JBS detects possible threats in the organization using the functions of Windows Defender ATP and other security products.
Managed Security Service for Microsoft Defender for Endpoint
Microsoft Defender for Endpoint realizes enhanced security for Microsoft’s Windows 10 client PCs. JBS operates the product on the customers’ behalf, supporting security enhancement and damage reduction to customers’ assets.
Sevice Overview
About Microsoft Defender for Endpoint
Microsoft Defender Advanced Threat Protection (ATP) is a malware countermeasure for Windows 10 client PCs that realizes Endpoint Detection and Response (EDR). It powerfully supports security measures for customers’ devices.
- Enables detection of post-penetration activities of high-level threats and attacks in real time.
- Enables swift response in identifying the range of impact and causes.
- A solution premised on invasion by a threat that is more effective when used in combination with Windows Defender.
Microsoft Defender for Endpoint gathers a wide variety of information from respective Windows 10 client PCs, explores potential threats from that information, analyzes past incidents, and determines response.
Service Merits
This product uses Microsoft’s big data and AI to analyze users’ sign-in risks and realize cutting edge entrance measures. It allows the prevention of impersonation and infiltration by attackers in real time and prevents access to important resources.
Monitoring and Analysis
Analysts monitor target PCs and analyze the threats and impacts expected from the alert contents. It is also possible to receive security advice about terminal protection as required.
Response
If JBS analysts determine that there is danger from the detection of incidents, they implement primary response to minimize the impact of any incident.
Recurrence Prevention and Response
Service Menu
In addition to the basic standard service, JBS has also prepared optional services such as investigating incident background and impact range of incidents and permanent response support.
Standard
Security monitoring
- Event monitoring
- Event analysis
Security incident countermeasure support
- Incident countermeasure support (emergency warning/ escalation)
- Monthly report
Option
Reporting
- Monthly report (detailed) / on-site debriefing session
Advanced services
- Incident investigation
- Incident recurrence prevention proposals
- Policy setting support