{"id":20864,"date":"2022-01-13T10:56:29","date_gmt":"2022-01-13T18:56:29","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/azuregov\/?p=20864"},"modified":"2022-01-27T06:31:58","modified_gmt":"2022-01-27T14:31:58","slug":"protecting-federal-information-systems-and-critical-infrastructure-with-the-microsoft-sentinel-it-ot-threat-monitoring-solution","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/azuregov\/protecting-federal-information-systems-and-critical-infrastructure-with-the-microsoft-sentinel-it-ot-threat-monitoring-solution\/","title":{"rendered":"Protecting federal information systems and critical infrastructure with the Microsoft Sentinel: IT\/OT Threat Monitoring Solution"},"content":{"rendered":"<p><em>Also contributing to this blog are <\/em><a href=\"https:\/\/www.linkedin.com\/in\/tjbanasik\/\">TJ Banasik<\/a><em>, CISSP-ISSEP, ISSAP, ISSMP, Senior Program<\/em><em> Manager, <\/em><em>and <a href=\"https:\/\/www.linkedin.com\/in\/katie-t-a9575655\/\">Katie Thomas<\/a>, Program Manager, of Microsoft Cloud &amp; AI Security.<\/em><\/p>\n<p style=\"padding-left: 80px;\"><iframe loading=\"lazy\" title=\"YouTube video player\" src=\"\/\/www.youtube.com\/embed\/hZS2aplJoy8\" width=\"560\" height=\"315\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>Security teams traditionally have not had tooling nor the expertise to provide them with visibility to monitor Internet of Things (IoT) \/ Operational Technology (OT) networks for vulnerabilities. As a result, IoT\/OT security risks have traditionally been overlooked. This poses a great risk to organizations, as we see adversaries moving laterally from IT to OT with ease. <a href=\"https:\/\/www.youtube.com\/watch?v=hZS2aplJoy8\">In this video<\/a>, we discuss the <em>Microsoft Sentinel: IT\/OT Threat Monitoring with Defender for IoT Solution<\/em>.<\/p>\n<p>This solution provides the foundation for building a Security Operations Center (SOC) for monitoring IoT\/OT and includes: one workbook for visibility\/reporting, 14 analytics rules for monitoring, and four playbooks for response. The workbook leverages Microsoft Sentinel telemetry to create visualization to understand, analyze, and respond to IoT\/OT threats. Understanding alerts over time provides unprecedented insights into security posture and where teams need to focus to harden against threats. Deep links directly to Microsoft Defender for IoT alerts empower analysts to focus on remediating threats rather than pivoting between tools. <strong>\u00a0<\/strong><\/p>\n<p><strong>Getting started<\/strong><\/p>\n<p>In addition to the video, we\u2019re sharing content designed to provide the foundation of monitoring critical infrastructure with Microsoft Sentinel and Microsoft Defender for IoT. This content is designed to provide the foundation for designing, building, and operating an IoT\/OT monitoring team. Below are the steps to onboard required dependencies, review content, and provide feedback.<\/p>\n<ol>\n<li>Onboard <a href=\"https:\/\/docs.microsoft.com\/azure\/sentinel\/quickstart-onboard\">Microsoft Sentinel<\/a><\/li>\n<li>Onboard <a style=\"background-color: #f7f7f9; font-size: 1rem;\" href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/defender-for-iot\/device-builders\/quickstart-onboard-iot-hub\">Microsoft Defender for IoT<\/a><\/li>\n<li>Connect <a style=\"background-color: #f7f7f9; font-size: 1rem;\" href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/defender-for-iot\/device-builders\/how-to-configure-with-sentinel\">Microsoft Defender for IoT to Microsoft Sentinel<\/a><\/li>\n<li><span style=\"font-size: 12pt;\">Deploy the <em>Microsoft Sentinel: IT\/OT Threat Monitoring with Defender for IoT Solution<\/em><\/span>\n<ol style=\"list-style-type: lower-alpha;\">\n<li><span style=\"font-size: 12pt;\">Microsoft Sentinel &gt; Content Hub &gt; Select <em>IT\/OT Threat Monitoring with Defender Solution<\/em> &gt; Install<\/span><\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<p style=\"padding-left: 80px;\"><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-1.png\"><img decoding=\"async\" class=\"alignnone wp-image-20873\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-1-300x243.png\" alt=\"Image Video 8211 Defender IoT Solution Image 1\" width=\"517\" height=\"419\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-1-300x243.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-1.png 500w\" sizes=\"(max-width: 517px) 100vw, 517px\" \/><\/a><\/p>\n<p style=\"padding-left: 40px;\">\u00a0 \u00a0 \u00a0<span style=\"font-size: 12pt;\">b. In Government Regions, leverage the <em>Deploy to Azure Gov<\/em> button from <a style=\"background-color: #f7f7f9;\" href=\"https:\/\/github.com\/Azure\/Azure-Sentinel\/tree\/master\/Solutions\/IoTOTThreatMonitoringwithDefenderforIoT\">GitHub ReadMe<\/a>.