Use PDIs? Take our 5-minute survey to help shape the PDI roadmap.

ShaunaV
ServiceNow Employee

Step 1: Identify Goals and Use Cases 

Step 2: Determine Data Sources 

Step 3: Deploy Collectors 

Step 4: Connect Data Sources and Integrations 

Step 5: Configure Key Components 

 

Through onboarding you will identify your goals for a successful Armis platform deployment. 

  • Do you need to ensure you are meeting compliance requirements for a customer or agency? 
  • Are you growing rapidly and need systems in place to ensure all assets are accounted for and protected? 
  • Are you a company with a large third-party presence who needs to ensure your infrastructure is protected? 

Predeployment Considerations 

The first step in any deployment is the “discovery phase.” Asking yourself the following questions helps formulate a better understanding of your goals and requirements for successful deployment: 

What problems are you trying to address? 

  • Device Visibility? 
  • Data Aggregation? 
  • Threat Analysis? 
  • Vulnerability Management? 

What are some of your current initiatives? 

Who will be consuming the data and how will it be consumed? 

What are the success criteria you are aiming for? 

What are some of your current technology stacks? 

  • Switching? 
  • Wireless LAN Controller (WLC)? 
  • Endpoint Security? 
  • Microsoft System Center Configuration Manager/Active Directory (SCCM/AD) 
  • Mobile Device Management (MDM)? 

Use Cases 

The Armis platform provides valuable data security and device usage insight and assistance for various personnel in multiple organizations. The documents listed in the following table outline use cases that your various teams (Vulnerability Managers, Network Operations, IT and Security Operations, and AssetManagers) can leverage to accomplish their goals. Although processes will differ, you can use the use cases described below as a starting point: 

 

Use Case Type

Example Use Cases 

Use Cases for the Asset Management 

Deep Discovery and Understanding of All Assets 

  • New Device Discovery in the Last Day 
  • New Device Discovery by the Device Type of "Desktop" in the Last Day 
  • New Device Discovery at Your Site in Dublin in the Last Day 
  • Device Discovery by the Ubuntu OR Debian Operating System 
  • Discovery of Manufacturing IOT Devices Located on Your Corporate Boundary 
  • Device Discovery Filtered by MacBook 
  • Device Discovery of the Office application at Version 016 in the Corporate Boundary 
  • Device Discovery NOT having the “Symantec Endpoint Protection” Application at Your Site in “Wichita” 

Use Cases for Security Operations 

Use Case: Network Threat Detection & Response  

  • Unencrypted Credentials Usage 
  • Corporate Device Experiencing a Threat 
  • Attack Attempt on a Device at the Lisbon Site 
  • Discovery of Heavy Port Scans 
  • Discovery of Devices Exhibiting Anomalous Behavior 
  • Corporate Device with a Potential Zeppelin Ransomware Infection 
  • Multiple SMB Authentication Failures in a Short Period 

Use Cases for the Vulnerability Manager 

  • High Severity Vulnerability Discovery 
  • High Severity Vulnerability Discovery on the Corporate Network 
  • High Severity Vulnerability Discovery on the Corporate Network at the London site 
  • Vulnerability Discovery on Manufacturing Devices 
  • “Urgent 11” Vulnerability Discovery 
  • Vulnerability Discovery of CVE-2019-0708 
  • Discovery of KB 4516115 Downloads (AVM add-on License required) 

 

 

Once you determine the best use case for your situation, you can: 

  • Save these as policies. 
  • Add to existing policies. 
  • Build dashboards to visualize the data within your environment. 
  • Save as reports within Armis. 
  • Run these manually and export the results to complete tasks such as: 
  • Compare results to your current Configuration Management Database (CMDB) device inventory or device configuration management records. 
  • Supplement, enhance, or supersede current network operations alerting procedures and processes. 
  • With additional queries you can filter the data to view exactly what you need, including attributes such as device type, device model, device brand, applications installed, and operating system installed. 
  • Supplement, enhance, or supersede current vulnerability management data and processes. 

 

Version history
Last update:
2 hours ago
Updated by:
Contributors