πŸ”΄

Security Hub

Cyber Security Β· Compliance Β· Governance β€” SOC Β· XDR Β· ICC Β· GRC Β· Vulnerabilities Β· SecOps
πŸ“š Knowledge Base πŸ—„ CMDB / Assets
πŸ›‘ SecOps capability avanzate NEW
⚑
NEW
SecOps Executive Dashboard Β· CISO view cross-domain
Vista executive CISO con drill-down ai 4 Director: Security Posture Β· Compliance Posture Β· Risk Exposure Β· Top IR Β· Vuln Top Risk Β· MITRE coverage Β· Framework score Β· Threat Intel Β· Emerging risks.
CISO viewDrill-downCross-domainAggregato
βš™
RUNTIME
SecOps Runtime Β· Risk Scoring Β· Approvals Β· Rollback
Configurazione runtime SecOps: scoring algorithm tuning Β· approval queue per azioni SOAR critiche Β· rollback one-click delle azioni eseguite.
Risk scoreApprovalsRollback
πŸ€–
AGENTIC
Secure Agentic IA Console Β· SOC Β· XDR Β· ICC L1
Monitoraggio operatori IA L1 per dominio Security. Console centralizzata: agent attivi, ticket gestiti/risolti/scalati, log attivitΓ , performance, token & costi.
Autonomia %FCR24/7Cost guard
πŸ›
VULN MGMT
Vulnerability Management Β· CVE Β· EPSS Β· Risk
Vulnerability response: risk-based prioritization, CVSS+EPSS+asset criticality, remediation workflow.
CVSSEPSSPatch
πŸ”΄ SOC β€” Security Operations Center CORE
πŸ“ž
SOC L1
SOC L1 Β· Phone-first Cockpit
Cockpit L1: alert triage real-time, chiamate live, prima containment, escalation L2/L3.
πŸ“ž Calls🚨 Alerts⬆ Escalate
πŸ”¬
SOC L2/L3
SOC L2/L3 Β· Investigation Workbench
Investigation deep: PIR Β· evidence locker Β· containment log Β· SOAR actions Β· threat landscape.
🎯 PIRπŸ”’ EvidenceπŸ€– SOAR
πŸ“Š
EXEC
SOC Service Director Β· Executive cockpit
Cockpit director: cross-domain SOC/XDR/ICC/GRC/VR KPI, MTTR trend, compliance posture, budget security.
KPITrendCompliance
🟣 XDR β€” Extended Detection & Response CORE
πŸ“ž
XDR L1
XDR L1 Β· Triage cockpit
L1 triage cross-domain: prima classificazione alert XDR, escalation a L2/L3.
TriageCross-domain
πŸ”
XDR L2/L3
XDR L2/L3 Β· Hunt & investigation
Threat hunting cross-domain, root cause analysis, advanced playbook execution.
HuntRCAPlaybook
πŸ”¬
EXEC
XDR Director Β· Cross-domain correlation
Correlation engine multi-source (EDR/NDR/SIEM/Email): unified incident view, threat scoring, KPI cross-domain.
CorrelationThreat score
πŸ›‚ ICC β€” Identity Compliance Cockpit CORE
πŸ›‚
ICC L1
ICC L1 Β· Identity Compliance Cockpit
Identity governance: access reviews, JML compliance, SoD checks.
AccessJMLSoD
πŸ”
ICC L2/L3
ICC L2/L3 Β· Investigation
Identity escalation, complex access analysis, anomaly detection.
EscalationAnomaly
πŸ“Š
EXEC
ICC Director Β· Identity Compliance Executive
Cockpit director ICC: oversight L1/L2/L3 Β· access reviews Β· JML compliance Β· SoD checks Β· identity anomaly trend.
ReviewsJMLSoD
βš– GRC β€” Governance Β· Risk Β· Compliance CORE
βš–
GRC
GRC Β· Governance Β· Risk Β· Compliance
Policy lifecycle, audit findings, control framework (ISO/NIST/PCI), compliance scorecards.
ISO 27001NISTAuditPCI
πŸ“Š
EXEC
GRC Director Β· Governance Β· Risk Executive
Cockpit director GRC: policy lifecycle Β· audit findings Β· framework (ISO/NIST/PCI) Β· compliance scorecards Β· risk register.
ISO 27001NISTAudit
πŸ“Š Dashboard & Reporting INSIGHT
πŸ“Š
DASHBOARD
Security Operations Dashboard Β· Real-time KPI
Dashboard SOC: alert per source, MTTR, SLA performance, top tactics MITRE.
KPIMITRESLA
πŸ“ˆ
REPORT
Security Report Center Β· Compliance Β· Executive
Report ricorrenti: weekly/monthly SOC summary, executive briefing, audit ready output.
PDFCSVExecutive
πŸŽ™
Voicemail Β· Inbox + AI risk score
VM ricevute da utenti / auditor / segnalazioni security. Audio player, AI risk scoring (Claude), callback integrato softphone.
πŸ”Š Audio🚨 RiskπŸ“ž Callback