SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Security Vision's ‘features’: general

Security Vision's ‘features’: general
23.01.2023


  |  Listen on Google Podcasts  |   Listen on Mave  |   Listen on Yandex Music  |  


Roman Dushkov, Security Vision


We are starting the publication of the ‘Security Vision “Features”’ series to introduce you to interesting solutions in our products that allow you to solve actual tasks as efficiently as possible. The first article is devoted to the general aspects of the platform.


Initially a single product and interconnection of any objects



When using different products, there is a need to switch between their interfaces. Security Vision has solved this problem by organising a single database where all objects are interconnected. Now there is no need to go to other sections, search to get the required content.


This feature allows the SOC operator to get deeper analytics on the asset to which an incident or vulnerability is related, and immediately proceed to its classification and risk assessment.


Adaptable to any architecture and ready to handle the load



There are two main options for implementing a distributed cluster:


1. Main server in the centre + remote connector services are installed, through which data collection and remote interaction with target systems takes place.


2. Several full-fledged installations, between which synchronisation via API is configured.


This allows to distribute the load between data streams and organise a large-scale SOC with geo-distributed infrastructure. Specific connector and data processing services also scale to run 500-1000 workflows in parallel.


Parsing large volumes of JSON and XML data formats



Typically, when analysing large data volumes, software products require more RAM and CPU speed. The Security Vision platform does not overestimate hardware requirements, having built the ability to parse large files piece by piece.


This allows you to work with large vulnerability reports or just large files with useful information without ‘brakes’ and the need to purchase hardware in the process of operation.


Granular cleansing of old data



The characteristics of hardware or virtual machine parameters on which IT and IS systems are deployed may change over time, so it is important to use not only modern architectures (separate separate processes or duplicate modules), but also to manage persistent memory utilisation in order to adapt.


The Security Vision platform allows not only to manage the database using built-in or external DBMS (e.g. hot backup in PosgreeSQL), but also to clean up old data directly in the platform settings, with rules customised for different types of objects, processes, logs and reports.

information security SOAR SGRC

Recommended

The ethical hacker and his role in security
The ethical hacker and his role in security
Webinars on object, menu and role builders on the Security Vision platform
Webinars on object, menu and role builders on the Security Vision platform
Threat analysis and cyber intelligence: what problems the updated Security Vision TIP solves
Threat analysis and cyber intelligence: what problems the updated Security Vision TIP solves
MITRE: followers and antagonists
MITRE: followers and antagonists
Darknet - what it is, how criminals use it, what to watch out for
Darknet - what it is, how criminals use it, what to watch out for
Cyberattacks. Part 1: Technical Tools and Implementation Techniques
Cyberattacks. Part 1: Technical Tools and Implementation Techniques
Enterprise information security policy - example and tips for development
Enterprise information security policy - example and tips for development
Static analysis of source code
Static analysis of source code
What is an authentication factor, why do you need a second one and how many are there in total
What is an authentication factor, why do you need a second one and how many are there in total
FSTEC Threat Model
FSTEC Threat Model
Current cybersecurity trends in 2021
Current cybersecurity trends in 2021
Information security tools overview: endpoint protection
Information security tools overview: endpoint protection

Recommended

The ethical hacker and his role in security
The ethical hacker and his role in security
Webinars on object, menu and role builders on the Security Vision platform
Webinars on object, menu and role builders on the Security Vision platform
Threat analysis and cyber intelligence: what problems the updated Security Vision TIP solves
Threat analysis and cyber intelligence: what problems the updated Security Vision TIP solves
MITRE: followers and antagonists
MITRE: followers and antagonists
Darknet - what it is, how criminals use it, what to watch out for
Darknet - what it is, how criminals use it, what to watch out for
Cyberattacks. Part 1: Technical Tools and Implementation Techniques
Cyberattacks. Part 1: Technical Tools and Implementation Techniques
Enterprise information security policy - example and tips for development
Enterprise information security policy - example and tips for development
Static analysis of source code
Static analysis of source code
What is an authentication factor, why do you need a second one and how many are there in total
What is an authentication factor, why do you need a second one and how many are there in total
FSTEC Threat Model
FSTEC Threat Model
Current cybersecurity trends in 2021
Current cybersecurity trends in 2021
Information security tools overview: endpoint protection
Information security tools overview: endpoint protection

Other articles

Information security trends. Part 3
Information security trends. Part 3
Review of NIST Publication SP 800-124 Rev. 2 (Draft) "Guidelines for Managing the Security of Mobile Devices in the Enterprise"
Review of NIST Publication SP 800-124 Rev. 2 (Draft) "Guidelines for Managing the Security of Mobile Devices in the Enterprise"
Don't trust and check seven times: how Zero Trust works
Don't trust and check seven times: how Zero Trust works
Protecting web applications: anti-DDoS
Protecting web applications: anti-DDoS
Directory of Information Security Legislation of the Russian Federation
Directory of Information Security Legislation of the Russian Federation
The Three Elephants of Windows Logging
The Three Elephants of Windows Logging
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
SGRC by law. KII
SGRC by law. KII
A summary of NIST's special publications on information security. Part 1
A summary of NIST's special publications on information security. Part 1

Other articles

Information security trends. Part 3
Information security trends. Part 3
Review of NIST Publication SP 800-124 Rev. 2 (Draft) "Guidelines for Managing the Security of Mobile Devices in the Enterprise"
Review of NIST Publication SP 800-124 Rev. 2 (Draft) "Guidelines for Managing the Security of Mobile Devices in the Enterprise"
Don't trust and check seven times: how Zero Trust works
Don't trust and check seven times: how Zero Trust works
Protecting web applications: anti-DDoS
Protecting web applications: anti-DDoS
Directory of Information Security Legislation of the Russian Federation
Directory of Information Security Legislation of the Russian Federation
The Three Elephants of Windows Logging
The Three Elephants of Windows Logging
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
Measuring the effectiveness of cybersecurity processes. IS metrics. Part 3
SGRC by law. KII
SGRC by law. KII
A summary of NIST's special publications on information security. Part 1
A summary of NIST's special publications on information security. Part 1