Customers: Raiffeisen Bank Moscow; Financial Services, Investments and Auditing Contractors: Jets Infosystems Product: IBM Security SOAR (formerly Resolient)Project date: 2021/03 - 2021/08
|
2021: IBM Security SOAR Platform Implementation
On September 28, 2021, Raiffeisen Bank announced that it had implemented the IBM Security SOAR platform together with the specialists of the IT company Jet Infosystems. The solution helped automate the response to information security incidents, increase the quality and speed of their processing. As part of the project, Jet Infosystems specialists implemented several special integrations and developed a number of plans for responding to typical incidents (playbooks).
Among the special solutions that were implemented during the implementation of IBM Security SOAR are integration with the center of monitoring and response to computer attacks in - creditnofinancial the sphere. Bank of Russia FINTSERT Now the management system (IB SOAR system: Security Orchestration, Automation and Response) can automatically conduct inspections and build the incident response process.
Another integration is with access control systems. Because of this, the infected host is automatically quarantined and completely disconnected from the bank network, and is automatically quarantined after reinstalling the operating system.
It was also important for the bank to automate the reporting of IB and frod incidents for the Bank of Russia through FinCERT and for the internal operational risk accounting system. At the same time, each case required its own data transmission format. Without the implementation of the SOAR system, it would be difficult to automate such reporting.
One hundred percent protection does not exist - the threat landscape is too diverse, and attackers are inventive. Protection requires an integrated and multifaceted approach. The implementation of the IBM solution gives us another tool for rapid and high-quality response to information security incidents, "said Ilya Zuev, head of the information security department of Raiffeisen Bank. |
The Raiffeisen Bank team approached the project well prepared: there was an accurate understanding of how SOAR systems work, what kind of integration and incident handling scenarios the bank needs, which is important to include in the incident cards. This helped to implement the project at a good pace and not be distracted by additional clarifications on business processes, "said Anna Bogdanova, head of the SOUNDdirection of the Jet Information Security Center, IBM business partner. |