We performed a comparison between Tenable.sc and VMware Aria Automation based on our users’ reviews in five categories. After reading all of the collected data, you can find our conclusion below.
Features: Tenable.sc excels in vulnerability detection, prioritization, and risk-based approach, while VMware Aria Automation stands out for its automation capabilities, DevOps features, and customizable user frontend experience. Tenable.sc could enhance its penetration testing, ticketing systems, GUI, reporting, vendor training, and user interface. Pricing is also a concern. VMware Aria Automation could benefit from simplification in areas such as multitenancy management, migration, API, vRealize Orchestrator Automation, automation, licensing, orchestration workflow, and reporting customization.
Service and Support: Tenable.sc's customer service has varying opinions, while some customers rate it positively, others believe it requires improvement. In contrast, VMware Aria Automation's customer service is generally viewed as good, with some customers citing the need for additional research for complex implementations.
Ease of Deployment: Tenable.sc has a simple and easy initial setup, taking only a day to complete. In contrast, VMware Aria Automation's setup is more complicated and can take anywhere from an hour to several months, depending on the version and environment.
Pricing: Tenable.sc offers pricing based on IP addresses scanned, while VMware Aria Automation has complex licensing options. Tenable.sc's cost is viewed as reasonable by some, but expensive by others. VMware Aria Automation is costly, but offers features such as workload management and auto-scaling suggestions that can result in cost savings.
ROI: Tenable.sc is a cost-effective solution that delivers a positive ROI by minimizing manpower costs. On the other hand, VMware Aria Automation saves time and provides greater visibility but ROI can be variable and indirect.
Comparison Results: Tenable.sc is the preferred choice over VMware Aria Automation for vulnerability management, as it offers more comprehensive features such as accurate detection and compliance scans, risk-based approach, accurate reports, and fewer false positives. While VMware Aria Automation has extensive automation capabilities for virtual machine deployment and feature customization, Tenable.sc is better suited for vulnerability management.
"Our most important features are those around entitlement, external exposure, vulnerabilities, and container security."
"The CSPM module has been the most effective. It was easy to deploy and covered all our accounts through APIs, requiring no agents. Wiz provides instant visibility into high-level risks that we need to address."
"With Wiz, we get timely alerts for leaked data or any vulnerabilities already existing in our environment."
"The solution is very user-friendly."
"The security baseline and vulnerability assessments is the valuable feature."
"The vulnerability management modules and the discovery and inventory are the most valuable features. Before using Wiz, it was a very manual process for both. After implementing it, we're able to get all of the analytics into a single platform that gives us visibility across all the systems in our cloud. We're able to correspond and understand what the vulnerability landscape looks like a lot faster."
"Out of all the features, the one item that has been most valuable is the fact that Wiz puts into context all the pieces that create an issue, and applies a particular risk evaluation that helps us prioritize when we need to address a misconfiguration, vulnerability, or any issue that would put our environment into risk."
"The first thing that stood out was the ease of installation and the quick value we got out of the solution."
"The most important features are the dashboard and reporting. The dashboard provides statistics with graphs and bar charts for our management."
"The Auto-Remediate feature is good."
"It basically reviews our threat landscape vulnerability."
"One of the most valuable features is their distributed scan model for allotting engines to work together as a pool and handle multiple scans at once, across multiple environments. Automatic scanning distribution is a distinguishing feature of their toolset."
"The most valuable features of Tenable SC are scanning, reporting, dashboards, and automation."
"The solution is one of the most, if not the most, stable product available."
"We really love the Security Center dashboard. It basically performs vulnerability scanning and then outputs a vulnerability data."
"Tenable.sc's best features are the availability model, accident management, and scoring."
"The automation of the redundant tasks and the implementation of ServiceNow are huge for us..."
"The extensibility of it and the customization of a lot of the Blueprints, that you can customize, and the community as a whole. There's a ton of community-generated Blueprints that might be (helpful) to set up a design for your automation needs, that you can use as a base and go on from there and make changes to it."
"The most valued feature is the streamlining of the DevOps process, automation and orchestration. It provides the ability for the entire Dev lifecycle to actually be incorporated into a single stream."
"The solution is user-friendly and intuitive."
"One of the most valuable features is lifecycle management. It allows my teams to create, manage, and retire all of our infrastructure objects in the data center."
"vRealize automation stability is pretty good. They are always fixing bugs. The product team is doing a great job of addressing any issues that we might have."
"The operations manager does a fantastic job on the front end because it includes on-premises and cloud use cases."
"It is very stable, especially for high availability features."
"The only thing that needs to be improved is the number of scans per day."
