ANA (Automation and Standardization of Audits) is the solution developed by the CCN-CERT for the centralized and continuous management of vulnerabilities. This tool aims to reduce security management time through efficient vulnerability detection and alert notification, as well as by providing recommendations for timely remediation.
Among the most important features of this tool are:
- Evolution: it uses the most up-to-date technologies
- Fluidity: it allows multiple functions to be combined in it
- Versatility: it favours multiplatform visualization.
What exactly does ANA do?
- It accesses localized problems in real time, reproduces them and tracks their evolution over time.
- It dynamically generates reports of the actual status of the entity by department, server, application or any defined asset
- It organizes information by providing multiple views/control panel to users
- It centralizes and standardizes all security inspections performed
- Early warning through direct and detailed interaction of problems encountered allowing timely notification without undue delay
Furthermore, within the tasks of prevention, ANA relates all the work of the auditors, who load the vulnerabilities, to the work of the administrators. In this way, the Incident Response Team can add any type of audit of any company, keeping all the knowledge within the agency.
El Centro Criptológico Nacional ha desarrollado la herramienta ANA para la gestión y evolución de los niveles de exposición a los que se encuentra sometida una organización al objeto de poner a disposición de sus entidades usuarias elementos de apoyo para el tratamiento de los hallazgos determinados en su diagnostico del estado de seguridad, que, junto al resto de soluciones del ecosistema de herramientas del CCN-CERT contribuyen a la Gestión Continua de la Ciberseguridad.
Contact:






