跳到主内容
Microsoft
separator
https://store-images.s-microsoft.com/image/apps.51442.ed6dc71d-6d26-4053-a40b-9b88399b4fbe.9d1ba8d5-f777-4832-96c4-9011f4b94af4.d76abad8-617a-4154-a6db-0fdb97914016

User Shield: 4-Wk Implementation

Long View Systems

User Shield leverages Microsoft’s Sentinel SIEM technology combined with Long View’s 24x7 Security Operations Center (SOC) to secure not only your Microsoft cloud ecosystem, including (Office 365, OneDrive, Teams, Azure, Microsoft 365 Defender) and your on-prem environment and SaaS applications.

USER SHIELD DEPLOYMENT

Our SOC experts will professionally setup Sentinel in your Azure workspace including deployment of our proven expert rulesets & automated playbooks that will automatically respond to threats & other suspicious activities including workstation or user quarantine in near real-time.

Your company’s system administrators will be notified while our 24x7 SOC triages to provide you the best course of action for remediation. Automations can be leveraged to trigger playbooks developed by Long View to quarantine or suspend users access during malicious behavior. (Specific licenses are required). Other threats may require triage by Long View’s skilled SOC team, which is achieved via a connection to the clients’ tenant leveraging Azure Lighthouse.

ACTIVITIES & OUTCOMES

           
  • Turn on Microsoft Sentinel in Client workspace.
  •        
  • Apply initial Long View Custom Rule Sets & Long View Custom Playbooks. Add or modify Custom Rule Sets & Custom Playbooks as new threats are discovered.
  •        
  • The Long View SOC monitors client’s instance of Sentinel as oversight and triages alarms, validates successful automation & ensure Client notification &/or Client intervention when required.
  •        
  • Maintain Client specific Security Escalation Document. (SED)
  •        
  • Document & record all Security incidents in accordance with Long View Integrated Global Services best practices.
  •        
  • Provide Client monthly report of security incidents & actions as evidence of Sentinel automation, SOC & Client interventions.
  •        
  • Monitoring scope includes Azure Active Directory logs & sign-ins, Office 365 logging & Threat Intelligence Indicators. Third party connectors and server coverage are available for an additional cost. (Firewalls/Switches/Wireless controllers, etc.)
  •    

概览

https://store-images.s-microsoft.com/image/apps.17486.ed6dc71d-6d26-4053-a40b-9b88399b4fbe.9d1ba8d5-f777-4832-96c4-9011f4b94af4.d822425c-2011-4b94-9a47-6d33bcf29cbb
中文(中国)
你的隐私选择选择退出图标 你的隐私选择
消费者健康隐私 站点地图 Contact Us 隐私和 Cookie 使用条款 关于我们的广告 管理 Cookie