This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Missed scheduled scans, will they still run?

If I have a scheduled scan using 9.x for a certain time, and that system is turned off during that time, will it run the scheduled scan when its powered on next?

:1762


This thread was automatically locked due to age.
Parents
  • Hello Scissor,

    Executive VIP

    :smileylol: is just a forum rank (you could question the automated ranking system which assigns such a rank not only to serious advisors like Jak but also to motormouths - or motorfingers - like me).

    rationalize away as somehow being a fault of the customer 

    not at all. It is also not meant to discourage anyone from submitting feature requests. What I'm trying to do is to explain the rationale (as far as I understand it, I'm not Sophos and I don't have access to inside information) behind some "strategic and implementation decisions", their consequences and how to better live with them (if you excuse the presumptuous wording). Do not forget that even if your request is accepted it will often take considerable time until it is implemented. So, sorry if I've put you off - this was not my intention.

    [the] magical fairyland

    called university - with the lack of policies (or if there are, the lack of empowerment to enforce them) as its most exciting (or most frustrating, depending on your POV) charm. :smileyhappy:

    One more stab at scans:

    For a workstation a (scheduled) scan is supplement to on-access scanning (no more, no less) and not essential. Its main purposes are

    • scan the parts of the file system excluded from on-access scanning
    • scan inside archives and/or all files to prevent transfer of "buried" threats
    • clean up or remove items which at the time of detection have only been blocked
    • clean up adware and PUA (although it is covered by the above I mention it explicitly - BTW: Sophos recommends a daily scan if you are really aggressive in dealing with PUA)
    • scan for rootkits
    • last but not least - policy compliance

    As the timing of the scan is arbitrary (especially if it is weekly or even monthly) a missed scan doesn't actually make much difference in terms of protection or security. If you do think it does, then you shouldn't let the user log in before the scan has finished - otherwise ...

    Leaves the compliance. I assume though there aren't many requests for scan on/after boot or run ASAP if missed. Sophos "believing" in simplicity is reluctant to add too many features unless there is sufficient demand (Audit has been added recently but IMnshO it reeks of audit as defined by auditors and not audit as defined by administrators :smileywink:). As said, serious auditing/monitoring also requires to assure that the scan has completed, check the results and perform additional actions if necessary. In such an environment you likely have the means to wake up the machines as well. And then - patching is at least as important as regular scanning.

    staggered scan starts

    Sophos has at least made an attempt with the Virtualization Scan Controller. If it falls short in your environment please do tell them so. I'm not using it so I can't say if it is any good.

    *already* offered by competitors

    Philosophy - it's as simple (forgive the pun) as that. It is part of what makes Sophos Sophos. Strategy and economic reasons also define how a product is developed and placed. This is not to defend Sophos. There's only so much you can get for a certain amount you (and me too) are willing or can afford to pay. Whichever vendor, you have to adjust, you have to make the most of the product you bought. That's why I'm trying to get to the bottom of it (but obviously overshoot) and also to depict alternatives. 

    So, sorry about my rant - had too much coffee today :smileyhappy:

    Christian

    :45169
Reply
  • Hello Scissor,

    Executive VIP

    :smileylol: is just a forum rank (you could question the automated ranking system which assigns such a rank not only to serious advisors like Jak but also to motormouths - or motorfingers - like me).

    rationalize away as somehow being a fault of the customer 

    not at all. It is also not meant to discourage anyone from submitting feature requests. What I'm trying to do is to explain the rationale (as far as I understand it, I'm not Sophos and I don't have access to inside information) behind some "strategic and implementation decisions", their consequences and how to better live with them (if you excuse the presumptuous wording). Do not forget that even if your request is accepted it will often take considerable time until it is implemented. So, sorry if I've put you off - this was not my intention.

    [the] magical fairyland

    called university - with the lack of policies (or if there are, the lack of empowerment to enforce them) as its most exciting (or most frustrating, depending on your POV) charm. :smileyhappy:

    One more stab at scans:

    For a workstation a (scheduled) scan is supplement to on-access scanning (no more, no less) and not essential. Its main purposes are

    • scan the parts of the file system excluded from on-access scanning
    • scan inside archives and/or all files to prevent transfer of "buried" threats
    • clean up or remove items which at the time of detection have only been blocked
    • clean up adware and PUA (although it is covered by the above I mention it explicitly - BTW: Sophos recommends a daily scan if you are really aggressive in dealing with PUA)
    • scan for rootkits
    • last but not least - policy compliance

    As the timing of the scan is arbitrary (especially if it is weekly or even monthly) a missed scan doesn't actually make much difference in terms of protection or security. If you do think it does, then you shouldn't let the user log in before the scan has finished - otherwise ...

    Leaves the compliance. I assume though there aren't many requests for scan on/after boot or run ASAP if missed. Sophos "believing" in simplicity is reluctant to add too many features unless there is sufficient demand (Audit has been added recently but IMnshO it reeks of audit as defined by auditors and not audit as defined by administrators :smileywink:). As said, serious auditing/monitoring also requires to assure that the scan has completed, check the results and perform additional actions if necessary. In such an environment you likely have the means to wake up the machines as well. And then - patching is at least as important as regular scanning.

    staggered scan starts

    Sophos has at least made an attempt with the Virtualization Scan Controller. If it falls short in your environment please do tell them so. I'm not using it so I can't say if it is any good.

    *already* offered by competitors

    Philosophy - it's as simple (forgive the pun) as that. It is part of what makes Sophos Sophos. Strategy and economic reasons also define how a product is developed and placed. This is not to defend Sophos. There's only so much you can get for a certain amount you (and me too) are willing or can afford to pay. Whichever vendor, you have to adjust, you have to make the most of the product you bought. That's why I'm trying to get to the bottom of it (but obviously overshoot) and also to depict alternatives. 

    So, sorry about my rant - had too much coffee today :smileyhappy:

    Christian

    :45169
Children
No Data