FortiSIEM Overview - Exclusive Networks

36
FortiSIEM Overview La soluzione Fortinet alla gestione degli eventi e delle informazioni sulla sicurezza Piero Provenza System Engineer Exclusive Networks

Transcript of FortiSIEM Overview - Exclusive Networks

Page 1: FortiSIEM Overview - Exclusive Networks

FortiSIEM Overview

La soluzione Fortinet alla gestione degli eventi e delle informazioni sulla sicurezza

Piero ProvenzaSystem Engineer – Exclusive Networks

Page 2: FortiSIEM Overview - Exclusive Networks

FortiSIEM Overview Architecture Configuration Management DB (CMDB) Dashboard, Analytics & Reporting Vulnerabilities and Risks Customizing to Your Environment Incident Investigation & Remediation

Agenda

Page 3: FortiSIEM Overview - Exclusive Networks

FortiSIEM Overview

Page 4: FortiSIEM Overview - Exclusive Networks

What is SIEM

Page 5: FortiSIEM Overview - Exclusive Networks

The Goal To detect threats and breaches sooner Provide deep context for root causes Supply information for remediation and prevention

Primary data analysis tasks Indexing, searching, correlating, user ID/location, baseline

Logs Syslog, SNMP Traps, WMI, Netflow

Other Agent-less, Agents, Windows Agents

How SIEM Works

Page 6: FortiSIEM Overview - Exclusive Networks

FortiSIEM Key Features Overview

Page 7: FortiSIEM Overview - Exclusive Networks

Unified NOC & SOC – Single Pane of Glass

Page 8: FortiSIEM Overview - Exclusive Networks

Architecture

Page 9: FortiSIEM Overview - Exclusive Networks

Main Components

Page 10: FortiSIEM Overview - Exclusive Networks

Architecture

Page 11: FortiSIEM Overview - Exclusive Networks

FortiSIEM – Physical and Virtual

Page 12: FortiSIEM Overview - Exclusive Networks

FortiSIEM - Scenarios

Page 13: FortiSIEM Overview - Exclusive Networks

Configuration ManangementData Base (CMDB)

Page 14: FortiSIEM Overview - Exclusive Networks

FortiSIEM Discovery

Page 15: FortiSIEM Overview - Exclusive Networks

FortiSIEM Logs Collection

Page 16: FortiSIEM Overview - Exclusive Networks

FortiSIEM CMDB Summary

Page 17: FortiSIEM Overview - Exclusive Networks

After Discovery

Page 18: FortiSIEM Overview - Exclusive Networks

After Discovery – Collection Templates Applied

Page 19: FortiSIEM Overview - Exclusive Networks

CMDB Performance and Availability Monitoring

Page 20: FortiSIEM Overview - Exclusive Networks

CMDB Business Services

Page 21: FortiSIEM Overview - Exclusive Networks

Dashboard, Analytics & Reporting

Page 22: FortiSIEM Overview - Exclusive Networks

Dashboards

Page 23: FortiSIEM Overview - Exclusive Networks

FortiSIEM Analytics

Page 24: FortiSIEM Overview - Exclusive Networks

Reporting

Page 25: FortiSIEM Overview - Exclusive Networks

Vulnerabilities and Risks

Page 26: FortiSIEM Overview - Exclusive Networks

Vulnerability Scanner Integration

Page 27: FortiSIEM Overview - Exclusive Networks

FortiSIEM Risk Dashboard and Host Risk Score

Page 28: FortiSIEM Overview - Exclusive Networks

Customizing to Your Environment

Page 29: FortiSIEM Overview - Exclusive Networks

Extensible and Customizable

Page 30: FortiSIEM Overview - Exclusive Networks

Incident Investigation & Remediation

Page 31: FortiSIEM Overview - Exclusive Networks

FortiSIEM Incident Investigation and Response

Page 32: FortiSIEM Overview - Exclusive Networks

FortiSIEM Incident Remediation

Page 33: FortiSIEM Overview - Exclusive Networks

Summary – Benefits to Your Environment

Page 34: FortiSIEM Overview - Exclusive Networks

PowerLAB & Prossimi EventiExclusive Networks

Page 35: FortiSIEM Overview - Exclusive Networks

PowerLAB Torino – Network Layout

Page 36: FortiSIEM Overview - Exclusive Networks

Thank you!

Piero [email protected]