The Approach & Advantages
Security Event Monitoring
BT Counterpane's Managed Security Monitoring (MSM) plus Verano's Industrial Defender (ID) provides a single plant-centric system and user interface for multiple layers of real-time cyber-security and performance monitoring. It monitors multi-vendor control systems, industrial applications, real-time networks and perimeter firewalls.
Once a potential incident is detected, MSM+ID notifies and alerts authorized personnel through phone, secure browser, email, pagers, and Internet enabled devices. For the ultimate protection, ID allows perimeter security settings to be pre-defined and rapidly adjusted according to threat level. For centralized security policy management and forensics purposes, it centralizes all security log information from existing control systems and offers comprehensive real-time and historical reporting.
Perimeter Protection
MSM+ID provide a simple means of complete protection at the real-time system network perimeter from a vast array of attacks. This comprehensive security appliance provides anti-virus filtering at the firewall level, secure remote communication through a VPN gateway, and detection and prevention of malicious attacks before they enter the network. All security events and statistics detected by MSM+ID are reported through the Industrial Defender console and BT Counterpane's web portal, providing a single operator interface.
The Approach and its Advantages
An important advantage of BT Counterpane's approach is its passive nature. The customer retains full control over what is, and is not, submitted to BT Counterpane's systems for security review. Sensitive information, such as customer-identifying transaction records, can be demonstrably excluded so no risk of data leakage is present. By the same token, any message the customer explicitly wants to include in the security program can be classified to any severity level.
The key, from the security officer's point of view, is that these capabilities are available for any device, on any part of the network. Enterprise-wide policies can be monitored and enforced via BT Counterpane Managed Security Services, whether on a private specialty network, or a general-purpose corporate network, and tangible metrics of security performance and compliance are available to measure everything from incident response parameters to technology effectiveness to staff escalations.
Managed Security Services are valuable not just because they can detect an attack in progress, but more importantly, they contribute to an ongoing program of security improvements which ensure the customer benefits from proactive advice. This is particularly helpful in the case of zero-day exploits where a reactive posture, by definition, can't work. The difference between a painful zero-day experience, and an inconsequential one, is how comfortably the targeted organization responds.
Managed Security Services help customers prepare for audits. Taken together, the raw data and prepared reports provide a centralized record of performance data from various security controls, and reduce the amount of time auditors must spend simply uncovering historical records.
|