Alert Logic Threat Manager With Activewatch: Solution Overview
Alert Logic Threat Manager With Activewatch: Solution Overview
WITH ACTIVEWATCH
DETECT AND RESPOND TO THREATS – FROM THE DATA CENTER TO THE CLOUD
Protecting your infrastructure requires you to detect threats, identify suspicious network traffic, and respond quickly –
whether the problem is in your own data center, a hosted environment or the cloud. How do you get a global view of the
threats impacting all of your infrastructure, day or night, without massive investments in multiple solutions and additional
staff?
Alert Logic Threat Manager with ActiveWatch Services gives you 24x7 network threat detection, monitored by Alert
Logic’s Security Operations Center (SOC), for the entire IT environment. Our patented expert system, driven by global
threat data, identifies potential problems for our analysts to investigate – acting as an extension of your team, day and
night, keeping an eye on suspicious activity.
We give you insight into the real threats in your environments, helping you make more informed security investment
and resource decisions. When the security program is driven by a clear understanding of the real threats affecting your
network, your efforts and investments will provide more benefit and significantly enhance your security posture.
ALER TLOGIC .COM / U.S. 877.4 8 4.83 83 / U.K . +4 4 (0) 203 011 5533
SOLU TION OV ER V IE W: A LER T LO GIC THR E AT M A N AGER W ITH AC TI V E WATCH
We help you meet compliance challenges. Threat Manager’s intrusion detection and vulnerability scanning capabilities
provide key elements to address the requirements of PCI DSS, HIPAA/HITECH, GLBA, Sarbanes-Oxley, and other
mandates. Compliance-specific reporting makes it easy to evaluate and document your compliance stance. Alert Logic
is a PCI-Approved Scanning Vendor (ASV).
You get these benefits without a large investment, staff burden or distractions from your strategic IT initiatives. Security-
as-a-Service delivery gives you Threat Manager with ActiveWatch for a fixed monthly fee, including all monitoring,
software and our 24x7 Security Operations Center (SOC) to validate incidents and provide support. You access your
Threat Manager data through a web interface – the very same one used by our analysts. There’s no complex integration
or implementation, no upgrades – just the latest security technology and the sharpest analysts, working for you 24 hours
a day, 7 days a week.
ALER TLOGIC .COM / U.S. 877.4 8 4.83 83 / U.K . +4 4 (0) 203 011 5533
SOLU TION OV ER V IE W: A LER T LO GIC THR E AT M A N AGER W ITH AC TI V E WATCH
1 2 3
In the protected environment, Threat Events are analyzed by Alert Logic’s Alert Logic security analysts investigate
Manager passively collects network expert system. Intelligent multifactor incidents and check for false positives.
traffic data and transports it to Alert correlation identifies suspicious
•• Valid incidents are escalated
Logic through SSL channels patterns of events, and creates
according to the customer’s
actionable incidents. requirements, and analysts work with
•• Physical appliance
customers to help remediate threats
•• Virtual Appliance
and attacks.
•• Agents with virtual tap
•• Real-time customer data from more •• IDS and vulnerability signatures •• Patented correlation engine based
than 2,500 customers on global view of threat data
•• Correlation rules
•• Alert Logic security and emerging •• Continuously analyzes millions
•• Remediation and resolution
threat research of data points into meaningful
documentation
intelligence
•• Third-party security information
•• Performance and accuracy tools
sources and feeds
ALER TLOGIC .COM / U.S. 877.4 8 4.83 83 / U.K . +4 4 (0) 203 011 5533
SOLU TION OV ER V IE W: A LER T LO GIC THR E AT M A N AGER W ITH AC TI V E WATCH
When an incident or suspicious network activity is detected, the ActiveWatch team will conduct an analysis of the situation
and notify your staff based on predetermined escalation procedures. They will work with your team to perform in-depth
analysis and assessment of the incident and recommend containment and mitigation actions.
ActiveWatch also includes integrated incident and case management capabilities that allow customers to track and
report on incident trends across their entire enterprise, including the services hosted outside of the internal perimeter.
This capability provides an audit trail of suspicious findings and gives a historical record of the response and actions from
start to finish.
Additional services, including daily review by a senior security analyst, weekly reporting on security posture based on
business goals, and review of NetFlow for enhanced detection of malware and advanced persistent threats are also
available.
ALER TLOGIC .COM / U.S. 877.4 8 4.83 83 / U.K . +4 4 (0) 203 011 5533
SOLU TION OV ER V IE W: A LER T LO GIC THR E AT M A N AGER W ITH AC TI V E WATCH
ALER TLOGIC .COM / U.S. 877.4 8 4.83 83 / U.K . +4 4 (0) 203 011 5533
SOLU TION OV ER V IE W: A LER T LO GIC THR E AT M A N AGER W ITH AC TI V E WATCH
© 2015 Alert Logic, Inc. All rights reserved. Alert Logic and the Alert Logic logo are trademarks, registered trademarks, or
servicemarks of Alert Logic, Inc. All other trademarks listed in this document are the property of their respective owners.
03 0315US