Fortinet- FortiSOAR - Add value to SOC
Rating: 9 out of 10
IncentivizedUse Cases and Deployment Scope
FortiSOAR is only Security Orchestration Automation & Response tool that has extensive product capability & flexibility, tied to case management & leverage the power of Forti Security Fabric reducing the Burdon of Security operation center (SOC) team ultimately working as force multiplier for teams to response faster- vital to reducing the threat landscape for organizations .
FortiSOAR remedies alert fatigue & false positives by centralizing & aggregating alerts enriching them with add context while corelating them across a security stack to rapidly investigate . This includes custom playbook for triage process. Accelerating incident response & optimizing security operations.
FortiSOAR remedies alert fatigue & false positives by centralizing & aggregating alerts enriching them with add context while corelating them across a security stack to rapidly investigate . This includes custom playbook for triage process. Accelerating incident response & optimizing security operations.
Pros
- FortiSOAR address complexity by providing 160 +ply books & 300 Connectors to easily integrate with deployed security controls to ingest information & provide single point of control.
- FortiSOAR resolves collaboration complexities by providing teams with a comprehensive war room, module builder, granular RBAC, Segmenting Teams , duties and process . Seamless connecting all an organization s team together .
Cons
- Training Services- Fortinet offers courses geared towards administration and designed and development of FortiSOAR , Which required multiples access , we need all training services with self pace basis , I think here Fortinet need to improve.
- Licensing Model- Being as a new technology Licensing model should be crystal & Clear, be it Concurrent Users or The number of FortiSOAR nodes there should be no ambiguity .
Likelihood to Recommend
Most organization with medium & maturity SOC struggle with alert fatigue & false positives with addressing alert volume is result in increasing risk of critical alerts being masked by trivial one , in this situation FortiSOAR help in case management : rapidly response in case of crises also.
FortiSOAR is designed very well where Fortinet have other stack of security component also like Fortinet NGFW & Forti SIEM etc.. Fortinet NGFW can and generate the FortiSOAR instance through FortiCloud for Customer .
However In absence of FortiFabric it require lot of connectors to work well the solution.
FortiSOAR is designed very well where Fortinet have other stack of security component also like Fortinet NGFW & Forti SIEM etc.. Fortinet NGFW can and generate the FortiSOAR instance through FortiCloud for Customer .
However In absence of FortiFabric it require lot of connectors to work well the solution.