Azure Sentinel: 3 day implementation

Sulava Oy

Planning and implementing the Cloud-native Security Information and Event Management system (SIEM) Azure Sentinel

HOW:

Preparation call

  • Define full scope & align expectations
  • Schedule the work & plan attendees
  • Technical pre-requisites check

Workshop day 1:

  • Planning the role of Azure Sentinel in customer’s current security architecture & pricing review
  • Provisioning Azure Sentinel in customer’s Azure environment
  • Connecting available Microsoft cloud log sources
  • Defining log retention policy
  • Defining admin access to logs

Workshop day 2:

  • Configuring sample alerts in Sentinel Analytics
  • Walkthrough of utilizing detect / investigate / respond functionality
  • Creating a plan for connecting additional sources: on-premises servers, firewalls, 3rd party services etc. & Improving detection & response capability

DELIVERABLES:

  • Sentinel workspace provisioned
  • Long-term storage for Microsoft cloud log sources
  • Understanding for Sentinels basic operations
  • Capability for detecting & investigating anomalies
  • Plan & roadmap for integrating other log sources and improving detect & response capabilities
https://store-images.s-microsoft.com/image/apps.48521.73a4357b-2f1c-496b-8e55-a5996fbe19bd.4c8855cd-0a54-4dd6-8926-c73f3c8d0b86.1f07c7d6-0815-4e3b-bc39-66a178db8502
https://store-images.s-microsoft.com/image/apps.48521.73a4357b-2f1c-496b-8e55-a5996fbe19bd.4c8855cd-0a54-4dd6-8926-c73f3c8d0b86.1f07c7d6-0815-4e3b-bc39-66a178db8502
https://store-images.s-microsoft.com/image/apps.5349.73a4357b-2f1c-496b-8e55-a5996fbe19bd.4c8855cd-0a54-4dd6-8926-c73f3c8d0b86.8f5fc2e8-b1c0-4af8-80d9-53b2e8a6537a