https://www.facebook.com/itzonepakistan
×

HOW TO SHOP

1 Login or create new account.
2 Review your order.
3 Payment & FREE shipment

If you still have problems, please let us know, by sending an email to support@website.com . Thank you!

SHOWROOM HOURS

Mon-Fri 9:00AM - 6:00AM
Sat - 9:00AM-5:00PM
Sundays by appointment only!

FORGOT YOUR DETAILS?

Thursday, 19 January 2023 / Published in Uncategorized

Sign up for MarketBeat All Access to gain access to MarketBeat’s full suite of research tools:
Trevian Wealth Management LLC lifted its stake in shares of Microsoft Co. (NASDAQ:MSFT – Get Rating) by 10.7% in the third quarter, according to its most recent Form 13F filing with the Securities & Exchange Commission. The institutional investor owned 7,630 shares of the software giant’s stock after purchasing an additional 738 shares during the period. Microsoft comprises 2.0% of Trevian Wealth Management LLC’s investment portfolio, making the stock its 8th biggest position. Trevian Wealth Management LLC’s holdings in Microsoft were worth $1,777,000 as of its most recent filing with the Securities & Exchange Commission.
A number of other institutional investors and hedge funds have also modified their holdings of the stock. Monumental Financial Group Inc. acquired a new position in Microsoft during the first quarter worth about $28,000. Newfound Research LLC boosted its position in Microsoft by 25.4% during the second quarter. Newfound Research LLC now owns 296 shares of the software giant’s stock worth $76,000 after acquiring an additional 60 shares during the last quarter. Grayhawk Investment Strategies Inc. acquired a new position in Microsoft during the second quarter worth about $104,000. Darrow Company Inc. acquired a new position in Microsoft during the second quarter worth about $82,000. Finally, Morgan Dempsey Capital Management LLC acquired a new position in Microsoft during the third quarter worth about $82,000. Hedge funds and other institutional investors own 69.15% of the company’s stock.

Insider Activity

In other news, EVP Judson Althoff sold 24,144 shares of the company’s stock in a transaction on Thursday, December 1st. The shares were sold at an average price of $254.27, for a total value of $6,139,094.88. Following the completion of the transaction, the executive vice president now owns 150,047 shares in the company, valued at approximately $38,152,450.69. The sale was disclosed in a document filed with the SEC, which is available at this link. Company insiders own 0.03% of the company’s stock.

Microsoft Trading Down 1.9 %

Shares of NASDAQ:MSFT opened at $235.81 on Thursday. Microsoft Co. has a 52 week low of $213.43 and a 52 week high of $315.95. The company’s 50 day moving average is $241.83 and its two-hundred day moving average is $250.46. The company has a current ratio of 1.84, a quick ratio of 1.79 and a debt-to-equity ratio of 0.26. The company has a market cap of $1.76 trillion, a PE ratio of 25.41, a P/E/G ratio of 2.35 and a beta of 0.94.
Microsoft (NASDAQ:MSFT – Get Rating) last announced its quarterly earnings data on Tuesday, October 25th. The software giant reported $2.35 EPS for the quarter, beating analysts’ consensus estimates of $2.29 by $0.06. Microsoft had a net margin of 34.37% and a return on equity of 42.10%. The company had revenue of $50.12 billion for the quarter, compared to the consensus estimate of $49.70 billion. During the same period in the prior year, the firm posted $2.27 EPS. The company’s quarterly revenue was up 10.6% compared to the same quarter last year. Equities analysts predict that Microsoft Co. will post 9.52 earnings per share for the current fiscal year.

Microsoft Announces Dividend

The business also recently announced a quarterly dividend, which will be paid on Thursday, March 9th. Stockholders of record on Wednesday, February 15th will be issued a $0.68 dividend. This represents a $2.72 annualized dividend and a dividend yield of 1.15%. The ex-dividend date of this dividend is Wednesday, February 15th. Microsoft’s payout ratio is 29.31%.

