Using the Audit App
Total Page:16
File Type:pdf, Size:1020Kb
Using the Audit App Symantec CloudSOC Tech Note Tech Note — Using the Audit App Copyright statement Copyright (c) Broadcom. All Rights Reserved. Broadcom, the pulse logo, Connecting everything, and Symantec are among the trademarks of Broadcom. The term “Broadcom” refers to Broadcom Inc. and/or its subsidiaries. For more information, please visit www.broadcom.com. Broadcom reserves the right to make changes without further notice to any products or data herein to improve reliability, function, or design. Information furnished by Broadcom is believed to be accurate and reliable. However, Broadcom does not assume any liability arising out of the application or use of this information, nor the application or use of any product or circuit described herein, neither does it convey any license under its patent rights nor the rights of others. Copyright © 2021 Symantec Corp. 2 Tech Note — Using the Audit App Table of Contents Introduction Opening Audit Choosing data sources Viewing and filtering audit results Viewing summary results Viewing services, users, and destinations Filtering Audit Results Search Cloud Applications by Service, Category, Tag, Risk, User, Country, and Platform Saving and loading filters Using filter multi-select Configuring your services view Tagging cloud services Creating custom tags Viewing services tagged Ignore Adding comments for services Exporting Audit results Exporting ProxySG CPL block policy files from Audit Evaluating cloud services Viewing service information Customizing service rankings BRR Scoring for Individual Applications Customizing global service ratings Creating a custom BRR profile Comparing cloud services Exporting service and usage details Use of Attribute Filters in Find and Compare Services Copyright © 2021 Symantec Corp. 3 Tech Note — Using the Audit App Requesting a BRR review Submitting a new service request Tracking your service requests Creating Custom Gatelets in Audit Creating and scheduling custom reports Service attribute reference Service category reference Service Category Are services that... Revision history Copyright © 2021 Symantec Corp. 4 Tech Note — Using the Audit App Introduction The CloudSOC Audit application is a powerful tool that helps you make intelligent decisions about which cloud applications you should embrace, and which you should avoid. Audit finds and monitors all the cloud applications being used in your organization, and highlights any risks and compliance issues these applications may pose. With Audit, you can quickly identify risky services that your employees have adopted, as well as identify the employees using these services. It shows you why each app is risky, as measured against over 60 objective security, compliance and business continuity criteria. Opening Audit To open the Audit app: 1. Log into your CloudSOC account with your administrator credentials. 2. In CloudSOC, click Audit as shown in the following. Audit is at or near the middle of the bar. Tip: Once you’re familiar with Audit, you can use the Audit submenu to go directly to specific Audit pages. Copyright © 2021 Symantec Corp. 5 Tech Note — Using the Audit App Audit opens to the Summary tab as shown in the following. The summary tab shows you an overview of your organization’s SaaS usage and risk exposure. Choosing data sources The Audit app uses data from log files generated by your network devices and proxies to show you your company’s actual SaaS activity. You can select to use one, several, or all available, data sources. The compressed source files sent to Audit must be less than 9 GB. Note: This Tech Note assumes that you have already uploaded firewall and proxy logs to CloudSOC. It also assumes that CloudSOC has already processed the logs, and that the results of analysis are available. For more information, see the Tech Note Managing Data Sources for the CloudSOC Audit App. Copyright © 2021 Symantec Corp. 6 Tech Note — Using the Audit App To select data sources for Audit: 1. At the top of any Audit page, click Select Sources as shown in the following. Audit opens a list of available data sources as shown in the following. 2. Select one or more of the available sources, or select All to use an aggregate of all available sources. If you are using a supported centralized proxy/firewall management solution to aggregate logs from multiple devices into one data source, you can further narrow your data source selection to a specific devices within the data source: 1. If it is not already selected, click the aggregated data source. Copyright © 2021 Symantec Corp. 7 Tech Note — Using the Audit App 2. Click the gear icon to open a panel that shows the devices aggregated into the data source. If the gear icon is absent, filtering by individual devices is not supported for the data source. 