"The reporting isn't that great. They have executive summaries, but it's only a compliance report that maps all current issues to specific controls. Whether you look at one subscription or project, regardless of the size, you will get a multipage report on how the issues in that account map to that control. Our CSO isn't going to read through that. He won't filter that out or show that to his leadership and say, "Here's what we're doing." It isn't a helpful report. They're working on it, but it's a poor executive summary."
"One significant issue is that the searches are case-sensitive, so finding a misconfigured resource can become very challenging."
"The solution's container security could be improved."
"The only small pain point has been around some of the logging integrations. Some of the complexities of the script integrations aren't supported with some of the more automated infrastructure components. So, it's not as universal. For example, they have great support for cloud formation and other services, but if you're using another type of management utility or governance language for your infrastructure-as-code automation components, it becomes a little bit trickier to navigate that."
"We would like to see improvements to executive-level reporting and data reporting in general, which we understand is being rolled out to the platform."
"Wiz's reporting capabilities could be refined a bit. They are making headway on that, but more executive-style dashboards would be nice. They just implemented a community aspect where you can share documents and feedback. This was something users had been requesting for a while. They are listening to customer feedback and making changes."
"We wish there were a way, beyond providing visibility and automated remediation, to wait on a given remediation, due to a critical aspect, such as the cost associated with a particular upgrade... We would like to see preventive controls that can be applied through Wiz to protect against vulnerabilities that we're not going to be able to remediate immediately."
"At times we have had the typical bugs."
"Certain aspects require manual effort, such as exporting and analyzing data for our dashboards. The built-in components of the Tenable solution are somewhat clumsy that require external tools. So, this is an area of improvement."
"There's a lot of information being streamed out of the reports. What would be nice, and maybe we just haven't found it, would be more of an executive-type view. We still expect it to collect all this information, but we would like a feature that would allow us to show it to an executive or a director or someone like that and give them some type of high-level overview but not get into the nitty-gritty."
"The pricing is reasonable, but this could be brought down more aggressively, such as we see with Rapid7, Tenable SC's main competitor."
"The solution needs to improve the vulnerability assessment because we have experienced some challenges with accuracy."
"Tenable SC can improve by making it easier to create complicated reports and have more effectiveness in the remediation area for comparison between the scans."
"The GUI could be improved to have all concerns and priorities use the same GUI, allowing them to see all tickets, assign vulnerabilities, and assign variation failures to each member of their team."
"The product could be user-friendly, and they could enhance the web application's security features."
"They should concentrate on navigation and service improvements."
"In terms of additional features, I would like it to be able to poll my vCenter infrastructure more rapidly and adapt to changes quickly. It should alert me and let me know when there are broken components, as a result of underlying infrastructure changes. It needs to be more stringent."
"It has some limitations for scalability, especially for remote data center management. For some components, everything need to be centralized."
"The initial setup was not straightforward. It was not simple, and we had a PoC. We had VMware help us deploy it, and it took them an exorbitant amount of time."
"I don't think it's intuitive or user-friendly. I think it's a good tool. Any automation tool, these days, the learning curve is kind of high. You're teaching sysadmins who never developed stuff. Maybe they modified a little bit of code and now you tell them, "Hey, here's the tool, use it." But you have to know a little bit of DevOps. So you have to train them how to do the scripting."
"I have not found this solution to be user-friendly. It's really complicated. The demo shows that you can automate anything but they only show basic scenarios. If you want to do anything more complicated than that, it becomes very complicated to set up."
"The basic support is not there for Google Cloud and Azure. They are unable to provision nor do cost controls. Google is still left out. It is great that they have done AWS, but we are a retailer which means nothing to us because it is a competitor. Azure is good, but Google is where a lot of our development environments are."
"Upgrades are always a pain."
Tenable Security Center is ranked 10th in Cloud Security Posture Management (CSPM) with 48 reviews while VMware Aria Automation is ranked 15th in Cloud Security Posture Management (CSPM) with 133 reviews. Tenable Security Center is rated 8.2, while VMware Aria Automation is rated 8.0. The top reviewer of Tenable Security Center writes "A security solution for vulnerability assessment with automated scans". On the other hand, the top reviewer of VMware Aria Automation writes "Allows for a lot of orchestration or customization within our environment to suit our customers". Tenable Security Center is most compared with Tenable Vulnerability Management, Qualys VMDR, Tenable Nessus, Rapid7 InsightVM and Forescout Platform, whereas VMware Aria Automation is most compared with Red Hat Ansible Automation Platform, VMware Aria Operations, vCloud Director, Morpheus and vCenter Orchestrator. See our Tenable Security Center vs. VMware Aria Automation report.
See our list of best Cloud Security Posture Management (CSPM) vendors.
We monitor all Cloud Security Posture Management (CSPM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.