Preventing the use of Syslog collection circuits by malware: A prerequisite for SOC collaboration.
SOC services should absolutely not be a pathway for malware intrusion. The adoption of secure measures is increasingly becoming common.
EDR = "micro monitoring" of terminals, SIEM = "macro monitoring" of the entire organization, and SOC = a "human team (command center)" that monitors, analyzes, and responds 24/365 using those tools. The issue is the "people" who monitor, analyze, and respond 24/365. To realize zero trust, it is essential to continuously collect and analyze logs and monitoring data from each device, but if the information for system management cannot be sent to infrastructure engineers, it becomes hopeless to conduct detailed analysis consistently. Therefore, it is a natural progression to outsource to external specialized services. However, there is no difference in connecting to external services, and the question is how to secure it; if an intrusion occurs here, it could be catastrophic... This is where the data diode "OWCD" comes into play! In addition to its use for sending data to external SOC specialized services, OWCD is also perfect for sending logs and monitoring data from OT to SIEM. It can only allow one-way flow. The adoption by infrastructure engineers is rapidly increasing. It has become essential for support services. For SIers, if you want to promote cybersecurity, let's effectively utilize boundary control as well. There is a video explanation at the related link below! Feel free to contact us.
- Company:MHIパワーエンジニアリング 高砂事業部
- Price:1 million yen-5 million yen