FortiNDR
By Fortinet, Inc
The typical FortiNDR implementation process:
Planning and Assessment: The initial phase involves understanding the organization's network environment, security requirements, and objectives. This includes identifying critical assets, network architecture, traffic patterns, and compliance needs.
Deployment Method Selection: Based on the assessment, decide whether to deploy FortiNDR as a cloud-based SaaS solution (FortiNDR Cloud) or as an on-premises appliance (FortiNDR). For on-premise deployment, identify appropriate hardware or virtual appliance resources.
Sensor Placement and Configuration: Strategically place FortiNDR sensors (either hardware or virtual) throughout the network to capture relevant traffic. Configure sensors to mirror traffic from network segments, SPAN ports, or TAP devices.
Integration with Security Infrastructure: Integrate FortiNDR with other security tools, such as SIEM, SOAR, EDR, and firewalls, to enable coordinated threat detection and response.
Initial Configuration and Tuning: Configure FortiNDR settings, including threat intelligence feeds, detection rules, and alert thresholds. Tune the system based on initial traffic analysis to minimize false positives.
Training and Knowledge Transfer: Provide training to security personnel on how to use the FortiNDR platform, interpret alerts, and respond to incidents.
FortiNDR can be customized to fit specific business needs:
Flexible Deployment: FortiNDR offers both cloud-based (SaaS) and on-premises deployment options, allowing organizations to choose the model that best suits their infrastructure, security requirements, and compliance needs (including air-gapped environments).
Customizable Sensors: Organizations can choose from various hardware and virtual sensor options (AWS, Azure, GCP, ESXi/KVM) and deploy them strategically throughout their network to capture relevant traffic.
Integration with Existing Security Tools: FortiNDR integrates with a wide range of security tools, including SIEM, SOAR, EDR, NGFW, and XDR, enabling organizations to leverage their existing security investments and create a more coordinated security posture.
Customizable Detection Rules: Organizations can fine-tune detection rules and alert thresholds based on their specific risk profile and network environment, reducing false positives and ensuring that security teams focus on the most critical threats.
OT-Aware Solution: FortiNDR is designed with OT networks in mind, offering optional industrial security and OT malware detection capabilities, allowing organizations to protect their critical infrastructure and industrial control systems.
AI-Powered Detection: With supervised and unsupervised AI/ML that continuously analyzes network metadata.
FortiGuard Labs Threat Intelligence: ML and rule-based detections are backed by FortiGuard Labs threat intelligence.
FortiNDR training and support:
Technical Support Services: Fortinet provides various per-device options for efficient operations. The FortiCare Elite option offers a 15-minute response time for critical products.
FortiGuard Labs Expert Help: FortiGuard Labs comprised of experienced threat hunters, researchers, analysts, engineers, and data scientists - develops and enhances FortiGuard AI-powered Security Services as well as provides valuable expert help through FortiGuard Expert-driven Security Services.
FortiCare Services: Fortinet is dedicated to helping customers succeed, and every year FortiCare services help thousands of organizations get the most from their investments in Fortinet's products and services by following the life-cycle approach and providing unique services to help our customers in their success journeys.
Product Demos & Video Tutorials: The website offers product demos and video tutorials to guide users through the platform's features and functionalities.
Guided SaaS: As FortiNDR offers Guided SaaS.
FortiNDR Security measures:
AI/ML-Based Analysis: Employs AI/ML algorithms to analyze network traffic, including encrypted traffic, to detect malicious behavior while reducing false positives.
Behavioral Analysis: Uses behavioral analysis to identify anomalies and suspicious patterns in network traffic that may indicate malicious activity.
Threat Intelligence: Leverages FortiGuard Labs' threat intelligence to perform deep packet inspection/SSL inspection of network traffic to detect and block malicious traffic and activities.
Blocks Unauthorized Communication: Prevents unauthorized attempts to communicate with compromised remote servers for receiving malicious commands and extracting information.
