
Implementing Exabeam New-Scale SIEM involves several structured steps to ensure effective deployment and integration. The typical process includes:
Planning and Assessment:
Scope Definition: Identify specific security monitoring requirements and objectives.
Resource Allocation: Determine necessary hardware, software, and personnel.
Timeline Establishment: Set realistic milestones and deadlines for the implementation phases.
Preparation:
Information Gathering: Collect details about existing infrastructure, log sources, and network architecture.
Log Source Readiness: Ensure that all relevant log sources are configured and ready for integration.
Deployment:
Cloud Deployment: Set up the cloud-native New-Scale SIEM platform, selecting the appropriate hosting location to meet data residency requirements.
Data Collection Configuration: Implement collectors to securely gather data from on-premises systems, cloud services, and third-party applications.
Configuration and Integration:
Log Parsing and Normalization: Set up parsing rules to standardize incoming data for consistent analysis.
Third-Party Integrations: Integrate with existing security tools and platforms to enhance data correlation and threat detection capabilities.
Testing and Validation:
Functionality Testing: Verify that all components are operating as expected.
Performance Assessment: Ensure the system can handle the anticipated data volume and processing load.
Training and Knowledge Transfer:
User Training: Provide comprehensive training sessions for security analysts and administrators.
Documentation: Supply detailed guides and resources to support ongoing operations and troubleshooting.
Go-Live and Monitoring:
System Activation: Transition from the testing environment to full operational status.
Exabeam New-Scale SIEM is designed with extensive customization capabilities to align with specific business requirements. Key customizable features include:
Dashboard and Reporting Customization:
Diverse Visualization Options: Users can tailor dashboards using 14 different chart types, enabling the presentation of data in formats that best suit their analytical needs.
Custom Report Generation: Beyond pre-built compliance reports, organizations can create bespoke reports to extract and display SIEM data pertinent to their unique operational and regulatory requirements.
Correlation Rule Development:
Rule Creation Flexibility: Security teams can develop custom correlation rules from scratch, utilize templates, or convert existing searches into rules. This flexibility allows for the detection of a wide array of behaviors and events specific to the organization's threat landscape.
Event Condition Definition: Users can specify precise conditions and assign criticality levels to events, ensuring that alerts and responses are appropriately prioritized based on the organization's risk assessment.
Data Source Integration:
Extensive Pre-Built Parsers: With over 7,937 pre-built log parsers, New-Scale SIEM facilitates rapid onboarding of diverse log sources, ensuring comprehensive visibility across various systems and applications.
Broad Product Integration: The platform supports integration with 549 different security products, allowing organizations to seamlessly incorporate New-Scale SIEM into their existing security infrastructure.
Scalable Data Management:
High-Performance Data Handling: Capable of processing sustained data ingestion rates exceeding 2 million events per second, the platform ensures scalability to meet the demands of organizations of varying sizes and industries.
Efficient Data Search: Advanced search functionalities enable users to query across terabytes of data within seconds, facilitating swift access to critical information.
User-Friendly Search Interface:
Exabeam New-Scale SIEM offers a suite of training and support services to ensure new users can effectively utilize the platform:
Education and Training:
Role-Specific Learning Paths: Tailored programs are available to enhance skills pertinent to specific roles, such as security engineers and analysts. These paths encompass a range of instructional methods, including videos, instructor-led courses, and eLearning sessions.
Instructor-Led Training: Exabeam provides private training sessions that can be conducted virtually or on-site, offering flexibility to accommodate various organizational needs.
Continuous e-Learning: Users have access to self-paced courses covering both fundamental and advanced aspects of the Exabeam Security Operations Platform, enabling them to deepen their cybersecurity expertise.
Support Services:
Customer Success Team: A dedicated team of professionals offers technical assistance to ensure optimal configuration and performance of Exabeam solutions within your environment.
Exabeam New-Scale SIEM incorporates a range of security measures to ensure robust data protection:
Cloud-Native Architecture:
Scalability and Performance: Built on a cloud-native, multi-tenant foundation utilizing microservices, the platform offers enhanced scalability and performance. This design efficiently manages the increasing volume of cybersecurity data, ensuring rapid data ingestion and processing.
