2023 Global Medigate Aws Security Lake - Brief - v02

Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

HEALTHCARE

SOLUTION OVERVIEW

MEDIGATE BY CLAROTY
AND AMAZON SECURITY LAKE
The Healthcare Cybersecurity Solution Simplifying Converged
SOC Operations and Incident Response

Challenge
Digital Transformation continues to drive more and more connectivity into clinical environments.
The promise of reduced costs, increased productivity, and minimized device downtime continues to attract
investments that interconnect critical clinical environments with cloud and other IT systems. Securing
interconnected environments provides an opportunity to leverage outputs from IT and IOMT devices into a
converged SOC, but historically IOMT devices haven’t output event data in a consistent manner hampering
efforts to achieve that converged SOC strategy. Furthermore, event data from IOMT systems can be
expensive to maintain over long periods of time which impedes incident responders ability to access the
data they need to conduct forensic analysis.

The Integration of Medigate with Amazon Security Lake Enables a Converged


SOC Approach
Medigate by Claroty is a complete cybersecurity solution for clinical environments. Highly flexible and
rapid deployment options enable Medigate to reveal and protect all XIoT — the extended internet of things,
consisting of IOMT, IoT, OT and BMS assets — within the network, while automatically detecting the earliest
indicators of threats to operations. Medigate strengthens and increases the utility of Amazon Security Lake
by sending alerts detected within clinical networks to Security Lake with minimal configuration. Further
extending the value of these controls, Claroty maintains a vast integration ecosystem and robust API.
The Medigate and Security Lake integration’s advantage lies in its ability to import alerts into third-party
SIEMs seamlessly. Syslog has long served as the de-facto interoperability “standard” for various tools to
send event data to SIEMs. Almost every device can output events via syslog and offering syslog as a data
ingestion capability is tablestakes for all of the SIEM vendors. But even though all of these tools use syslog
to communicate, the formatting within the protocol typically varies making integrations cumbersome
and burdening asset owners with technical debt to maintain the integration. There’s no longer a need for
specific integrations with third-party SIEMs as long as they support Amazon Security Lake and the Open
Cybersecurity Schema Framework (OCSF) format. With the data formatted using OCSF consumers of the
integration can rely on a more complete and capable integration.
Leveraging data and findings from Medigate and other tools within Amazon Security Lake empowers
customers with a central view of their security posture by streamlining and simplifying how this data
gets imported into their SIEM and SOAR solutions. Alerts from Claroty are normalized into the Open
Cybersecurity Schema Framework (OCSF) and written to the Amazon Security Lake so that Amazon
Security Lake subscriber tools can import them more easily and consistently. This centralized platform allows
organizations to continuously monitor and improve their enterprise’s overall security.

claroty.com © 2023 Claroty Ltd. All rights reserved 1


The data is stored in the customer’s Amazon Security Lake which uses S3 for long-term storage. This
provides flexibility and durability of the data for long-term retention and compliance with corporate security
standards. Each customer can define their own rules for when the retained data is expunged per their
corporation’s security policy. The affordable long-term storage nature of AWS S3 means that that data will
be available to forensics teams conducting incident response activities during a post-mortum following any
cyber incident. Without that data, it is much harder to do any analysis, find out what happened, and make
improvements to limit similar breaches in the future.

Medigate by Claroty
• Extends cybersecurity across the XIoT with a modular, SaaS-powered industrial cybersecurity platform
• Is designed for scalability, flexibility, and ease-of-use regardless of network size, architecture, or diversity
of end users
• Integrates seamlessly with security solutions to extend existing cybersecurity controls into the
industrial environment
• Provides flexible asset discovery options including passive, Edge, and various third-party integrations
• Manages all assets with in-depth asset insights and an enriched CMDB
• Identifies, prioritizes, and manages risks and vulnerabilities with automated correlation and scoring for
all assets

The above figure depicts example deployments of Medigate and the integration with
Amazon Security Lake, with either passive asset discovery, Safe queries discoveries,
Proprietary Claroty Edge discovery tool, Project file import, 3rd party integrations.

Solution Overview © 2023 Claroty Ltd. All rights reserved 2


About Claroty
Claroty empowers organizations to secure cyber-physical systems across industrial (OT), healthcare (IoMT),
and enterprise (IoT) environments: the Extended Internet of Things (XIoT). The company’s unified platform
integrates with customers’ existing infrastructure to provide a full range of controls for visibility, risk and
vulnerability management, threat detection, and secure remote access. Backed by the world’s largest
investment firms and industrial automation vendors, Claroty is deployed by hundreds of organizations at
thousands of sites globally. The company is headquartered in New York City and has a presence in Europe,
Asia-Pacific, and Latin America.

For more information, visit claroty.com or email [email protected].

© 2023 Claroty Ltd. All rights reserved

You might also like