<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">
<channel rdf:about="http://www.nessus.org/">
<title>Tenable Audit Updates</title>
<link>http://www.nessus.org/</link>
<description>Configuration Auditing Updates for Nessus</description>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=153" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=148" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=147" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=136" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=135" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=125" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=124" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=123" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=122" />
<rdf:li rdf:resource="http://www.tenablesecurity.com/news/rssview.php?id=119" />
</rdf:Seq>
</items>
</channel>
<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus News</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=153">
<title>AIX Best Practice and PCI Audits Available</title>
<description><![CDATA[Tenable's Research group has published two new configuration audit policies for the AIX platform. <br />
<br />
The first is titled 'AIX Best Practices' and is based loosely on the Center for Internet Security CIS_AIX_Benchmark_v1.0.1 best practices guide. This guide referenced an older version of AIX. The new AIX audit policy from Tenable is applicable for modern AIX deployments and performs comparable CIS style audits. <br />
<br />
The second AIX policy is for PCI configuration auditing. It is aptly named 'PCI AIX'. Although Tenable recommends Center for Internet Security policies for more comprehensive auditing, the PCI audit polices focus on the minimal settings required for PCI. <br />
<br />
Both of these AIX audit policies are available on the Tenable Support Portal by logging in, clicking on Downloads, then by clicking on Download Configuration Audit Polices. <br />
<br />
Each of these new audit policies also makes use of some new APIs available for the UNIX compliance checks. If you are testing or trying these plugins, but sure to update your plugins prior to running these. The new APIs include support for the "info" keyword which allows more information to be generated in the Nessus report about the specific item being audited. <br />
<br><a href="http://plugins-customers.nessus.org/">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=153</link>
<dc:date>2008-07-04T12:44:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=148">
<title>Solaris 10 CIS Audit Update </title>
<description><![CDATA[Tenable Network Security has received certification from the Center for Internet Security to perform best practice configuration audits of Solaris 10 deployments. <br />
<br />
The certified audit policy is now available on the Support Portal. To obtain the policy, click on 'Downloads', then click on 'Download CIS Compliance Audit Files' and then look for the 'Solaris 10 v4.0' audit policy. <br />
<br />
To use this policy with Nessus, save the audit file to the system running the Nessus Client and create a scan policy that makes use of this new audit for Solaris 10. <br />
<br />
To use this policy with Security Center 3.4, as an administrator, upload the new audit policy and then create one or more vulnerabilities policies which make use of the Solaris 10 audit.  <br><a href="https://plugins-customers.nessus.org/support-center/index.php?x=&mod_id=104">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=148</link>
<dc:date>2008-07-04T14:44:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=147">
<title>Windows Nessus Policy Creator 1.0.5 Released</title>
<description><![CDATA[Tenable Network Security has released version 1.0.5 of the Windows Nessus Policy Creator. This releases includes performance enhancements, Windows 2000 compatibility and consistent behavior when connected to a domain or while detached.<br />
<br />
To obtain the tool, log into the Customer Portal at the below link, choose 'Downloads', then choose 'Download Compliance Checks Tools' and then WNPC-1.0.5.exe download.  <br />
<br />
The WNPC allows Windows users and administrators to create a Nessus .audit file from the current running settings of a Windows system. <br />
<br />
 <br><a href="https://plugins-customers.nessus.org/support-center/index.php?x=">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=147</link>
<dc:date>2008-07-04T13:44:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=136">
<title>Version 2.0.3 of i2a Tool</title>
<description><![CDATA[Version 2.0.3 of the i2a tool is now available. This release adds support for reversible encryption and also fixes a bug which incorrectly interprets file, service and registry audit settings as permission settings. <br />
<br />
The updated tool is available on the Tenable Customer Portal by clicking on the "Download" button and then the "Download Compliance Checks Tools" button.<br><a href="http://plugins-customers.nessus.org/">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=136</link>
<dc:date>2008-07-04T22:44:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=135">
<title>Security Center Receives FDCC Certification</title>
<description><![CDATA[Tenable recently concluded certification testing for the Federal Desktop Core Configuration and SCAP certifications. <br />
<br />
