20
BUSINESS USER MONITORING OBSERVEIT 5.8

BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

Embed Size (px)

Citation preview

Page 1: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

BUSINESS USER MONITORING OBSERVEIT 5.8

Page 2: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

Firewall

IDS

IAM

SIEM

Business Users IT Users

USERS ARE GATEWAYS OF RISK

Contractors

SystemsApps Data

Page 3: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

RISK = APPS+ USERS

Systems

Applications

Data

Maintain backend application systems, DBs, and infrastructure for business users

Risks• Remote Access• Configuration

Changes• Audit &

Compliance

IT Users

User variety of applications everyday to drive business

Risks• App Data

Extraction• Shadow IT • Audit &

Compliance

Business Users

Page 4: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

USER RISK LANDSCAPE

ContractorsBusiness Users ITApp Admins

Users

ManufacturingHealthcare

Banking Insurance

Energy

RetailApplications

IAM Firewalls SIEM

Infrastructure

DLPData

Page 5: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

BUSINESS USER

BUSINESS USER RISK

Source: Gartner 2013 Key IT Metrics Report 

IT USER

5% 95%

84% of Insider based breaches involve users with no admin rights

Page 6: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

ENTERPRISE SCALE FOR BUSINESS USER MONITORING Scale Storage and Performance Scale Management Security Automation Maintaining User Privacy

Page 7: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

ScaleSTORAGE AND PERFORMANCE

Page 8: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

IMPROVED PERFORMANCE

Over 10,000 concurrent users 1,500 screenshots per second 3,500 Unix system calls per second

Page 9: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

ScaleMANAGEMENT

Page 10: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

ADMIN DASHBOARDMini Dashboard – preview 

important stuff

See what is currently deployed Recent agents installed / 

uninstalled

Get status of critical services

Application Server status

Agent status:- Attempts to stop or kill- Offline, unreachable- Unregistered, uninstalled- Tampered with- Data loss

Page 11: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

MONITORED DEVICE LIST

Show agent status

Tampering and data loss indications

Flexible filters

Drill down to specific events

Page 12: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

EVENTS, AND NOTIFICATIONS

Large list of detailed events

Full support for Unix/Linux agent

Email notifications (per event, digest – similar to Alerts)

Integrate with SIEM via Monitor Log and API

Page 13: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

SECURITYAUTOMATION

User Context

SIEM IAMITSM

Page 14: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

EVENT AND ACTIVITY API

Real-time event and activity stream via Direct DB connection

Support all user activities, alerts and system events

Fully supported and documented API

Partners and integrators can provide additional value to customers

Page 15: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

MAINTAINING USER PRIVACY

Page 16: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

NEW PRIVACY CONTROLS

Secure audit of critical configuration changes

Detailed auditing reports the changes

Unable to view any recorded data

Can also manage ‘Configuration Admin’ users

Role for Configuration Only

Configuration Change Auditing

Page 17: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

ADDITIONAL ENHANCEMENTS

Page 18: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

ENHANCED RECORDING

Common way to transfer data on hosted servers

SFTP application agnostic

Can search, report and alert

Record SFTP

Time based recording, even without user activity

Now you also know what did the user sees

Configured via Server Policy

Continuous Recording

Page 19: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

NEW PLATFORMS

Solaris 11 RHEL/CentOS/Oracle Linux 5, 6

Support latest updates for:

SQL Server 2014 Citrix XenDesktop and Citrix XenApp 7.6 Amazon Linux Fedora 19, 20 RHEL/CentOS/Oracle Linux 7 SLES SuSE 12, Ubuntu 14.04

Post GA (5.8 SP1 and beyond)

Page 20: BUSINESS USER MONITORING OBSERVEIT 5.8. Firewall IDS IAM SIEM Business Users IT Users USERS ARE GATEWAYS OF RISK Contractors Systems AppsData

THANK YOU