NetRise introduces VEX Support for enhanced XIoT security

May 8, 2024

Posted by: Magda Dabrowska

Cyber security concept

Image by Freepik

NetRise has announced support for creating Vulnerability Exploitability eXchange (VEX) documents to help organisations track and convey risk associated with the software they are manufacturing or consuming.

VEX documents are commonly found alongside Software Bill of Materials (SBOMs) and allow software, firmware and device developers to convey if an asset is or is not affected by a particular vulnerability. The developer can also provide recommendations and workarounds in a standardised, machine-readable format. Asset owners and operators then consume VEX information to help influence vulnerability and risk management processes.

Users of the NetRise Platform now have a single solution that allows them to identify software components in their software and XIoT assets, automatically discover the vulnerabilities that affect them, triage the vulnerabilities and generate SBOM and VEX documents that exceed the minimum requirements defined by the National Telecommunications and Information Administration.

Understanding the SBOM and VEX specifications that meet the minimum standards is daunting and time-consuming for many organisations. By using the NetRise Platform, organisations can be confident they are generating documents that adhere to the specifications without needing to be intimately familiar with them, which is especially important for organisations with limited development or security resources as well as those who are or may become required to comply with Executive Order 14028.

Key new features and capabilities include:

“Our latest updates address the critical challenges organisations face when mitigating risks in firmware and software components to secure their connected devices,” said Thomas Pace, the CEO of NetRise. “We are a customer-first organisation, which means that we continuously anticipate and respond to our customers’ needs. One of our customers’ most requested features has been access to vulnerability remediations and VEX statuses. I’m excited that we are now able to provide this, and look forward to seeing how they use it and how VEX continues to evolve. With our new offerings, we are empowering organisations with advanced vulnerability insights, simplified workflows and a more complete, secure SBOM.”

Comment on this article below or via X: @IoTGN