How OSID is updated in Enterprise Scanner

Enterprise Scanner uses OSID information or reassesses the OSID during an assessment scan, and it explains when SiteProtector updates OSID that it has for an asset.

Conditions for reassessing OSID

The following conditions must be met for Enterprise Scanner to use the OSID information from SiteProtector:

vThe operating system name, the certainty of the OSID, and a timestamp must all be available.

vThe OSID information is user supplied, or the age of the of the information is no more than the age that is defined in the Assessment Policy.

vThe OSID matches a valid operating system.

Exception

The concept of certainty was introduced with SiteProtector SP6, so that it is undefined for the assets already in SiteProtector. Because OSID is undefined, SiteProtector accepts the first reported OSID for each asset, regardless of its source.

Rules for updating OSID

SiteProtector updates OSID for existing assets based on the following rules:

Table 24. Rules for updating OSID

Certainty of Old Data

Certainty of New Data

Updated?

 

 

 

Certain

Certain

Yes

 

 

 

Certain

Uncertain

No, unless both sources of

 

 

OSID are Enterprise Scanner

 

 

 

Uncertain

Certain

Yes

 

 

 

Uncertain

Uncertain

Yes, unless the old OSID is

 

 

from Enterprise Scanner and

 

 

the new OSID is from

 

 

Internet Scanner

 

 

 

About user-supplied OSIDs

SiteProtector updates user-supplied OSIDs only in the following cases:

vA local Desktop agent reports an OSID to SiteProtector for that asset.

vA scan from Enterprise Scanner with authenticated access reports an OSID for that asset.

Important: If you enter user-supplied OSIDs and do not meet either of the preceding conditions, you are responsible for maintaining any changes to the OSID.

Chapter 8. Interpreting scan results in SiteProtector 105

Page 113
Image 113
IBM Partner Pavilion 2.3 manual How Osid is updated in Enterprise Scanner, Conditions for reassessing Osid, Exception