Likelihood to Recommend Onapsis is divided into 4 major components,
Assess Comply Defend Control In assess, it does a whitebox and blackbox testing of the ERP systems that have been added to the Onapsis console. It highlights relevant application issues and automates the process, also provides the solutions to implement the fix. In comply, it provides a governance on the various regulatory compliances which the firm has to follow, as well as provides a firm grip to the audit and ERP admin team. In control, it enables a workflow of 15 pre-defined parameter values within the SAP system and helps monitor, and track the changes made to those parameters. The capabilities are to either block, or request for an approval for changes made to those parameters in addition to just monitoring them. In defend, it goes through the SAP logs; and compares it with a pre-defined ruleset to alert the end-users via email or SIEM tool or both.
Read full review Nessus is perfectly suitable for performing comprehensive vulnerability assessment scans being a vulnerability scanner. It is less appropriate for performing penetration testing since it is not a penetration testing tool, it does not have the ability and modules to exploit the vulnerabilities of the system.
Read full review Pros Eliminating the manual process improves the overall accuracy of results and also frees up valuable resources to focus on other different projects. Onapsis provides great leverage to our technical teams in order to review in a standardized way of the landscape. Onapsis always matches vulnerabilities with useful context and finds possible solutions. Onapsis is usually implemented to continuously monitor, and alert us on any issues on the SAP systems. Not only this but implementing Onapsis also eliminates the network on the year-end and month-end audits and helps in making the overall process faster, smooth, efficient as well as accurate. Read full review With Nessus we can find the missing critical patches for a server or workstations. Nessus points out any vulnerable or outdated software Technologies used in the system, thus eliminating any chances for security flaws being turned up. Nessus typically points any configuration level issues in accordance with the OWASP guidelines. Even the configuration of SSL related which are most of the time handled by some vendors or 3rd parties. Nessus not only lists out these Vulnerabilities but describes clearly the vulnerabilities in details with its thousands of plugins updated regularly, the tool also recommends solution with practical details of easy implementation. Read full review Cons Multiple UIs No proper customization of UI log-off Tedious setup of Control component No proper error messages received Read full review Could use an upgrade within reports. Scans can take a long time to complete. Have to break them down in small sections. Read full review Likelihood to Renew Nessus is best and easy to use application for Vulnerabilities finding and reporting, it has multiple platforms and wide scope covering almost all devices for security improvement so far, thus we are very likely to continue its services.
Read full review Usability It's very much a plug and play application that the user can go into with limited knowledge and set-up scans in minutes.
Read full review Support Rating I haven't needed to contact support yet. But issues are easily solved with a quick internet search which means support and by extension, the larger community are involved and knowledgeable.
Read full review Alternatives Considered Honestly, I havent use something like Onapsis before and currently I am not aware if there is something similiar out there. They are one of a kind and is a complete suit, so is unlikelly that someone from outside will appear with a better solution.
Read full review Sometimes when we identify a vulnerability with Nessus that has an exploit, we made a proof of concept with
Metasploit in order to show to the IT managers the importance of the software/hardware hardening.
Read full review Return on Investment It offers very reasonable packages. The customer support of Onapsis is reliable and efficient. It is a great platform as it shows a unified and easy-to-read different and complex topics in a simpler way. Read full review Nessus certainly has a positive impact while me while performing my job, either as security research, or performing vulnerability assessments for clients. It gives a lot of information about the system/application after performing scans. The number of false positives is also less compared to other vulnerability scanners. The professional edition is very useful as policy templates available in this edition are very handy and useful even to perform compliance scan like PCI DSS scan. Also, the ability to export the scan results into reports in formats like HTML, PDF is very useful which could be for performing system/application reviews. Read full review ScreenShots