You are here

FortiScan Receives Secure Content Automation Protocol Validation

Fortinet Adds to its Impressive List of Products Meeting Compliance Mandates

SUNNYVALE, Calif. - July 22, 2009 - Fortinet® - a market-leading network security provider and worldwide leader of unified threat management (UTM) solutions today announced that the FortiScan™ product line has completed the Secure Content Automation Protocol (SCAP) validation. In order for government agencies to provide Federal Information Security Management Act (FISMA) compliance reporting, they must utilize a SCAP validated product. Likewise, in order for vendors to sell to the federal government, their products must be SCAP validated.

The SCAP compliance program was established to ensure that security tools comply with the National Institute of Standards (NIST) and Technology SCAP standards. In addition, the compliance program enabled federal agencies to not only continuously monitor systems against the Office of Management and Budget mandated Federal Desktop Core Computing (FDCC) standards, but also provide reporting in a consistent format within FISMA.

The Fortinet FortiScan appliance allows organizations to identify and close IT compliance gaps and implement continuous monitoring in order to audit, evaluate, and comply with internal, industry, and regulatory policies for IT controls and security. The FortiScan appliance utilizes SCAP benchmarks and technologies to facilitate compliance validation against these published standards.

FortiScan provides a centrally managed, enterprise-scale solution. System administrators can monitor as well as optionally remediate assets from a central location that may or may not be geographically collocated with the assets without the need to manually visit potentially thousands of assets in person. The FortiScan appliance also provides the ability to correlated SCAP scanning results including Common Vulnerabilities and Exposures (CVE®), Common Configuration Enumeration (CCE), Common Platform Enumeration (CPE™), Common Vulnerability Scoring System (CVSS) and Open Vulnerability and Assessment Language (OVAL™) references (where appropriate) as well as export detailed reports in Extensible Configuration Checklist Description Format (XCCDF) format.

FortiScan offers federal agencies and enterprises alike, a highly adaptable solution for conducting continuous monitoring and reporting of FDCC compliance within FISMA. Not only does FortiScan provide agent-based scanning/reporting for organizations that have NAT networks, but also agent-less capabilities for network discovery. FortiScan integrates endpoint vulnerability management, industry and federal compliance, patch management, remediation, auditing and reporting into a single, unified appliance for immediate results.

ÏWe are very pleased to have completed the SCAP Validation Program with our FortiScan product. In typical Fortinet fashion, FortiScan is delivered in a unified appliance designed to provide immediate results, integrating endpoint vulnerability management, industry and federal compliance, patch management, remediation, auditing and reporting, said Jeff Lake, vice president of Federal operations at Fortinet.

A listing of Fortinets SCAP validation can be found at: http://nvd.nist.gov/validation_fortinet.cfm

About Fortinet (www.fortinet.com)

Fortinet is a leading provider of network security appliances and the market leader in Unified Threat Management or UTM. Fortinet solutions were built from the ground up to integrate multiple levels of security protection -- including firewall, VPN, antivirus, intrusion prevention, Web content filtering, spyware prevention and antispam -- designed to help customers protect against network and content level threats. Leveraging a custom ASIC and unified interface, Fortinet solutions offer advanced security functionality that scales from remote office to chassis-based solutions with integrated management and reporting. Fortinet solutions have won multiple awards around the world and are the only security products that are certified in five programs by ICSA Labs: Firewall, Antivirus, IPSec VPN, Network IPS and Antispam. Fortinet is based in Sunnyvale, California.

Copyright © 2009 Fortinet, Inc. All rights reserved. The symbols ® and ™ denote respectively federally registered trademarks and unregistered trademarks of Fortinet, Inc., its subsidiaries and affiliates, including, but not limited to, the following trademarks: Fortinet, FortiGate, FortiGuard, FortiManager, FortiMail, FortiClient, FortiCare, FortiAnalyzer, FortiReporter, FortiOS, FortiASIC, FortiWiFi, FortiSwitch, FortiVoIP, FortiBIOS, FortiLog, FortiResponse, and FortiDB. Other trademarks belong to their respective owners. Fortinet has not independently verified statements above attributed to other parties, and Fortinet does not endorse any such statements.

How to Buy

Purchase Fortinet Products


The system is highly cost-effective in terms of functionality and efficiency and provides unmatched security, said Mr. Wooho Kyeong, Manager of IT Team at AMC. "We were impressed by the wide range of security features and we found, in particular, that the FortiGuard? Distribution Network was particularly effective in dealing with viruses and spam. Our regional hospitals now have the degree of stability and availability in their computer networks that is needed in the important medical work that they do."

Wooho Kyeong
Manager of IT Team
AMC