Wall Street Analyst Weigh In

Several research firms have weighed in on MSFT. Macquarie began coverage on shares of Microsoft in a report on Wednesday, November 2nd. They issued a “neutral” rating and a $234.00 target price on the stock. UBS Group set a $250.00 target price on shares of Microsoft in a report on Thursday, January 12th. JPMorgan Chase & Co. decreased their target price on shares of Microsoft from $305.00 to $275.00 in a report on Wednesday, October 26th. Evercore ISI decreased their target price on shares of Microsoft from $330.00 to $300.00 and set an “outperform” rating on the stock in a report on Wednesday, October 26th. Finally, Rosenblatt Securities decreased their target price on shares of Microsoft from $300.00 to $285.00 and set a “buy” rating on the stock in a report on Thursday, October 27th. One research analyst has rated the stock with a sell rating, three have given a hold rating and thirty have given a buy rating to the company’s stock. According to data from MarketBeat.com, the stock currently has an average rating of “Moderate Buy” and a consensus target price of $289.15.

About Microsoft

(Get Rating)
Microsoft Corporation develops, licenses, and supports software, services, devices, and solutions worldwide. The company operates in three segments: Productivity and Business Processes, Intelligent Cloud, and More Personal Computing. The Productivity and Business Processes segment offers Office, Exchange, SharePoint, Microsoft Teams, Office 365 Security and Compliance, Microsoft Viva, and Skype for Business; Skype, Outlook.com, OneDrive, and LinkedIn; and Dynamics 365, a set of cloud-based and on-premises business solutions for organizations and enterprise divisions.

Recommended Stories

Institutional Ownership by Quarter for Microsoft (NASDAQ:MSFT)
This instant news alert was generated by narrative science technology and financial data from MarketBeat in order to provide readers with the fastest and most accurate reporting. This story was reviewed by MarketBeat’s editorial team prior to publication. Please send any questions or comments about this story to contact@marketbeat.com.
Before you consider Microsoft, you’ll want to hear this.
MarketBeat keeps track of Wall Street’s top-rated and best performing research analysts and the stocks they recommend to their clients on a daily basis. MarketBeat has identified the five stocks that top analysts are quietly whispering to their clients to buy now before the broader market catches on… and Microsoft wasn’t on the list.
While Microsoft currently has a “Moderate Buy” rating among analysts, top-rated analysts believe these five stocks are better buys.
View The Five Stocks Here
Which stocks are likely to thrive in today’s challenging market? Click the link below and we’ll send you MarketBeat’s list of ten stocks that will drive in any economic environment.
Enter your email address below and we’ll send you MarketBeat’s guide to investing in electric vehicle technologies (EV) and which EV stocks show the most promise.
Sign up for MarketBeat All Access to gain access to MarketBeat’s full suite of research tools:
View the latest news, buy/sell ratings, SEC filings and insider transactions for your stocks. Compare your portfolio performance to leading indices and get personalized stock ideas based on your portfolio.
Get daily stock ideas from top-performing Wall Street analysts. Get short term trading ideas from the MarketBeat Idea Engine. View which stocks are hot on social media with MarketBeat’s trending stocks report.
Identify stocks that meet your criteria using seven unique stock screeners. See what’s happening in the market right now with MarketBeat’s real-time news feed. Export data to Excel for your own analysis.
As Featured By:
326 E 8th St #105, Sioux Falls, SD 57103
contact@marketbeat.com
(844) 978-6257
© American Consumer News, LLC dba MarketBeat® 2010-2023. All rights reserved.
© 2023 Market data provided is at least 10-minutes delayed and hosted by Barchart Solutions. Information is provided ‘as-is’ and solely for informational purposes, not for trading purposes or advice, and is delayed. To see all exchange delays and terms of use please see Barchart’s disclaimer.

