Securely Enabling Business

Threat Response Manager (TRM)

Highlights

  • Instantly quarantine any node, anywhere
  • Experience quick and easy deployment
  • Leverage your existing network on your network and management technologies

An Automated Approach to Incident Response
There is no shortage of prevention and detection technology in the marketplace. What is missing is technology that supports your incident response plan. Incident response requires a multi-dimensional approach that addresses a variety of issues challenges including:

  • Corporate process
  • Company communication
  • Technology
  • Compliance
  • Audit

Organizations could address these challenges with manual processes, but that is not a practical approach. Why? Because if your network is ever compromised, you need to respond fast. With the ArcSight Threat Response Management (TRM) solution, relief is only seconds away.

Instantly Locate Any Incident on Your Network
ArcSight TRM builds and maintains a detailed understanding of your network's topology by communicating directly with your network infrastructure devices including routers, switches, firewalls, wireless access points and VPNs.

Because ArcSight TRM communicates natively using telenet, SSH and HTTP(s), it does not require clients or agents to be deployed on your network. As a result, you can easily operate the solution without making any changes to your existing network infrastructure and desktop environment.

The system's advanced patent-pending algorithms can instantly identify the exact location of any node (wireless, wired or VPN) across your network, and implement specific, policy-based actions. These actions include disabling the node's switch port, implementing a filter on the node's traffic and moving the node to a virtual quarantine network.

Manage and Control User Rights
Organizations commonly have multiple support teams, each with its own location-dependent rights. The user account control feature in ArcSight TRM defines task groups within each module, allowing you to easily control and restrict access rights in accordance to individual

  • Instantly identify the exact switch port the node is plugged into and disable the switch port.
  • Perform MAC filters on switch ports, causing the switch to stop forwarding traffic from a specific node.
  • Enable remote remediation by moving the node to a Quarantine VLAN.
  • Work with VPNs and authentication systems to quickly quarantine remote users.
  • Quickly dictate how IP ports and protocols are routed across your network.
  • Disable individual user accounts via the Quarantine Enterprise function.

ArcSight Threat Response Management (TRM) allows you to pinpoint the exact location of any compromise on your network-and respond immediately with specific, policy-based actions.

For more information, click here.



© 1996-2008 FishNet Security, Inc. All rights reserved. The FishNet Security logo symbol is a registered trademark of FishNet Security, Inc. SecureSkills is a trademark of FishNet Security, Inc.  Legal Statement  | Privacy Policy