
Implementing ConnectWise SIEM involves a structured process designed to ensure effective deployment and integration. The typical implementation stages are:
Onboarding
Service Delivery Coordination: A coordinator guides you through initial setup, including completing required documentation and configuring your server.
Scheduling: Arrange meetings between your administrator and a ConnectWise consultant to plan the implementation.
Implementation
Configuration Sessions: The consultant presents an implementation plan and conducts sessions to configure the SIEM solution tailored to your environment.
User Acceptance Testing: Your team reviews the setup and performs testing to ensure the system meets your requirements.
Go Live
Rollout Support: The consultant assists with the software rollout, addressing any questions and providing support during the transition.
ConnectWise SIEM offers extensive customization capabilities to align with specific business requirements, ensuring a tailored security management experience. Key customization features include:
Custom Event Notifications: Administrators can set up personalized event notifications for any event type logged within ConnectWise SIEM, enabling prompt responses to incidents pertinent to their environment.
Dashboard Personalization: Users have the flexibility to utilize pre-made dashboards or create their own, facilitating focused monitoring and management of security events relevant to their operations.
Enhanced Alerting: The platform allows for the identification of patterns of suspicious activity across multiple sources through pre-configured or custom rules and sequences, enhancing threat detection and response.
Perchybana Integration: ConnectWise SIEM integrates with Perchybana, enabling users to search, view, and interact with data stores for all traffic records and logs collected by the SIEM, thereby facilitating in-depth data analysis.
Marketplace Access: The platform provides access to a marketplace where users can install dashboards, visualizations, event notifications, and saved searches created by the ConnectWise SIEM community, promoting collaborative enhancement and customization.
ConnectWise SIEM offers a suite of training and support resources to assist new users in effectively deploying and managing the platform. These resources are designed to cater to various learning preferences and ensure users can maximize the platform's capabilities.
Training Resources:
ConnectWise Certify: This program provides a variety of role-based training courses and certification programs aimed at enhancing users' understanding of technology solution provider (TSP) best practices and the ConnectWise platform. These on-demand courses allow users to learn at their own pace, offering flexibility to accommodate different schedules.
On-Demand Demos: ConnectWise offers on-demand demonstrations, such as the Co-Managed SIEM Security Demo, which provide insights into key security features and functionalities of the SIEM platform. These demos are designed to help users familiarize themselves with the system's capabilities and operational workflows.
Support Resources:
Documentation: Comprehensive online documentation is available, offering detailed information on product features, functionality, and step-by-step guides to assist users in navigating and utilizing the platform effectively.
Community Forums: ConnectWise maintains an active virtual community where users can engage with peers, share experiences, and seek advice. This collaborative environment fosters knowledge exchange and problem-solving among users.
ConnectWise SIEM implements a comprehensive suite of security measures to safeguard data and ensure robust threat detection and response. Key security features include:
1. Multi-Tenancy: Designed for Managed Service Providers (MSPs), the platform supports multi-tenant environments, enabling centralized management of security alerts across multiple clients from a single, unified interface.
2. Advanced Threat Detection and Response:
Integrates a built-in network-based Intrusion Detection System (IDS) to monitor network traffic for suspicious activities, providing real-time threat detection.
Employs automated incident response mechanisms to swiftly address identified threats, minimizing potential damage.
3. Comprehensive Log Management: Aggregates and retains logs from diverse sources, including syslog and Windows Event Logs, facilitating compliance reporting and forensic analysis.
4. Threat Intelligence Integration:
Utilizes MSP-specific threat intelligence feeds to stay updated on emerging threats, enhancing the platform's ability to detect and respond to new vulnerabilities.
5. Data Encryption and Access Control:
Implements data encryption protocols to protect sensitive information during transmission and storage.
Enforces role-based access control, ensuring that only authorized personnel have access to specific data and functionalities.
6. Compliance Support: Offers features like flexible log capture, retention, and review, enabling organizations to generate compliance reports and adhere to regulatory requirements such as HIPAA and PCI-DSS.
ConnectWise SIEM maintains a clear stance on data ownership and portability, emphasizing that customers retain control over their data and have the flexibility to manage it as needed.
Data Ownership:
Customer Control: Customers are designated as the data controllers (i.e., data owners) for all information stored within their ConnectWise instances. This designation grants them full authority over their data, including decisions regarding access, modification, and deletion.
Access Management: Given their role as data controllers, customers are responsible for implementing appropriate access controls. This responsibility ensures that data handling aligns with their internal policies and complies with relevant regulatory requirements.
Data Portability:
Data Export Capabilities: ConnectWise SIEM offers features that facilitate the export of data, enabling customers to retrieve their information in commonly used formats. This functionality supports seamless data migration or integration with other systems as needed.
ConnectWise SIEM contract renewal and cancellation policies are outlined in their Master Agreement and associated addendums. Key aspects include:
Contract Renewal:
Automatic Renewal: Subscriptions and Assurance services automatically renew for additional periods equal to the expiring term or one year, whichever is shorter. To prevent automatic renewal, either party must provide notice of non-renewal at least 30 days before the current term ends. During renewal, per-unit pricing adjusts to the then-current list price. Promotional pricing does not carry over; renewals revert to standard rates. A decrease in service volume from the prior term may result in re-pricing without regard to previous per-unit costs.
Contract Cancellation:
Termination for Breach: Either party can terminate the agreement if the other party materially breaches its terms and fails to remedy the breach within a specified period after receiving notice.
ConnectWise SIEM is designed to assist organizations in meeting various regulatory compliance standards by providing features that support adherence to key frameworks. While specific certifications for ConnectWise SIEM are not explicitly listed, ConnectWise has successfully completed third-party HIPAA assessments for several of its services and offerings, including:
ConnectWise RMM
ConnectWise Automate
BrightGauge, a ConnectWise Solution
ConnectWise Cybersecurity Management
ConnectWise ScreenConnect
ConnectWise Identify
ConnectWise BCDR
ConnectWise PSA
ConnectWise CPQ
ITBoost, a ConnectWise Solution
These assessments indicate a commitment to maintaining high standards of data protection and compliance across their product suite. Additionally, ConnectWise is a member of the EU-US and Swiss-US Privacy Shield Frameworks, demonstrating its dedication to adhering to international data protection standards.
For organizations aiming to comply with regulations such as HIPAA, PCI DSS, and GDPR, ConnectWise SIEM offers features like comprehensive log management, real-time threat detection, and incident response capabilities. These tools are essential for monitoring security events, maintaining audit trails, and ensuring the protection of sensitive information, thereby facilitating adherence to various compliance requirements.