source

Thursday, 19 January 2023 / Published in Uncategorized

If you’re on a Galaxy Fold, consider unfolding your phone or viewing it in full screen to best optimize your experience.
Credit Cards
Banks
Brokers
Crypto
Mortgages
Insurances
Loans
Small Business
Knowledge
by DP Taylor | Updated Aug. 5, 2022 – First published on May 18, 2022
Image source: Getty Images
Those stacks of paper scattered throughout your office may not seem like they’re costing your business money, but you’d be surprised.
One study found that, on average, 7.5% of paper documents get lost completely, and 3% are misfiled. And it costs about $2,000 annually in terms of work hours just to maintain a single, four-drawer filing cabinet.
The way we deal with documents these days is totally different from how it was 20 years ago. Our electronic signatures and electronic record-keeping systems bear no resemblance to the rows of folders packed away in filing cabinets. There’s no reason to be stuck in the old ways of doing things.
If you don’t have an electronic document and record management system (EDRMS), you’re probably losing a lot of money without realizing it.
This stems from valuable documents being lost into the ether, or your employees spending a significant amount of time dealing with documents when they could be doing other things. This guide will help you understand how to use EDRMS to streamline your business.
An EDRMS is a process which organizations use to organize all important information in one central location.
Organizations often use an EDRMS (also referred to as an electronic document management system or EDMS) not only to make it easy to locate documents and records, but also for document control and advanced record management.
The system creates an audit trail showing who has accessed certain information, how and when it has been altered, and any other pertinent information.
EDRMS software solutions integrate all current business document management into one seamless, centralized electronic records system, sometimes hosted in the cloud for convenience and easy access.
An EDRMS is more than just an electronic filing system — it is a fundamental part of running your organization.
This is the most basic purpose of electronic data systems. At any organization, paperwork tends to pile up over time, making it difficult to find that permit you got a year ago or an employee record.
An EDRMS either receives user input or automatically files paperwork electronically, placing all of that documentation in one convenient place so it isn’t taking up space on your shelves or in miscellaneous folders spread out across various computers within your organization.
A key part of good records management is making sure all of that paperwork is in order and can be found easily and quickly. An EDRMS sorts and categorizes paperwork so it can be found with just a few keystrokes. This feature alone will save an organization hundreds or even thousands of work hours.
Some documents are highly sensitive, and having vital organizational information sitting on a shelf or in an unsecured computer folder is a recipe for disaster. An EDRMS keeps everything in one centralized place and prevents unauthorized users from accessing it.
Most EDRMS software allows the administrator to set different permissions for different files, so one person who needs access to one file doesn’t get the keys to the kingdom.
An EDRMS often has communication features, such as alerting a department that a specific relevant document has been uploaded to the system, or automatically sharing a file with individuals tagged on it. Some systems may allow users to directly message each other through the system, or even to mark up business documents.

eFileCabinet


eFileCabinet
has a communication feature within the document management system for sending and receiving files. Source: eFileCabinet.
Document management may not seem like the most important part of your business, but these four benefits explain why it can have such a huge impact on how your organization runs.
In the digital age, keeping information safe is difficult. You face numerous threats from people around the world who want to steal sensitive information. An EDRMS makes sure that data are safe and secure with features that require permissions to access certain information.
And by tracking changes to documents, an EDRMS can alert managers to any unauthorized changes so that they can revert the document to its previous forms.
An EDRMS also ensures that companies are in compliance with laws and regulations requiring information security, such as HIPAA with medical records and GDPR for protecting data of citizens of the European Union.

Box allows you to see what kind of changes are being made to which documents. Image source: Author
Businesses must be organized — it’s hard to operate if you’re not. When all of your documentation is organized, you add a veneer of professionalism to your organization.
This helps everyone’s mindset since it’s easier to work when you feel like everything is at your fingertips. As the old saying goes, a cluttered desk is a sign of a cluttered mind. By streamlining your documentation, you take a big step toward streamlining your business as a whole.

