SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Security Vision's ‘Chips’: working together

Security Vision's ‘Chips’: working together
06.02.2023


  |  Listen on Google Podcasts  |   Listen on Mave  |   Listen on Yandex Music  |  


Roman Dushkov, Security Vision


We continue publishing the series ‘Security Vision “Features”’, which is aimed at introducing you to interesting solutions in our products. We have dedicated this article to the peculiarities of the functionality that enables collaborative work in Security Vision.


Ability to manage tasks, your own HelpDesk in the Security Vision interface



The functionality allows you to monitor the progress of tasks, set tasks to different accounts that are stored in Security Vision. Also the ability to integrate with external ITSM systems (if they exist on the customer's side) with ‘pulling’ tasks into Security Vision allows you to more accurately monitor and aggregate the entire scope of tasks.


Granular customisation of access rights and visibility even for individual properties



For collaboration and simplified support from IT departments, it is important to reduce the number of interfaces and points of failure, without forgetting the proper delineation of the capabilities of all user groups. At the same time, it is important to maintain a variety of roles and not to limit the company's ability to create them (including licensing).


A special designer of role model and menu appearance in Security Vision platform supports not only differentiation of access to individual tabs, but also point assignment of rights. Thus, the role model of a risk manager, auditor, IT specialist and several incident response teams can be configured in detail: read, write and modification, management and administration rights can be set for different blocks and individual properties.


Print schematics and workflows on any size of paper for brainstorming sessions



Workflows in companies evolve and ‘live’ for a long time, so for adaptation it is possible to organise separate meetings to organise the evolution of business processes. According to our customers' experience, it can be convenient to make such brainstorms by simply drawing on top of already created processes.


For this purpose, the platform supports export of flowcharts as pictures or direct printing using a printer-friendly interface.

Recommended

MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #5: Prioritise response to cyber incidents
MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #5: Prioritise response to cyber incidents
ChatGPT in IS - on the dark side and the light side
ChatGPT in IS - on the dark side and the light side
Open software supply chain attack reference (OSC&R)
Open software supply chain attack reference (OSC&R)
IDE for development of no-code security features
IDE for development of no-code security features
Information security trends. Part 3
Information security trends. Part 3
Features of the new versions of UEBA and Anomaly Detection products on the Security Vision 5 platform
Features of the new versions of UEBA and Anomaly Detection products on the Security Vision 5 platform
IRP/SOAR by law. GIS, PDN, GOST project
IRP/SOAR by law. GIS, PDN, GOST project
Review of NIST Publication SP 800-128 "Guide for Security-Focused Configuration Management of Information Systems"
Review of NIST Publication SP 800-128 "Guide for Security-Focused Configuration Management of Information Systems"
Protecting web applications: anti-DDoS
Protecting web applications: anti-DDoS
Role-based security model and its differences from the attribute-based access control model
Role-based security model and its differences from the attribute-based access control model
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #4 ‘Recruit and Retain Qualified Employees’
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #4 ‘Recruit and Retain Qualified Employees’
Situational awareness in cyber security
Situational awareness in cyber security

Recommended

MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #5: Prioritise response to cyber incidents
MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #5: Prioritise response to cyber incidents
ChatGPT in IS - on the dark side and the light side
ChatGPT in IS - on the dark side and the light side
Open software supply chain attack reference (OSC&R)
Open software supply chain attack reference (OSC&R)
IDE for development of no-code security features
IDE for development of no-code security features
Information security trends. Part 3
Information security trends. Part 3
Features of the new versions of UEBA and Anomaly Detection products on the Security Vision 5 platform
Features of the new versions of UEBA and Anomaly Detection products on the Security Vision 5 platform
IRP/SOAR by law. GIS, PDN, GOST project
IRP/SOAR by law. GIS, PDN, GOST project
Review of NIST Publication SP 800-128 "Guide for Security-Focused Configuration Management of Information Systems"
Review of NIST Publication SP 800-128 "Guide for Security-Focused Configuration Management of Information Systems"
Protecting web applications: anti-DDoS
Protecting web applications: anti-DDoS
Role-based security model and its differences from the attribute-based access control model
Role-based security model and its differences from the attribute-based access control model
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #4 ‘Recruit and Retain Qualified Employees’
MITRE publication ‘11 Strategies for a World-Class SOC Centre’. Strategy #4 ‘Recruit and Retain Qualified Employees’
Situational awareness in cyber security
Situational awareness in cyber security

Other articles

Review of the publication NIST SP 800-47 Rev. 1 "Managing the Security of Information Exchanges"
Review of the publication NIST SP 800-47 Rev. 1 "Managing the Security of Information Exchanges"
Access control and user identification. IDM systems
Access control and user identification. IDM systems
IRP/SOAR by law. CII
IRP/SOAR by law. CII
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
IDE for development of no-code security features
IDE for development of no-code security features
MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #8 ‘Use automation tools to support the work of SOC analysts’
MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #8 ‘Use automation tools to support the work of SOC analysts’
The ethical hacker and his role in security
The ethical hacker and his role in security
Static analysis of source code
Static analysis of source code

Other articles

Review of the publication NIST SP 800-47 Rev. 1 "Managing the Security of Information Exchanges"
Review of the publication NIST SP 800-47 Rev. 1 "Managing the Security of Information Exchanges"
Access control and user identification. IDM systems
Access control and user identification. IDM systems
IRP/SOAR by law. CII
IRP/SOAR by law. CII
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Review of NIST Publication SP 800-61 "Computer Security Incident Handling Guide". Part 2
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
Dynamic IRP/SOAR 2.0 playbooks on the Security Vision 5 platform
IDE for development of no-code security features
IDE for development of no-code security features
MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #8 ‘Use automation tools to support the work of SOC analysts’
MITRE publication ‘11 World-Class SOC Centre Strategies’. Strategy #8 ‘Use automation tools to support the work of SOC analysts’
The ethical hacker and his role in security
The ethical hacker and his role in security
Static analysis of source code
Static analysis of source code