FusionVM from Critical Watch is an award winning, patented solution that automates Vulnerability Management and Security Configuration Policy Compliance so that compliance is sustained and critical systems are secured. FusionVM not only delivers patented vulnerability assessment technology spanning network devices, Web applications, and databases but also automates back-end process steps needed to scale and execute security, risk and compliance management across multiple internal groups and audiences with varying levels of access.
Offered as a service or a product, you can choose the option that best meets your needs. The FusionVM suite provides solutions that fit enterprises both large or small, consulting firms or audit teams and managed service providers looking for an “in-the-box” service delivery architecture to place in their SOC.
FusionVM SaaS: A remotely hosted service delivered via a secure portal for those needing rapid deployment and low overhead.
FusionVM Enterprise: Security, Risk and Compliance Management appliance(s) that can be installed on your premises.
FusionVM MSSP: A Security, Risk and Compliance Management Service “in-a-box” for those needing multi-tenant capability to manage multiple distinct entities within a common portal but with separate reporting. FusionVM MSSP enables an on-site service platform to be placed in your SOC.
FusionVM PCI: A turnkey, portal-driven service fulfilling the quarterly scan requirement for merchants and service providers needing to comply with PCI DSS v.1.1.
FusionVM Consultant: A portable laptop version of the FusionVM scanning appliance for consultants or auditors needing to run assessments at client locations.
Discover and Profile Critical Assets |
Automatically identifies and profiles critical assets including devices, ports, operating systems, services, applications, versions and vendors. |
Pinpoint Risks on Critical Assets |
Completely agentless, both zero-privileged and configurable credentialed scanning enable safe, scalable and thorough testing of enterprise networks on a repeatable basis. In addition to traditional broad based network assessment coverage, FusionVM also addresses web application and database vulnerabilities in a single platform. |
Passive Threat Alerts |
Delivers same day alert feeds on newly emerging vulnerabilities as applicable. These alerts are driven passively off of the current asset baseline, and occur automatically without requiring an active scan to provide proactive risk management over an above scheduled scanning. |
Remediation Management |
Provides a workflow platform for assigning, tracking and validating remediation tasks across large enterprises with multiple operational teams participating in the process. |
Risk and Compliance Metrics |
FusionVM delivers a powerful and unique reporting capability. Leveraging the CEM, it delivers new dimensions of security visibility based on an organization’s own unique business environment and risk management requirements. Individual asset owners receive report information personalized for them based on their role and the assets for which they are responsible, while management and security teams can rollup aggregate information and also drill down from any vantage point on the CEM tree. |
Security Configuration Policy Compliance |
With FusionVM's agentless configuration policy compliance scanning and vulnerability management policies, enterprises can validate and enforce internal security policies as well as regulatory policy compliance on asset groups relating to Sarbanes-Oxley, HIPAA, GLBA, PCI, FISMA, and others. |
Research |
The research module provides a source for aggregated daily security risk information as well as visibility to the FusionVM vulnerability library. |
Exceptions Management |
FusionVM enables the ability to embed your unique business risk requirements for optimizing mitigation efforts and report effectiveness. |
SaaS: Software-as-a-Service
No hardware or software is required for external scanning. For internal scanning, a VM Server (includes scanning engine) can be deployed to the internal network and remotely managed from the Critical Watch Secure Center.
All-In-One Manager: Includes FusionVM Management Software, Vulnerability, Asset, and Reporting databases, Policy Library and Scanning Engine. Delivers end-to-end Security, Risk and Compliance Management in a single appliance.
VM Server: Includes scanning engine and can be managed by the All-In-One Manager to add distributed scanning capability.