Solutions
Solutions > IDS/IPS Management > Managed Intrusion Prevention Systems

Managed Intrusion Prevention Systems

IPS is not “plug-and-play”, nor is it “out-of-the- box ready” for maximum deployment. That is where SOS Security adds value to a new or existing IPS implementation: expert knowledge and technical support. SOS Security ensures implementations are properly configured, continuously monitored, and proactively managed to maximize effectiveness in stopping attacks.

Managed IPS Service includes:

  • Vendor-agnostic services
  • Design, implementation, and configuration solutions
  • Expert tuning and proactive, comprehensive management
  • Real-time blocking of threats
  • 24×7 real-time monitoring and verification of alerts
  • Customized incident response and escalation
  • Incident tracking and correlation by security experts
  • Supports security and compliance initiatives (e.g., PCI, ISO, SOX, GBLA, 
HIPAA/HITECH/HITRUST, etc.)

100% certified Security Operations Center (SOC) experts monitor, track, and report suspect activity, which affects business-critical systems and information assets. With end-to-end management processes and detailed security event data, Solutionary tailors solutions to specific risk profiles and presents actionable events in real- time through the ActiveGuard Security & Compliance Portal.

Benefits Include

  • Reduction of Operational Costs
  • Increased Security and Compliance 
Posture
  • Real-time Blocking of Network-based Threats
  • ActiveGuard Event Correlation
    • Cross-correlation of vulnerability data to determine impact (on-target and off- target attacks)
    • User identity and assets add context to normally IP-based alerts (LDAP or AD feed required)
  • 24×7 Event Monitoring
    • Real-time monitoring allows appropriate and precise countermeasures to minimize impact
    • Meets regulatory requirements by ensuring documented actions are taken in a timely manner
  • Device Management
    • Configured to fit client needs, eliminating the risk of inadvertently blocking legitimate traffic
    • Timely countermeasures are implemented in response to serious security threats
    • Continuous device management and rule maintenance ensures a high level of effectiveness
    • Cross-client, global views enable creation of signatures to address emerging threats
  • Threat Blocking
    • Proactive vendor and industry signature updates to protect against the latest threats and trends
    • Blacklisting on an ongoing basis