M-Files provides a top-down overview of your files so you can quickly navigate to the right document. Image source: Author
Your employees will be able to access documents much easier thanks to an EDRMS. They won’t have to dig through stacks of papers in a cardboard box tucked away in a closet, or even search multiple computers for a file hidden somewhere in a random folder.
Instead, they’ll have one centralized system they can use to locate a file with just a few keystrokes. This makes it easy for them to do their jobs and allows them to focus on more important tasks.
When all of your paperwork is organized and accessible, your business is more efficient and therefore more productive. Your employees will spend less time manually entering data and searching for necessary documentation.
Also, you’ll spend less money on document management expenses because everything is digital, and many of the processes are automated.
It's impossible to say how much a system will cost because it depends on the nature of your business, how much documentation you need organized, and what extra features you need. Generally, the amount you spend on an EDRMS will be driven by:
An EDRMS may cost thousands of dollars or more each month if you need an extensive file management system. However, if you're a small business, you can manage your documents for much less than that.
For example, DocSend offers a plan for business teams for $45/month per user. And Box (For Business) offers a long-term free version with a 10 GB storage cap that could be enough if you're running a one-person shop. You can bump that up to 100 GB for just $5 per month.
If you are a medium or large organization, you need an EDRMS. An organization of any reasonable size will have oceans of documentation, and many of these records will be sensitive or have legal ramifications, so you must have a secure system for managing them.
Even smaller organizations should have an EDRMS. You can find an inexpensive system, and it will give you peace of mind to know all of your documentation is in one secure place.
The only time an EDRMS might not be necessary is if you are a one- or two-person shop with almost no documents. But that's a rare situation, and even then you can opt for a free EDRMS option to cover your bases.
Chances are you have some documentation that could stand protection, if only because it has personally identifiable information on it that hackers could steal.
Determining what kind of EDRMS will fit your business is trickier, and it requires consultation with your staff on what documentation you have and how it should be organized. Specifically, you should know:
With this information in hand, you can examine EDRMS options. The Ascent has reviewed some of the top document management systems, so read a few reviews and get an idea of some options that look interesting. Then give a couple of them a try and settle on one to implement in your organization.
If you’re reading this, chances are you’re tired of the chaos and clutter of your organization’s documentation “system,” if it can be called that. This is a sign that it’s time to stop putting it off.
Set aside some time in the coming weeks to start dealing with this issue, implementing document management best practices, and identifying software that can organize the mess. You’ll wonder how you ever got along without it.

If you're using the wrong credit or debit card, it could be costing you serious money. Our expert loves this top pick, which features a 0% intro APR until 2024, an insane cash back rate of up to 5%, and all somehow for no annual fee. 
In fact, this card is so good that our expert even uses it personally. Click here to read our full review for free and apply in just 2 minutes. 
Read our free review

DP Taylor is a business software expert writing for The Ascent and The Motley Fool.
We’re firm believers in the Golden Rule, which is why editorial opinions are ours alone and have not been previously reviewed, approved, or endorsed by included advertisers. The Ascent does not cover all offers on the market. Editorial content from The Ascent is separate from The Motley Fool editorial content and is created by a different analyst team.
The Ascent is a Motley Fool service that rates and reviews essential products for your everyday money matters.
Copyright © 2018 – 2023 The Ascent. All rights reserved.

