“It’s no secret that IT and security professionals are overloaded with privilege, vulnerability and attack information,” said Brad Hibbert, vice president, product strategy and operations, BeyondTrust. “With today’s announcement of threat analytics as a part of the BeyondInsight console, we’re enabling IT and security teams to spotlight those risky users and assets that were previously overlooked. BeyondTrust strives to stay a step ahead of competitors by delivering innovative technologies that combat issues as they arise, rather than after the damage is done.”
Advanced persistent threats (APTs) often go undetected because traditional security analytics solutions are unable to correlate diverse data to discern hidden risks. Seemingly isolated events are often written off as exceptions, filtered out, or lost altogether in a sea of data. The intruder continues to traverse the network, and the damage continues to multiply.
With BeyondInsight Clarity, IT and security leaders quickly cut through data overload to identify their organizations’ most critical risks. The solution automatically taps into a rich database of information from company desktops and servers to set baselines for normal behavior, observe changes, and identify anomalies that signal critical threats. This database, part of BeyondInsight v 5.4, is comprised of feeds from a variety of privilege and vulnerability management solutions, including:
· PowerBroker for Windows: user and account activity data from desktops and servers
· PowerBroker for UNIX & Linux: user and account activity from servers
· PowerBroker Endpoint Protection Platform: IPS, IDS, anti-virus and firewall log data
· Retina CS Enterprise Vulnerability Management and a variety of third-party vulnerability scanning solutions: asset vulnerability data
With the BeyondInsight management, reporting and analytics console, IT and security teams have a single, contextual lens through which to view and address user and asset risk. Additional new features in BeyondInsight v5.4 include:
· BeyondTrust PowerBroker® Password Safe management updates, including expanded platform support, plus filtering and API enhancements
· Reporting support for NIST 800-53 Revision 4 and PCI Data Security Standard (DSS) 3.0
· Threat Intelligence Connector for ServiceNow®, which imports BeyondTrust Retina vulnerability data, launches Retina vulnerability scans, and generates incident response tickets in ServiceNow service automation solutions