Evaluate Your Security Program
Your Security Program, also known as the Command Platform Home page, is a dashboard that details the key focal areas that Rapid7 has identified to ensure your organization’s Security Program is a success. The data displayed on this page is aggregated and summarized from Attack Surface Management (Surface Command) and the solutions contained within Exposure Command. For more information on what Exposure Command offers, see Exposure Command Overview .
Unlock Your Security Program
To view the Command Home page, you must be either a Command Platform administrator or an Administrator for the following solutions:
- Cloud Security (InsightCloudSec)
- Vulnerability Management (InsightVM)
- Attack Surface Management (Surface Command)
Because Your Security Program relies on data from several different Rapid7 solutions, we recommend you follow the Quick Start Guide to ensure you’re receiving the most enriched perspective of Your Security Program.
Understand Your Security Program
The Home page diagnoses the most important facets of your organization’s security:
Emergent Threats
Occasionally, Rapid7 may also add a banner to Command Home that details recent Emergent Threats for easy tracking. Emergent Threats are severe new vulnerabilities (CVEs) or threats that may impact you. The banner also includes information on how you can take proactive measures to protect your organization.
Attack Surface
A large part of your security program is keeping track of your Attack Surface. Rapid7 organizes your Attack Surface into four distinct types:
- Assets - Assets (for example, servers and laptops) as identified by Attack Surface Management (Surface Command) Connectors or Vulnerability Management (InsightVM)
- Identities - Users or identities (roles) as identified by Attack Surface Management (Surface Command) Connectors or SIEM (InsightIDR)
- External Discoveries - External discoveries as identified by External Attack Surface Management (EASM) or relevant Attack Surface Management (Surface Command) Connectors
- Cloud Assets - Cloud Assets (EC2 instance, Azure VM, etc.) as identified by Attack Surface Management (Surface Command) Connectors or Cloud Security (InsightCloudSec)
The counts and statistics presented on this card come from Attack Surface Management (Surface Command) queries and External Assets or a combination of Vulnerability Management (InsightVM) , SIEM (InsightIDR) , and Cloud Security (InsightCloudSec) . For more information on a detailed view of your Attack Surface and Attack Surface Management (Surface Command), see Explore Your Attack Surface .
Priority Actions
Priority actions are the easiest and best way to protect your environments and revolve around:
- Assets without endpoint protection
- Assets without a recent vulnerability scan
- Users without multi-factor authentication turned on
External Attack Surface
The External Attack Surface section details key discoveries for your external attack surface:
- How many externally accessible domains and subdomains you have
- How many externally accessible hosts you have
- How many SSL certificates you have
- How many running services are exposed on external hosts