Certification

Description

Hands-on training focused on both the administrative and operational aspects of SecureVue. Learn how to implement and navigate SecureVue for maximum results in any size environment. Discover how to use pre-defined and customized templates to meet specific needs.

Length

4 days

Delivery Method

Instructor-led training

Audience

System/Network Administrators or Engineers
Security Analysts

Prerequisites

Familiarity with windows operating system
Knowledge of basic information security infrastructure and data
Understanding of networking protocols and concepts

Training Agenda

Section 1

SecureVue Introduction Introduce users to the functionality available in the SecureVue. Start presenting collection methods used in SecureVue to help understand the scope of data SecureVue can collect

Section 2

Network Requirements and SecureVue Installation Discuss what steps need to be taken for a successful rollout of SecureVue on a variety of network infrastructures. Users will learn how to best optimize SecureVue within their environment.

Hands On: Users will install SecureVue on their own systems.

Section 3

Data Flow and Data Collection Learn how nodes are populated in SecureVue. Gain an understanding of how data travels from nodes up to the Central Server. Hands On: Users will add nodes and customize collection of data for different nodes within SecureVue.

Section 4

Application Management Addresses the basics of being a SecureVue administrator. Customize SecureVue for your enterprise by creating users and setting up their role based access into SecureVue. Optimize your SecureVue implementation with data archival and purging. Hands On: Users will create new users in SecureVue and setup their permissions in relation to the SecureVue Application.

Section 5

Security Center Portal

Viewing data in SecureVue. The Security Center Portal consists of both real-time monitors and historical reports. This section will cover every section of the portal looking at each data collection point (in it's own section of SecureVue) as well the correlated views of data in dashboards and reports. Hands On: Users will learn to navigate the portal. There are numerous exercises designed to learn each section of the portal and learn the best way to access your security data.

Section 6

Forensics Learn how to perform Forensics investigation within SecureVue. Hands On: Users will learn how to search for specific data to aid in investigations of incidents.

Section 7

Correlation Rules - Alerting

Understanding the predefined SecureVue Correlation Policies and optimizing them for your environment. Learn the process of creating your own correlation policies.

Hands On: Customize existing correlation rules and create custom rules in SecureVue.

Section 8

Workflow SecureVue's built-in ticketing system. Discover how to track and investigate security incidents attaching all incriminating data to a single ticket for easy review of an incident.
Hands On: Work through the process of creating a ticket and attaching appropriate data.

Section 9

Advanced SecureVue Administration Overview of advanced options available in SecureVue. Learn how to assess the risk score of nodes on the network, by optimizing the risk policy in SecureVue. Perform Visualization Searches on data to find traffic patterns. Introduction to the Universal Parser, which is used to add support for logs that are not natively supported in SecureVue.
Hands On: Create custom policies and use visualization to look at attack data SecureVue has collected.

Section 10

Troubleshooting
Basic troubleshooting techniques used in SecureVue. Learn what data diagnostics files contain.
Hands On: Looking for data in diagnostics files.

Section 11

ComplianceVue
Introduction to ComplianceVue and how it can be used in your environment.
Hands On: Create your own Audit Policy.