Implementing Blumira Cloud SIEM is designed to be swift and straightforward, typically completed within minutes to a few hours. The process involves the following steps:
Account Registration: Sign up for a Blumira account using your existing Microsoft account or email address. No credit card is required for the free edition.
Integration Setup: Connect Blumira to your existing technology stack. Blumira offers seamless integration with various cloud services, including Microsoft 365, AWS, Google Workspace, and more. These integrations can be set up in minutes using Blumira's Cloud Connectors, which ingest log data directly from third-party APIs.
Log Configuration: Configure log flows from your systems to Blumira. This may involve setting up agents or using existing logging mechanisms to forward logs to Blumira for analysis.
Automated Detection Deployment: Once integrations are established, Blumira automatically deploys pre-built detection rules. These rules are designed to identify potential security threats without requiring manual configuration, enabling immediate security value.
Blumira Cloud SIEM offers several customization features to align with specific business needs:
Detection Rule Management: Users can view all active detection rules and have the flexibility to enable or disable them as required.
Detection Filters: Customize rules by allowing known safe users, IP addresses, and more, reducing false positives and focusing on genuine threats.
Report Builder: Access logs and create tailored reports to meet specific compliance and operational requirements.
Advanced Dashboards: Utilize specialized dashboards such as Responder, Manager, and Security views to monitor and manage security operations effectively.
Manual Dynamic Blocklists: Respond to findings by adding known threats to blocklists, controlling access by malicious IPs.
Automated Host Isolation: Automatically isolate devices associated with detected threats, preventing potential spread within the network.
Integration Options: Blumira supports a wide range of integrations, including Microsoft 365, Google Workspace, AWS, and various firewalls and endpoint protection solutions, allowing businesses to tailor the platform to their existing infrastructure.
Blumira offers range of training and support resources to assist new users in effectively deploying and utilizing their Cloud SIEM solution:
Onboarding Assistance: Blumira support team provides guidance during the initial setup, ensuring seamless integration with your existing infrastructure.
Support Center: An extensive online support center offers detailed articles and guides covering various topics, including account management, deployment procedures, and integration setups.
Webinars and Video Tutorials: Blumira hosts webinars and provides video tutorials to help users understand platform features and functionalities. For instance, the Maximize Security with $0: Get Started with Blumira Free SIEM webinar offers insights into setting up and optimizing the free SIEM edition.
Blumira Cloud SIEM employs set of security measures to protect user data:
Data Encryption: All data transmitted to and from Blumira is encrypted using industry-standard protocols, ensuring that sensitive information remains secure during transfer.
Access Controls: Blumira enforces strict access controls, allowing only authorized personnel to access sensitive data. This includes user authentication mechanisms and role-based access controls to limit data exposure.
Compliance Certifications: Blumira maintains SOC 2 compliance, demonstrating adherence to stringent security standards for data protection and privacy.
Continuous Monitoring: The platform continuously monitors for suspicious activities and potential security threats, enabling rapid detection and response to any anomalies.
Blumira Privacy Policy outlines its approach to data ownership and portability:
Data Ownership
User Control: Users have the right to review, update, correct, or delete their Identifiable Information. Requests can be made by contacting Blumira at [email protected].
Retention Policy: Upon request, Blumira will return Identifiable Information within a reasonable timeframe. However, Blumira may retain one copy for record-keeping purposes and may also keep unidentifiable information for analysis and improvement of services.
Data Portability
Blumira Cloud SIEM service operates under specific terms and conditions regarding contract renewal and cancellation:
Contract Renewal
Automatic Renewal: Contracts are typically set for an initial term of one year. At the end of this period, and each subsequent renewal term, the agreement automatically renews for an additional one-year term unless either party provides written notice of termination at least 30 days prior to the end of the current term.
Contract Cancellation
Termination for Cause: Either party may terminate the agreement before the end of the current term if the other party defaults on any payment due and fails to remedy the default within 30 days after receiving written notice. Additionally, if a party breaches any other provision of the agreement and does not cure the breach within 30 days of notice, the non-breaching party may terminate the contract.
Termination Without Cause: Either party has the right to terminate the agreement without cause by providing at least 60 days' prior written notice. Payment obligations that accrued before the effective termination date remain unaffected.
Automatic Termination: The agreement may automatically terminate if certain conditions occur, such as the appointment of a receiver for either party, an assignment for the benefit of creditors, initiation of bankruptcy proceedings not dismissed within 60 days, liquidation or dissolution of either party, or a material breach related to Blumira proprietary rights.
Suspension or Termination of Service Orders: Blumira reserves the right to suspend or terminate any service order immediately if the associated customer violates the pass-through terms of service.
Blumira Cloud SIEM platform is designed to assist organizations in meeting a wide range of compliance standards by providing advanced threat detection, logging, and reporting capabilities:
NIST 800-171: Blumira helps organizations comply with NIST SP 800-171 by centralizing log management, monitoring user activities, and providing audit trails essential for protecting Controlled Unclassified Information (CUI).
CMMC: For federal contractors, Blumira supports Cybersecurity Maturity Model Certification (CMMC) compliance by offering logging, auditing, threat detection, and reporting functionalities that align with various CMMC controls across multiple levels.
PCI DSS: Blumira assists organizations in adhering to Payment Card Industry Data Security Standard (PCI DSS) requirements by performing monitoring and reporting activities that address specific standards, such as audit log management and malware protection.
HIPAA: Healthcare organizations can utilize Blumira to meet Health Insurance Portability and Accountability Act (HIPAA) mandates by implementing audit controls, monitoring login attempts, and ensuring the security of electronic protected health information (ePHI).
ISO 27001/27002: Blumira supports compliance with ISO 27001 and ISO 27002 by providing pre-built global reports and security controls that help organizations establish and maintain an effective information security management system.
FFIEC: Financial institutions can leverage Blumira to meet Federal Financial Institutions Examination Council (FFIEC) guidelines by implementing automated audit trails and comprehensive logging to ensure robust information security standards.