Detection of Evasive Threats: Designed to detect threats that may have slipped past traditional security solutions by looking for signs of attacker activity by analyzing network traffic.
Air-Gapped Environment Support: Can operate in isolated environments to meet additional confidentiality and compliance requirements for mission-critical infrastructure.
Network Traffic Analysis: Collects network traffic from cloud, hybrid-cloud, IT, and OT infrastructures to identify malicious network activity and files.
AI-driven network traffic and file-based analysis: automates investigation efforts through AI-driven network traffic and file-based analysis, providing real-time identification of advanced threats, including persistent threats that may be lingering in your network.
Fortinet Security Operations Solution: monitors activity across users, devices, networks, emails, applications, files, and logs and detects anomalous or malicious actions that humans may easily overlook.
Data Encryption: Analyzes encrypted traffic for malicious behavior.
FortiNDR provides robust data retention and management policies, allowing organizations to control the duration and storage of their event data. Administrators can establish retention policies specifying which events are retained and for how long in both online and archive event databases. These policies can be tailored based on event attributes such as organization, reporting device, and event type.
Regarding data portability, FortiNDR enables the restoration of archived data for querying and analysis. Administrators can restore archived event data to the system, making it accessible for standard queries and investigations. This functionality ensures that organizations can retrieve and analyze historical data as needed.
FortiNDR Terms and Conditions:
FortiNDR Services:
Automatic Shutdown Upon Expiry: When a FortiNDR Cloud subscription expires, the associated cloud instances are automatically shut down without a grace period. Users lose access to these instances immediately upon contract expiration. All data generated by FortiNDR Cloud, including event logs and incidents, is automatically removed from the platform within 14 days post-expiry.
License Registration and Renewal: To register or renew a FortiNDR Cloud license, users must have a FortiNDR account and purchase the appropriate product SKUs. Upon purchase, service contract registration codes are sent to the registered email address. Users can then register their entitlements or upgrade existing ones through the FortiCare portal.
On-Premises FortiSIEM:
Backdating Policy: For on-premises deployments, if a subscription lapses and is renewed after the expiration date, Fortinet's policy is to backdate the renewal to the original expiration date. This means that if a subscription expires three months ago and is renewed today, the new subscription would cover the period from the original expiration date, effectively providing nine months of service on a one-year renewal. However, backdating is limited to a maximum of six months, ensuring that users do not lose more than six months of service.
Extended Renewals: Purchasing multi-year contracts (e.g., two or more years) may offer flexibility regarding backdating. In such cases, Fortinet may choose not to backdate the renewal, providing a full term from the date of purchase. It's advisable to confirm specific terms with a Fortinet representative or authorized reseller.
General Considerations:
Continuous Coverage: Fortinet designs its support and subscription services to be continuous. To avoid service interruptions, it's recommended to renew contracts before the expiration date. A lapse in service can lead to backdated renewals, as described above.
FortiNDR is designed to assist organizations in meeting a variety of regulatory compliance standards by providing out-of-the-box support and pre-built reports for several key frameworks. These include:
Payment Card Industry Data Security Standard (PCI DSS): FortiNDR offers predefined reports and monitoring tools to help organizations adhere to PCI DSS requirements, ensuring the protection of cardholder data.
Health Insurance Portability and Accountability Act (HIPAA): The platform includes policies and reporting features that facilitate compliance with HIPAA regulations, safeguarding sensitive patient information.
Sarbanes-Oxley Act (SOX) with COBIT guidelines: FortiSIEM provides tools to monitor and report on controls related to financial reporting, aiding in SOX compliance.
General Data Protection Regulation (GDPR): The system assists in tracking and demonstrating compliance with GDPR mandates, focusing on the protection of personal data within the European Union.
International Organization for Standardization (ISO) 27001: FortiNDR supports the implementation and monitoring of an Information Security Management System (ISMS) in line with ISO 27001 standards.