<\/span><\/p>\n<p style=\"padding-left: 80px;\"><a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-2.png\"><img decoding=\"async\" class=\"alignnone wp-image-20874\" src=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-2-300x97.png\" alt=\"Image Video 8211 Defender IoT Solution Image 2\" width=\"374\" height=\"121\" srcset=\"https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-2-300x97.png 300w, https:\/\/devblogs.microsoft.com\/azuregov\/wp-content\/uploads\/sites\/43\/2022\/01\/Video-Defender-IoT-Solution-Image-2.png 758w\" sizes=\"(max-width: 374px) 100vw, 374px\" \/><\/a><\/p>\n<ol>\n<li value=\"5\">Review the <em style=\"font-size: 1rem;\">IT\/OT Threat Monitoring with Defender for IoT <\/em><span style=\"font-size: 1rem;\">Workbook<\/span>\n<ol style=\"list-style-type: lower-alpha;\">\n<li>Microsoft Sentinel &gt; Workbooks &gt; Select <em style=\"font-size: 1rem;\">IT\/OT Threat Monitoring with Defender<\/em><em style=\"font-size: 1rem;\"> for IoT<\/em><\/li>\n<\/ol>\n<\/li>\n<li>Review the<em style=\"font-size: 1rem;\"> IT\/OT Threat Monitoring with Defender for IoT <\/em><span style=\"font-size: 1rem;\">Analytics Rules<\/span>\n<ol style=\"list-style-type: lower-alpha;\">\n<li>Microsoft Sentinel &gt; Analytics &gt; Search \u201cIoT\u201d<\/li>\n<\/ol>\n<\/li>\n<li>Review the<em style=\"font-size: 1rem;\"> IT\/OT Threat Monitoring with Defender for IoT <\/em><span style=\"font-size: 1rem;\">Playbooks<\/span>\n<ol style=\"list-style-type: lower-alpha;\">\n<li>Microsoft Sentinel &gt; Automation &gt; Playbooks &gt; Search \u201cIoT\u201d<\/li>\n<\/ol>\n<\/li>\n<li>Review the content and provide feedback through the <a style=\"background-color: #f7f7f9; font-size: 1rem;\" href=\"https:\/\/forms.office.com\/r\/tqe4bXUEXS\">survey<\/a><\/li>\n<\/ol>\n<p><strong style=\"font-size: 1rem;\">Learn more about defending IoT\/OT with Microsoft Security<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-defender-for-iot-blog\/enabling-iot-ot-threat-monitoring-in-your-soc-with-microsoft\/ba-p\/2902569\">Enabling IoT\/OT Threat Monitoring in Your SOC with Microsoft Sentinel<\/a><\/li>\n<li><a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-defender-for-iot\/\">Defender for IoT product summary<\/a><\/li>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-defender-for-iot\/cloud-delivered-iot-ot-threat-intelligence-now-available-for\/ba-p\/2335754\">Cloud-delivered IoT\/OT threat intelligence<\/a><\/li>\n<li><a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/03\/15\/5-steps-to-enable-your-corporate-soc-to-rapidly-detect-and-respond-to-iot-ot-threats\/\">5 steps to enable your corporate SOC to rapidly detect and respond to IoT\/OT threats<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Also contributing to this blog are TJ Banasik, CISSP-ISSEP, ISSAP, ISSMP, Senior Program Manager, and Katie Thomas, Program Manager, of Microsoft Cloud &amp; AI Security. Security teams traditionally have not had tooling nor the expertise to provide them with visibility to monitor Internet of Things (IoT) \/ Operational Technology (OT) networks for vulnerabilities. As a [&hellip;]<\/p>\n","protected":false},"author":62910,"featured_media":20869,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1,14],"tags":[75,216,3458,315,357,358,502,3457],"class_list":["post-20864","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azuregov","category-learning","tag-azure","tag-cybersecurity","tag-defender","tag-government","tag-internet-of-things","tag-iot","tag-security","tag-sentinel"],"acf":[],"blog_post_summary":"<p>Also contributing to this blog are TJ Banasik, CISSP-ISSEP, ISSAP, ISSMP, Senior Program Manager, and Katie Thomas, Program Manager, of Microsoft Cloud &amp; AI Security. Security teams traditionally have not had tooling nor the expertise to provide them with visibility to monitor Internet of Things (IoT) \/ Operational Technology (OT) networks for vulnerabilities. As a [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20864","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/users\/62910"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/comments?post=20864"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/posts\/20864\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media\/20869"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/media?parent=20864"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/categories?post=20864"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/azuregov\/wp-json\/wp\/v2\/tags?post=20864"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}