Data Security and Compliance:
Certifications: The New-Scale Platform has achieved ISO 27001 and SOC 2 Type II certifications, demonstrating adherence to stringent security standards and effective data protection practices.
GDPR Compliance: Exabeam implements robust technical and organizational measures to support GDPR compliance, ensuring the protection of personal data and upholding data privacy rights.
Behavioral Analytics and Threat Detection:
User and Entity Behavior Analytics (UEBA): The platform employs machine learning to establish baselines of normal user and device behavior. By identifying deviations from these baselines, it detects potential security threats, including compromised credentials and insider threats.
Automated Investigation: New-Scale SIEM automates the investigation process by compiling comprehensive timelines of user and device activities. This automation accelerates threat detection and response, reducing the window of exposure to potential breaches.
Data Handling and Storage:
Efficient Data Management: The platform is capable of processing sustained data ingestion rates exceeding 2 million events per second, ensuring scalability to meet the demands of organizations of varying sizes and industries.
Exabeam contractual terms for their New-Scale SIEM solution encompass specific provisions regarding payment obligations, renewal processes, and cancellation policies. Below is a detailed overview:
Payment Terms:
Non-Cancelable and Non-Refundable Fees: All fees outlined in an accepted order are binding, non-cancelable, and non-refundable.
Payment Deadlines: Invoices are typically due within thirty (30) days of receipt, unless otherwise specified in the order.
Late Payment Charges: Overdue payments incur a late fee of one percent (1.0%) per month, or the maximum rate permitted by applicable law, calculated from the due date until full payment is received.
Suspension and Cancellation:
Suspension of Services: Exabeam reserves the right to suspend licenses, access to the SaaS environment, and support services if any fees remain overdue.
Subscription Cancellation: Persistent non-payment may lead to the cancellation of the subscription or its renewal associated with the outstanding fees.
Credit Reporting: In cases of repeated failed attempts to collect overdue payments, Exabeam may report the delinquency to credit reporting agencies.
Renewal Terms:
Maintenance Renewal Documentation: Exabeam maintains records of customers' maintenance renewal terms and conditions to facilitate upcoming renewals.
Additional Considerations:
Service Level Agreements (SLAs): Exabeam provides SLAs that guarantee monthly data upload availability of 99.9% and product access availability of 99.5%, ensuring reliable service delivery.
Exabeam New-Scale SIEM software is designed to assist organizations in meeting a variety of regulatory compliance standards by providing detection rules, behavioral models, and compliance reporting. The platform supports adherence to several key standards, including:
ISO Certifications: Exabeam has obtained ISO 27001, 27017, and 27018 certifications, demonstrating a commitment to maintaining robust information security management systems and protecting sensitive data.
SOC 2 Type II: The platform has successfully completed SOC 2 Type II auditing, ensuring that Exabeam follows strict information security policies and procedures to safeguard customer data.
General Data Protection Regulation (GDPR): Exabeam has implemented technical and organizational measures to comply with GDPR requirements, aiding organizations in protecting personal data and ensuring privacy rights.
EU-U.S. Data Privacy Framework (EU-U.S. DPF): Exabeam adheres to the EU-U.S. DPF Principles regarding the processing of personal data received from the European Union and the United Kingdom, as certified by the U.S. Department of Commerce.
Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF): The company complies with the Swiss-U.S. DPF Principles for processing personal data received from Switzerland, ensuring alignment with Swiss data protection standards.
Information Security Registered Assessors Program (IRAP): Exabeam has completed an IRAP assessment at the PROTECTED level, aligning with the Australian government's security requirements and supporting organizations in meeting their obligations under Australian cybersecurity legislation.
Additionally, Exabeam New-Scale SIEM provides pre-built compliance reports and dashboards to assist organizations in demonstrating adherence to various regulatory requirements, such as:
Payment Card Industry Data Security Standard (PCI DSS): The platform offers predefined compliance reports and detection rules to help organizations secure credit card data and meet PCI DSS obligations.
Health Insurance Portability and Accountability Act (HIPAA): Exabeam provides tools to monitor user activity and detect anomalies, aiding healthcare organizations in maintaining HIPAA compliance.