Incident response workflow can be found at Alert Center Module. Alert Center Module used to automatically monitor data flows and alert security officers about any possible data breaches. Alert Center Module platform:
- Client-server architecture, installed on a dedicated server.
- Scans intercepted documents and sent notifications if any words or texts match the search queries.
- Installed on a security officer’s workstation and is used to set up security policies.
- Supports indexes and databases created by the Risk Monitor components.
Alert Center monitors:
- File/Documents stored on hard drives of domain workstations
- All Data transferred to removable media ( USB, CD/DVD, external drives, Bluetooth adapters, etc)
- Incoming and outgoing (inbound outbound) FTP traffic
- Messages posted to web blogs and Internet forums (GET and POST requests)
- Instant messages and social (social media) network messages (Facebook, LinkedIn, etc)
- E-mails sent via mail clients or web mail services
- History of file (records file) operations on file servers or workstations
- Employee (user) conversations in office
- Data displayed (On-screen content ) user screens monitor
- All documents sent to local or network printers
- Text and voice messages, files and SMS sent over Skype
- Files and contact list, text and voice messages sent over Viber
- Files and contact list, text and voice messages sent over Telegram
- Files and contact list, text and voice messages sent over WhatsApp