source

Thursday, 19 January 2023 / Published in Uncategorized

Hi, what are you looking for?
By
Published
This press release was orginally distributed by SBWire
New Jersey, NJ — (SBWIRE) — 01/17/2023 — The latest study released on the Global Insurance Software Market by AMA Research evaluates market size, trend, and forecast to 2027. The Insurance Software market study covers significant research data and proofs to be a handy resource document for managers, analysts, industry experts and other key people to have ready-to-access and self-analyzed study to help understand market trends, growth drivers, opportunities and upcoming challenges and about the competitors.
Key Players in This Report Include:
IBM (United States), Microsoft (United States), Oracle Corporation (United States), Salesforce (United States), Vertafore (United States), Applied Systems, Inc. (United States), Adobe (United States), Allied System Inc. (United States), Mitchell International, Inc. (United States), Solera Holdings (United States), SAP (Germany), Acturis (United Kingdom)
Download Sample Report PDF (Including Full TOC, Table & Figures) @ https://www.advancemarketanalytics.com/sample-report/16914-global-insurance-software-market#utm_source=SBWireShubhangi
Definition:
In the midst of a global economic slowdown and facing severe pressure, the insurance industry has undergone consolidation and integration. Insurance software is a solution which helps insurance companies, agencies, or brokers facilitate operational and organizational tasks in a more efficient and effective way. Insurance software is the automated and user-friendly program which helps in providing a large set of accurate data for underwriting managers and superior information. It saves a considerable amount of resources and time. Insurance software provides regular status report making business run more efficiently and help to generate ideas about the integration of the system in the trading process. It enhances the efficiency with consistent data sharing for binding, rating and policy processing is kept within an insurance software system.
Market Trend:
– Rapid Growth Of Cyber Insurance Market
– Integration Of Wearablea€™s Into Customer Engagement Metric For Life Insurance Market
Market Drivers:
– Uncertain Catastrophic Events Leading To Increased Need For Insurance
– Increased Awareness About Importance Of Insurance
– Rapid Growth Of The Insurance Industry
– Maintenance Of Database And Improved Customer Services
Market Opportunities:
– Investors Collaborating With Insurtech Firms
The Global Insurance Software Market segments and Market Data Break Down are illuminated below:
by Type (Customer Relationship Management Software (CRM), Document Management Software, Enterprise Resource Planning Software (ERP), Claims Management Software, Others), Deployment Mode (Cloud, On-Premise), End User (Brokers, Agencies, Insurance Companies), Insurance Type (Life Insurance, Accident and Health Insurance, Property & Casualty Insurance, Other)
Global Insurance Software market report highlights information regarding the current and future industry trends, growth patterns, as well as it offers business strategies to help the stakeholders in making sound decisions that may help to ensure the profit trajectory over the forecast years.
Have a query? Market an enquiry before purchase @ https://www.advancemarketanalytics.com/enquiry-before-buy/16914-global-insurance-software-market#utm_source=SBWireShubhangi
Geographically, the detailed analysis of consumption, revenue, market share, and growth rate of the following regions:
– The Middle East and Africa (South Africa, Saudi Arabia, UAE, Israel, Egypt, etc.)
– North America (United States, Mexico & Canada)
– South America (Brazil, Venezuela, Argentina, Ecuador, Peru, Colombia, etc.)
– Europe (Turkey, Spain, Turkey, Netherlands Denmark, Belgium, Switzerland, Germany, Russia UK, Italy, France, etc.)
