analysis results, reports and metrics are used in your organisation to drive the company’s cyber security and other processes.
The key areas included in our assessment are:
The planned value of the investment in Skybox is only going to be delivered if the people using it, and its results, are engaged and trained.
In our 360 Assessment, we will interview key stakeholders to obtain their feedback and assess their level of knowledge of the Skybox software, its reports and any reliance on the Skybox analysis.
We have collected the frequently asked questions our customer asked us before the assessments. Cannot find your question? Ask us and our friendly team will respond promptly.
Preferably, we use full admin access to both Skybox application and underlying servers. If this is not possible, we can work in screen sharing session with your IT team to run scripts we have developed to obtain necessary information.
With your permission, our script copies the diagnostic data collected, and the Skybox model to our secure storage, to be analysed by our experts. If this is not possible, we ask you to provide a secure server inside your network.
Typically, with full access, the amount of interactions is limited to 4-6 hours total with the IT team managing Skybox, and up to 10 hours total interview time with stakeholders using the Skybox application and data.
The length of time depends on the complexity of the model and size of the Skybox installation, e.g. number of servers and collectors. The time to deliver the report can be as quick as 2 weeks and as long as 2 months, especially if stakeholders are not available for interviews or our team not having direct access to the Skybox application.
For small Skybox installations - 1 Skybox server and 1 collector with up to 50 network devices in the model, the cost is fixed to GBP 5000. For larger installations the cost is GBP 10000. However, if the customer later orders our managed services, the cost of the assessment is deducted from the service on-boarding fee.