Preventing the use of the syslog collection circuit by malware: A prerequisite for SOC collaboration.
SOC services should absolutely not be a pathway for malware intrusion. The adoption of secure measures is increasingly becoming a common practice.
EDR = "micro monitoring" of terminals, SIEM = "macro monitoring" of the entire organization, and SOC = a "team of people (command center)" that monitors, analyzes, and responds 24/365 using those tools. The issue is the "people" who monitor, analyze, and respond 24/365. To achieve zero trust, it is essential to continuously collect and analyze logs and monitoring data from each device, but if the information for system management cannot be sent to infrastructure engineers, it becomes hopeless to conduct detailed analysis consistently. Therefore, it is a natural progression to outsource to external specialized services. However, there is no difference in connecting to external services, and the question remains how to secure that connection. If breached, it could lead to catastrophic consequences... This is where the data diode "OWCD" comes into play! OWCD is perfect not only for the line that sends data to external SOC specialized services but also for the route that sends logs and monitoring data from OT to SIEM. It allows data to flow in only one direction. The adoption by infrastructure engineers is rapidly increasing. It has become indispensable for support services. SIers, if you want to promote cybersecurity, let's effectively utilize boundary control as well. There is a video explanation at the related link below! Feel free to contact us.
- 企業:MHIパワーエンジニアリング 高砂事業部
- 価格:1 million yen-5 million yen