– Asia-Pacific (Taiwan, Hong Kong, Singapore, Vietnam, China, Malaysia, Japan, Philippines, Korea, Thailand, India, Indonesia, and Australia).
Objectives of the Report
– -To carefully analyze and forecast the size of the Insurance Software market by value and volume.
– -To estimate the market shares of major segments of the Insurance Software
– -To showcase the development of the Insurance Software market in different parts of the world.
– -To analyze and study micro-markets in terms of their contributions to the Insurance Software market, their prospects, and individual growth trends.
– -To offer precise and useful details about factors affecting the growth of the Insurance Software
– -To provide a meticulous assessment of crucial business strategies used by leading companies operating in the Insurance Software market, which include research and development, collaborations, agreements, partnerships, acquisitions, mergers, new developments, and product launches.
Buy Complete Assessment of Insurance Software market Now @ https://www.advancemarketanalytics.com/buy-now?format=1&report=16914#utm_source=SBWireShubhangi
Major highlights from Table of Contents:
Insurance Software Market Study Coverage:
– It includes major manufacturers, emerging player's growth story, and major business segments of Insurance Software market, years considered, and research objectives. Additionally, segmentation on the basis of the type of product, application, and technology.
– Insurance Software Market Executive Summary: It gives a summary of overall studies, growth rate, available market, competitive landscape, market drivers, trends, and issues, and macroscopic indicators.
– Insurance Software Market Production by Region Insurance Software Market Profile of Manufacturers-players are studied on the basis of SWOT, their products, production, value, financials, and other vital factors.
– Key Points Covered in Insurance Software Market Report:
– Insurance Software Overview, Definition and Classification Market drivers and barriers
– Insurance Software Market Competition by Manufacturers
– Impact Analysis of COVID-19 on Insurance Software Market
– Insurance Software Capacity, Production, Revenue (Value) by Region (2021-2027)
– Insurance Software Supply (Production), Consumption, Export, Import by Region (2021-2027)
– Insurance Software Production, Revenue (Value), Price Trend by Type {Payment Gateway, Merchant Account, Subscription Management,}
– Insurance Software Manufacturers Profiles/Analysis Insurance Software Manufacturing Cost Analysis, Industrial/Supply Chain Analysis, Sourcing Strategy and Downstream Buyers, Marketing
– Strategy by Key Manufacturers/Players, Connected Distributors/Traders Standardization, Regulatory and collaborative initiatives, Industry road map and value chain Market Effect Factors Analysis.
Browse Complete Summary and Table of Content @ https://www.advancemarketanalytics.com/reports/16914-global-insurance-software-market#utm_source=SBWireShubhangi
Key questions answered
– How feasible is Insurance Software market for long-term investment?
– What are influencing factors driving the demand for Insurance Software near future?
– What is the impact analysis of various factors in the Global Insurance Software market growth?
– What are the recent trends in the regional market and how successful they are?
Thanks for reading this article; you can also get individual chapter wise section or region wise report version like North America, Middle East, Africa, Europe or LATAM, Southeast Asia.
For more information on this press release visit: http://www.sbwire.com/press-releases/insurance-softwaremarket-to-witness-revolutionary-growth-by-2027-ibm-oracle-vertafore-1369339.htm
Praveen Kumar
PR Marketing Manager
AMA Research & Media LLP
Telephone: +1(201) 7937323, +1(201) 79371
Email: Click to Email Praveen Kumar
Web: https://www.advancemarketanalytics.com/