3. On the panel, select devices to include in the Audit view. Viewing and filtering audit results The power of the Audit app comes from in-depth research on Cloud applications such as SaaS, PaaS and IaaS conducted by the CloudSOC research team, and a powerful yet simple set of analytics tools. These features let you quickly drill down and answer key questions such as: ● What unapproved cloud applications are my users using most? ● Which enterprise cloud applications are the riskiest, and who is using those applications? ● What cloud services have been compromised in the last 90 days? ● Which SaaS applications have my users adopted recently that can be risky? ● Which cloud applications consume the most bandwidth? ● Which cloud applications are hosted in locations that violate company or regulatory requirements? Copyright © 2021 Symantec Corp. 8 Tech Note — Using the Audit App ● Which cloud applications fail to meet security and compliance requirements? ● What alternatives are there to the SaaS applications in use? Are there alternatives that fulfill my users’ needs but are more secure and enterprise-friendly? You can answer all these questions and more using the Audit app’s filters. These filters let you slice and dice Audit data along various dimensions such as type of service, its risk level, services used by specific users, services hosted in a particular geographical location and much more. We encourage you to explore various filtering and drill down options to see how they can show you about your company SaaS activity. Viewing summary results To view Audit results and see the top 20 SaaS applications your employees actually use: 1. In CloudSOC, select Audit, and then select Summary. Audit opens to the Summary tab as shown in the following. The Summary tab shows you your current overall Audit score, and a trend chart of your Audit score over time. The current overall Audit score is based on your Copyright © 2021 Symantec Corp. 9 Tech Note — Using the Audit App company Business Readiness Rating of every cloud service in use, weighted according to the number of users of each service, and is a value between 0 and 100. It is also dependent on your selections, such as service visibility and selected number of days. Business Readiness Rating (BRR) is a metric that the CloudSOC research team assigns to each cloud service based on a variety of criteria, such as how secure is the service. The research team also categorizes each cloud service as high risk (rating of 0 - 33), medium risk (rating of 34 - 66), or low risk (rating of 67 - 100). For more information about how cloud services are rated, see Viewing service details. The trend chart is calculated once a day at midnight, and is based on: ○ All available data sources that are not marked as "Ignored" ○ All Cloud SaaS services which are allowed traffic ○ The previous 12 months of data You can select the time range from seven days to 12 months. Use this chart to track your Audit score. Hover over a point on the curve to see the score at that point in time. Blue diamonds mark points in time at which you edited the global BRR profile. This feature lets you see when changes in the score were caused by changes to the way Audit evaluated your cloud services. The right endpoint of the curve may not match the numerical audit score, since the numerical score is based on the currently selected data sources, while the curve is based on all available sources. Copyright © 2021 Symantec Corp. 10 Tech Note — Using the Audit App The Audit Summary tab also shows you when the selected service has been involved in a recent security compromise. You can sort the Summary tab services list for compromises using the sort menu as shown in the following. You can also configure CloudSOC to reduce the BRR of any cloud service that has been compromised in the prior 90 days. The Compromised in Last 90 Days process works as follows: a. The machine learning algorithm retrieves data from multiple internet sources and identifies probable data breaches of your apps. b. Any sources flagged as being likely application data breaches are sent to reviewers in the security team. c. The reviewers analyze the available information and source to determine details such as the breach date, public notification date, responsible party, and root cause of breach. If the analysis determines a breach, then it is flagged as a breach and included in the Cloud Threat Feed functionality. The preceding process is performed multiple times a day. See Customizing service rankings for more information. Copyright © 2021 Symantec Corp. 11 Tech Note — Using the Audit App You can view the top five users and destinations for each service by clicking the service on the list. The top five users and destinations appear on the right hand side of the page. To view all users of a service, click View All above the list of service users as shown in the following. 2. To change the view to the most-used services, select Top Used Services from the menu above the services list as shown in the following.