Security Center customers that wish to perform FDCC certified audits and reporting to NIST, can email support@tenablesecuritiy.com to request a copy of the new xTool. The xTool allows conversion of XCCDF SCAP content to Nessus .audit policies which can be loaded into the Security Center. Results from the Security Center audit can also also be then loaded back into the xTool to produce an FDCC XML report for submission to NIST. <br />
<br />
The Tenable blog entry below provides more detail on how this process works. An extensive <a href="http://cgi.tenablesecurity.com/XTool_SCAP.pdf">document </a> which has step-by-step guides to performing FDCC auditing with the Security Center is also available.<br />
<br><a href="http://blog.tenablesecurity.com/2008/04/tenable-receive.html">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=135</link>
<dc:date>2008-07-04T21:44:00-04:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=125">
<title>Windows Nessus Policy Creator 1.0.4 Released</title>
<description><![CDATA[Version 1.0.4 of the Windows Nessus Policy Creator has been released and is now available on the <a href="https://plugins-customers.nessus.org/support-center/index.php?x=&mod_id=1">Customer Support Portal</a>. <br />
<br />
Version 1.0.4 now supports <a href="http://blog.tenablesecurity.com/2007/12/version-2-of-wi.html">version 2</a> of the Windows compliance checks. <br />
<br />
To obtain the updated tool, log into the support portal, click on the 'Downloads' button and then the 'Download Compliance Check Tools' button.<br />
<br />
The link below points to an original Tenable Blog entry about Windows Nessus Policy Creator usage. <br><a href="http://blog.tenablesecurity.com/2006/09/creating_gold_b.html">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=125</link>
<dc:date>2008-07-04T12:44:00-05:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=124">
<title>CIS Certified Windows 2000 Audits</title>
<description><![CDATA[Tenable has received certification to perform audits of Windows 2000 servers against the following <a href="http://www.cisecurity.org">Center for Internet Security</a> benchmarks: <br />
<ul><br />
<li>Windows 2000 Server Level 2 Benchmark v2.2.1</li><br />
<li>Windows 2000 Level 1 Benchmark v1.2.2</li><br />
</ul><br />
These policies are available to Direct Feed and Security Center customers by logging into the Tenable Support Portal, clicking on the 'Downloads' button, and then the 'Download CIS Compliance and Audit Files'. <br />
<br><a href="http://www.cisecurity.org/tenable_cert.html">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=124</link>
<dc:date>2008-07-04T21:44:00-05:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=123">
<title>Updated CIS Windows 2003 Audits</title>
<description><![CDATA[Recently, the <a href="http://www.cisecurity.org">Center for Internet Security</a> (CIS) released the Windows 2003 v2.0 benchmark which replaced the previous v1.2 benchmark. <br />
<br />
Tenable has received CIS certification to perform audits of Windows 2003 servers against the v2.0 benchmark with the Security Center and Nessus. <br />
<br />
The updated Windows 2003 audit polices are now available at the <a href="https://plugins-customers.nessus.org/support-center/index.php?x=">Customer Support Portal</a>. Once logged in, select the 'Downloads' button, then the 'Download CIS Compliance and Audit Files'. <br />
<br />
These policies should be used in any future Nessus Direct Feed scans or should be added to the Security Center and made part of existing or new vulnerability scan policies.<br />
<br />
<br><a href="http://www.cisecurity.org/tenable_cert.html">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=123</link>
<dc:date>2008-07-04T20:44:00-05:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=122">
<title>Unix Compliance Audit Update</title>
<description><![CDATA[Version 1.4.5 of the unix_compliance.nbin plugin has been released to Direct Feed and Security Center customers. This update enhances the accuracy and analysis of text based configuration files. <br />
<br />
Along with this upgrade, all UNIX based CIS audit polices have been modified to account for this new functionality. If you are currently using any of the following polices, please log into the Customer Support Portal and upgrade to the most recent policy:<br />
<br />
<ul><br />
<li>CIS_Redhat_ES4_105.audit</li><br />
<li>CIS_SuSE_9_v1.audit</li><br />
<li>CIS_Solaris_9_v13.audit</li><br />
</ul><br />
<br />
These updated policies should be downloaded and used in your Nessus Direct Feed scans or saved to your Security Center in the /opt/sc3/admin/nasl directory. <br><a href="https://plugins-customers.nessus.org/support-center/index.php?x=">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=122</link>
<dc:date>2008-07-04T20:44:00-05:00</dc:date>
</item>
<item rdf:about="http://www.tenablesecurity.com/news/rssview.php?id=119">
<title>i2a Version 2.0.2 Available</title>
<description><![CDATA[Version 2.0.2 of the i2a tool which converts .inf policy files to Nessus .audit files is now available. Version 2.0.2 supports the password complexity testing format in the most recent release of the Windows Compliance Checks. <br />
<br />
If you are a user of the i2a tool, you should upgrade. <br />
<br />
The tool is available for download from the Tenable Support Portal by choosing 'Downloads', then 'Download Compliance Check Tools' and then you will see the i2a download link alongside the WNPC and c2a tools. <br><a href="https://plugins-customers.nessus.org/support-center/index.php?x=&mod_id=106">More info</a>]]></description>
<link>http://www.tenablesecurity.com/news/rssview.php?id=119</link>
<dc:date>2008-07-04T15:44:00-05:00</dc:date>
</item>
</rdf:RDF>
