AIS Managed SIEM
A cloud-based Security Information and Event Management (SIEM) platform that provides the proactive monitoring and technology you need to secure workstations, servers, devices, and networks — including business-grade antivirus and anti-malware threat intelligence, web content filtering, firewall rule review, vulnerability patching, and inbound/outbound email security.
Technology has transformed what’s possible for today’s small and medium-sized organizations, but it also increases exposure to potential security risks. The AIS Managed SIEM (Security Information Event Management) platform changes all that with enterprise-level, cost-effective protection for SMBs.
The AIS Managed SIEM (Security Information Event Management) Platform supports threat detection and security incident response through real-time collection and historical analysis of security events from a wide variety of event and contextual data sources. It provides real time analysis of security alerts generated by network-connected devices and on-premise, Cloud, and SaaS applications.
Why AIS Managed SIEM is different
1
Delivery
The SIEM can be delivered solely as a managed SIEM platform or as a turnkey managed service. AIS’ IT consultants can implement, configure, and maintain the SIEM, while its SOC team can monitor and respond to security alerts.
2
Technology
The platform architecture utilizes both proprietary code and open-source packages, allowing for efficient development that results in faster-to-market functionality and more robust product features.
3
Integration
AIS Managed SIEM is agnostic in terms of device brand and infrastructure architecture. It can aggregate information from network-connected devices as well as on-premise, cloud (AWS, Azure, etc.), and third-party SaaS tools, or even hybrid infrastructure architectures.
Features
- Reduce costs and internal IT resource strain with an affordable, turnkey managed service that speeds up root-cause analysis for security, performance, and reliability issues
- Proactively manage evolving threats across all devices and platforms
- Increase ROI by maximizing the value of security investments and identifying cloud cost-savings opportunities
- Reduce audit effort and expense for PCI, HIPAA, and other compliance standards
- Get a single portal for centralized security and event log collection, monitoring, analysis, and alerting
- Aggregate data across brands and architectures — on-premise, cloud, third-party SaaS, and hybrid environments
- Grant granular, role-based permissions to specific users
- Collaborate seamlessly with AIS or your own vendors on escalation support
- Choose a managed SIEM platform alone, or pair it with a fully managed SOC (Security Operations Center)
- Reduce the implementation effort and ongoing work of keeping alerting conditions up to date
- Rely on a dedicated response team to act on alerts and threats so your IT staff doesn't have to
- Take advantage of flexible, tiered response options
- Start from dashboards and alerting configured to best-practice guidelines, then customize to your needs
- Identify device configuration changes and errors
- Monitor security audit logs to detect unauthorized access attempts
- Apply robust security policy controls
- Use real-time, automated, and custom alerting and dashboard capabilities
- Alert on standard and custom conditions (for example, Office 365 logins from outside the United States)
- View real-time and historical status at a glance from web dashboards
Benefits
- Provided as an affordable, turnkey managed service
- Automated alerts sent via flexible channels — text message, email, Slack, and more
- Proactively manages evolving threats
- Closes the gap between perceived and actual security
- Maximizes the value of security investments
- Frees IT staff to focus on business priorities
- Provides single-pane-of-glass visibility across all devices
- Reduces audit effort and expense for PCI, HIPAA, and other standards
- Gives you access to security professionals and expertise
- Anomalous Logins
- Compromised Passwords
- Accidentally Deleted Emails
- Proprietary Applications Security
- Unauthorized 3rd Party Application Detection
- SIEM Office 365 Alerts
- SIEM Windows Event Log Alerts
- SIEM Firewall Alerts
- SIEM Syslog Alerts
- Windows File Modification Monitoring
- Server SSH Key Access Monitoring
- SIEM — Microsoft Events to Monitor
- Windows — Application Whitelisting
- Windows — Application Crashes
- Windows — System or Service Failures
- Windows — Windows Update Errors
- Windows — Windows Firewall
- Windows — Clearing Event Logs
- Windows — Software and Service Installation
- Windows — Account Usage
- Windows — Kernel Driver Signing
- Windows — Group Policy Errors
- Windows — Defender Activity Monitoring
- Windows — Mobile Device Activities
- Windows — External Media Detection
- Windows — Printing Services
- Windows — Pass the Hash Detection
- Windows — Remote Desktop Logon Detection
- Windows — DNS/Directory Services
- Windows — PowerShell Activities
- Windows — Task Scheduler Activities
- Windows — Microsoft Cryptography API
- Windows — Certificate Services
- Windows — Network Policy
- Windows — Boot Events
- Windows — System Integrity
- Service Log Consolidation
- Threat Actor Device Fingerprints
- Financial Analysis of IT Solutions Ingest Logs from IT Business Solutions (Cloudflare) being used in your environment and Turn Data into Actionable tasks- The SIEM can ingest logs and data from other data sources/solutions and give IT Departments insight and the ability to make data backed decisions around cost removing uncertainty.
- Business Intellectual Property Data Loss Prevention/Information Lockdown- The SIEM can detect if files are being exported/imported instead of being stored where the information security policy dictates.
Example Project Plan
Implementation
- Alert conditions and configuration
- Alert and Dashboard Review Meeting
- Customize Grok Patterns to ensure fields are extracted properly
Discovery
- SIEM Requirements Gathering
Validation
- Customer Diligence — AIS SIEM Compliance Docs
Recurring — Quarterly
- Review customer specific alerting criteria
- Quarterly Meeting
Recurring — Ongoing/As Needed
- Alert triage — False positive identification, correlation and escalation
- Verified incident reporting – Threat explanation, criticality evidence, affected assets/users, remediation next steps
Recurring — Monthly
- Monthly Meeting — Alert activity review
Recurring Tasks
- Review customer specific alerting criteria
- Alert triage — False positive identification, correlation and escalation
- Verified incident reporting – Threat explanation, criticality evidence, affected assets/users, remediation next steps
- Monthly Meeting — Alert activity review
- Quarterly Meeting