My WebLink
|
Help
|
About
|
Sign Out
Home
Browse
Search
2022-02-28-minutes-it-study-session
>
Meetings
>
2022
>
03. March
>
2022-03-15 10:00 AM - Commissioners' Agenda
>
2022-02-28-minutes-it-study-session
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
3/10/2022 1:48:55 PM
Creation date
3/10/2022 1:47:06 PM
Metadata
Fields
Template:
Meeting
Date
3/15/2022
Meeting title
Commissioners' Agenda
Location
Commissioners' Auditorium
Address
205 West 5th Room 109 - Ellensburg
Meeting type
Regular
Meeting document type
Supporting documentation
Supplemental fields
Alpha Order
a
Item
Approve Minutes
Order
1
Placement
Consent Agenda
Row ID
87183
Type
Minutes
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
29
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
View images
View plain text
<br /> 2 <br />• Provide relevant provisioning documentation for Graph API <br />or MCAS <br /> <br />Each platform has unique data streams and CI has approved specific <br />data streams for ingest and monitoring. Data types not listed here may <br />not yet be approved. The following list details the CI-approved data <br />streams, which include but are not limited to (inquire for specifics as <br />needed): <br /> <br />• On-premises customers <br />• Specific Intrusion-detection event streams <br />• Specific Device, server, infrastructure, and application logs <br />• Continuous onsite packet collection for network segments <br />specified by Customer <br />• CI will generate flow records from collected packets <br />• CI ephemerally stores packets for a period limited by the <br />storage capacity of the customer’s chosen collectors <br />• Microsoft Defender (Azure Cloud and/or Endpoint) and MCAS <br />Customers <br />• Event streams, e.g. Graph API SecurityEvents or MCAS <br />(Required) <br />• AWS <br />• GuardDuty Event Streams (Required) <br />• CloudTrail Audit Logs (Required) <br />• VPC Flow Records <br />• WAF Logs <br /> <br /> <br />Managed <br />Detection and <br />Response <br />(CI-MDR) <br /> <br />Activation: <br />• On-Premises Collector Activation: <br />• Verify acquisition of NetFlow, named log sources, packet <br />capture <br />• Verify network scope of packet capture <br />• Verify transmission of event data and correct ingestion into <br />Critical Insight analytics engine <br />• Verify ability to perform extract of packet capture for <br />investigation <br />• AWS Activation: <br />• CloudTrail <br />• Customer verifies successful delivery of CloudTrail logs <br />into the accessible resource determined in provisioning
The URL can be used to link to this page
Your browser does not support the video tag.