SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Security Vision's ‘tricks’: objects and processes

Security Vision's ‘tricks’: objects and processes
27.02.2023


  |  Listen on Google Podcasts  |   Listen on Mave  |   Listen on Yandex Music  |  


Roman Dushkov, Security Vision


We continue publishing the series ‘Security Vision's Features’, which is aimed at introducing you to interesting and useful solutions in our products. This material is dedicated to the peculiarities of working with objects and processes.


Flexible setting of colour indication for text in the interface



To emphasise security threats and deadlines, Security Vision uses the possibility of detailed property customisation. For example, text indicating a high threat level or requests approaching a deadline can be highlighted in red (or any other colour).


Commercial and in-house SOCs can use these features not only to set accents and improve the quality of work, but also to customise the appearance of interfaces to match the corporate style.


Any transactions in workflows



Sometimes a workflow needs to be built in a complex way: branching, with cycles, with returns to previous statuses. For this purpose, the mechanism of process creation in Security Vision does not limit transitions between states and allows you to organise any transition ‘in one button’.


Linking any number of processes to each object



One object in a company can be simultaneously involved in different business processes and be at different stages in each process. Thanks to an inherently unified database, the Security Vision platform provides interconnections natively, without the need for additional integrations or navigating through interface elements.


For example, with one click from the card of any object, you can go to the list of all related workflows or other objects with their own output forms.

Recommended

Information security trends. Part 1
Information security trends. Part 1
SOAR technology and its place in the SOC
SOAR technology and its place in the SOC
Biometric personal data, changes in regulation of its processing and market impact
Biometric personal data, changes in regulation of its processing and market impact
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 1
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 1
Bespoke hacking: who does it and why, what is most often hacked
Bespoke hacking: who does it and why, what is most often hacked
Open software supply chain attack reference (OSC&R)
Open software supply chain attack reference (OSC&R)
Vulnerabilities
Vulnerabilities
Protecting web applications: anti-DDoS
Protecting web applications: anti-DDoS
Access control and user identification. IDM systems
Access control and user identification. IDM systems
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
Darknet - what it is, how criminals use it, what to watch out for
Darknet - what it is, how criminals use it, what to watch out for
Practical protection of personal data. What are the information protection means that have undergone the conformity assessment procedure in accordance with the established procedure
Practical protection of personal data. What are the information protection means that have undergone the conformity assessment procedure in accordance with the established procedure

Recommended

Information security trends. Part 1
Information security trends. Part 1
SOAR technology and its place in the SOC
SOAR technology and its place in the SOC
Biometric personal data, changes in regulation of its processing and market impact
Biometric personal data, changes in regulation of its processing and market impact
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 1
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 1
Bespoke hacking: who does it and why, what is most often hacked
Bespoke hacking: who does it and why, what is most often hacked
Open software supply chain attack reference (OSC&R)
Open software supply chain attack reference (OSC&R)
Vulnerabilities
Vulnerabilities
Protecting web applications: anti-DDoS
Protecting web applications: anti-DDoS
Access control and user identification. IDM systems
Access control and user identification. IDM systems
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
Darknet - what it is, how criminals use it, what to watch out for
Darknet - what it is, how criminals use it, what to watch out for
Practical protection of personal data. What are the information protection means that have undergone the conformity assessment procedure in accordance with the established procedure
Practical protection of personal data. What are the information protection means that have undergone the conformity assessment procedure in accordance with the established procedure

Other articles

IDE for development of no-code security features
IDE for development of no-code security features
Review of the publication NIST SP 800-161 Rev. 1 (Draft) "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations"
Review of the publication NIST SP 800-161 Rev. 1 (Draft) "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations"
Using MITRE ATT&CK in the Threat Intelligence Platform
Using MITRE ATT&CK in the Threat Intelligence Platform
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #11 ‘Increase Efficiency by Expanding SOC Functionality’
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #11 ‘Increase Efficiency by Expanding SOC Functionality’
Cyberattacks. Part 2: Advanced Techniques and Manipulations
Cyberattacks. Part 2: Advanced Techniques and Manipulations
Why and how to build data networks
Why and how to build data networks
Anatomy of visualisation. Part One: From Task to Execution
Anatomy of visualisation. Part One: From Task to Execution
DDoS attacks: what they are and how to protect against them
DDoS attacks: what they are and how to protect against them
How the technical side of data leakage protection is organised
How the technical side of data leakage protection is organised

Other articles

IDE for development of no-code security features
IDE for development of no-code security features
Review of the publication NIST SP 800-161 Rev. 1 (Draft) "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations"
Review of the publication NIST SP 800-161 Rev. 1 (Draft) "Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations"
Using MITRE ATT&CK in the Threat Intelligence Platform
Using MITRE ATT&CK in the Threat Intelligence Platform
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #11 ‘Increase Efficiency by Expanding SOC Functionality’
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #11 ‘Increase Efficiency by Expanding SOC Functionality’
Cyberattacks. Part 2: Advanced Techniques and Manipulations
Cyberattacks. Part 2: Advanced Techniques and Manipulations
Why and how to build data networks
Why and how to build data networks
Anatomy of visualisation. Part One: From Task to Execution
Anatomy of visualisation. Part One: From Task to Execution
DDoS attacks: what they are and how to protect against them
DDoS attacks: what they are and how to protect against them
How the technical side of data leakage protection is organised
How the technical side of data leakage protection is organised