ReleaseWire is a leading online newswire service and media engagement platform, designed for and used by businesses of all sizes including nonprofit organizations, connecting marketers and communicators to journalists, editors, bloggers and other online publishers around the world. For more information visit www.releasewire.com.
The London-based news company says that personal data of U.K. staff members has been accessed in the incident.
Nissan and Renault are nearing a “historic” rebalancing of their auto alliance, with a deal likely to be announced in the coming weeks.
The EU on Monday said it would take “decisive steps” to protect Europe in the face of massive US subsidies.
The Bank of Japan’s upcoming policy decision will be closely followed by traders after it announced a surprise tweak last month – Copyright AFP…
COPYRIGHT © 1998 – 2023 DIGITAL JOURNAL INC. Sitemaps: XML / News . Digital Journal is not responsible for the content of external sites. Read more about our external linking.

source

Thursday, 19 January 2023 / Published in Uncategorized

By
CSO |
The fallout of the SolarWinds cybersecurity incident, coupled with Cybersecurity Executive Order (EO) put the topic of software supply chain security, and by association, software bills of material (SBOM) center stage in the security dialog. Coupled with the Log4j vulnerability and impact that left countless organizations scrambling to determine the impact, SBOMs are now a critical component of modern cybersecurity vulnerability programs. 
Among the benefits of SBOMs, which are essentially a list of components that make up a piece of software, is to identify potentially vulnerable components. Leading SBOM platforms and tools such as Dependency Track do this by tying vulnerabilities associated with components to the attention of those using the SBOM to analyze their software components. Dependency Track and other tools facilitate this process by querying sources such as the National Vulnerability Database (NVD), Sonatype OSS Index, VulnDB or OSV.
However, just because a vulnerability is associated with a component in software does not mean that the component is exploitable. This is where the Vulnerability Exploitability eXchange (VEX) comes into play.
As defined by guidance from the U.S. National Telecommunications and Information Administration (NTIA), VEX’s primary use case is “to provide users (e.g., operators, developers, and services providers) additional information on whether a product is impacted by a specific vulnerability in an included component and, if affected, whether there are actions recommended to remediate.”
This is a lengthy way of saying VEX adds context to vulnerabilities to inform risk management activities. Much like other leading SBOM and software supply chain transparency and security guidance, VEX was born out of the NTIA’s Multistakeholder Process for Software Component Transparency. The guidance states that while VEX was developed for a specific SBOM use case, it isn’t limited to use with SBOMs or necessarily required, either.
Again, just because a vulnerability is present does not mean it is exploitable. This is critical information to know because with vulnerability management programs and activities, organizations are performing risk management. In cybersecurity risk management, organizations are looking to identify, analyze, evaluate and address cybersecurity threats based on the organization’s risk tolerance. This leads to the organization prioritizing risks based on likelihood and the severity of the risk materializing. Without knowing if a vulnerability is exploitable, it would be impossible to accurately project its likelihood.
How does VEX solve this challenge? It empowers software suppliers to issue a VEX, which is an assertion about the status of a vulnerability in a specific product. VEX supports four primary status options:
With the SBOM itself as an example, we’re seeing a push toward machine-readable artifacts and documentation, which enables better automation, accuracy and speed. We’re seeing similar trends in the realm of compliance with NIST’s Open Security Controls Assessment Language (OSCAL), which brings traditional paper-based security controls and authorization documents into a machine-readable format.
VEX is doing something similar, avoiding the need to email security advisories or details about vulnerabilities and recommendations, and instead bringing that information into a machine-readable format to foster automation and the use of modernized security tooling that moves at a pace much closer to the current thread landscape than humans and manual activities. As the push for software supply chain transparency and security evolve, it isn’t hard to imagine a world where enterprise software inventories are able to be visualized in dashboards and tooling, along with their associated vulnerabilities and the actual exploitability of the vulnerabilities, all empowered by SBOM’s and accompanying VEX data.
That’s a stark contrast to the modern ecosystem where most organizations don’t have accurate inventories of the software components they consume and have deployed, nor the vulnerabilities associated with it. This is all despite the reality that modern software is overwhelmingly composed of open-source software (OSS) components, with some estimates reaching as high as 80% to 90%.
The guidance also states that while VEXs can be authored by a software supplier, they can also be authored by third parties, leaving users in a position to determine how to use the data. This makes it easy to see scenarios where security researchers and vulnerability vendors may make attempts to produce VEXs for products as part of their own product offering.
The SBOM initiative moved from NTIA to the U.S. Cybersecurity Infrastructure Security Agency (CISA), coinciding with a move of SBOM evangelist and leader Dr. Allan Friedman. In 2022 CISA has published two additional VEX documents. One is the VEX Use Cases document and the other is the VEX Status Justifications document.
The VEX Use Cases document provides minimum data elements of a VEX document, much like NTIA defined the minimum elements for an SBOM (as tied to the cyber EO). In this guidance, it states that a VEX document must include the VEX metadata, product details, vulnerability details and product status. These product status details include status information about the vulnerability in a product and can be not affected, affected, fixed or under investigation.
The VEX Status Justifications document subsequently focuses on the requirement for VEX documents to contain a justification statement on why the VEX document creator chose to assert that the product’s status is not affected, if they indeed did make that choice. This allows suppliers to provide justifications for why a product is not affected by a vulnerability. Options include the component or vulnerable code not being present, the vulnerable code not being able to be controlled by an adversary or the code not being in the execution path, and lastly the existence of inline mitigations already being in place in the product.
VEX represents a key next step in assisting SBOMs become actionable by providing contextual insights and assertions from product vendors about the exploitability of vulnerabilities present in their products. By using both the minimum elements as defined for VEX documents and their associated not affected justification fields, if applicable, software producers are able to empower software consumers for make risk informed decisions to drive their vulnerability management activities as part of broader cybersecurity programs.
Copyright © 2022 IDG Communications, Inc.
Copyright © 2023 IDG Communications, Inc.

source

TOP