June 22nd, 2010

I've just read today about the natural integration between Qualys and Imperva, two of the vendors that I work with and I highly appreciate.
Timing is great for Imperva because the proactive services offered by Imperva's Discovery and Assessment Server had no real correspondence in web application world and that's why QualysGuard Web Application vulnerability scanner fits like a glove.
To put it in their words,
The integration of QualysGuard Web Application vulnerability scanner and Imperva’s SecureSphere Web Application Firewall (WAF) significantly reduces the need for disruptive patching of vulnerabilities. Organizations can use QualysGuard to scan their Web applications for vulnerabilities and then import the scan results into SecureSphere WAF. SecureSphere WAF provides instant mitigation for imported vulnerabilities using a “virtual patch,” which limits the window of exposure and reduces the security risk on the business.
On the other hand QualysGuard gets a couple of benefits suchs as :
- World wide recognition for it's new Web Application Scanner which is the latest addition to the QualysGuard scanner family .
- Sales support from Imperva's Channel . I know I will present this combination (Qualys and Imperva) to all my Imperva customers, whenever possible because I believe I's an effective web application security solution
Here is a short whitepaper (pdf) on this topic.
June 16th, 2010
It brings me great pride and joy to announce the public release of Pro CERT ( Provision Computer Emergency Response Team), the first commercial CERT structure in Romania.
Quoting from Pro CERT RFC2550 charter :
Pro CERT is a project initiated and sponsored by Provision Software Division SRL, the largest privately owned Romanian IT security company.
"Pro CERT offers assistance and coordination in early detection and handling of computer and network security incidents for all it’s constituents. Pro CERT primary constituency include all networks and systems belonging to Provision Software Division SRL and it’s customers.A secondary goal in terms of constituency is represented by the Romanian TLD : .ro for which Pro CERT aims to be a certified point of contact for incidents targeting or initiated from Romania.
Pro CERT is dedicated to preventing security incidents by offering direct proactive measures and security quality management services. Pro CERT operates under the authority of Provision’s Managed Security Services business division, which manages the operational authority between Pro CERT and each of its constituents trough individual SLAs.
Pro CERT core activities imply close cooperation with all large ISP's abuse teams from Romania and abroad, direct contact and data exchange in order to prevent and recover from security incidents that affect Pro CERT’s constituents.
Pro CERT operates under the restrictions imposed by Romanian law. This involves careful handling of personal data as required by Romanian Data Protection laws, but it is also possible that – according to Romanian law – Pro CERT may be forced to disclose information due to a Court's order. "
Just like the Oscar winners, I would like to thank my team without whom none of this could have happened
. It's a young project but we are very ambitious and we have set our goals high ! Please contact me directly,leave comments or register on www.pro-cert.ro if you would like to cooperate with Pro CERT.
Please find below the opening presentation I gave on Provision Security Days conference about Pro CERT.
Do you like my presentation ?
Thanks !