Fortinet- FortiSOAR - Add value to SOC
Use Cases and Deployment Scope
FortiSOAR is only Security Orchestration Automation & Response tool that has extensive product capability & flexibility, tied to case management & leverage the power of Forti Security Fabric reducing the Burdon of Security operation center (SOC) team ultimately working as force multiplier for teams to response faster- vital to reducing the threat landscape for organizations .
FortiSOAR remedies alert fatigue & false positives by centralizing & aggregating alerts enriching them with add context while corelating them across a security stack to rapidly investigate . This includes custom playbook for triage process. Accelerating incident response & optimizing security operations.
Pros
- FortiSOAR address complexity by providing 160 +ply books & 300 Connectors to easily integrate with deployed security controls to ingest information & provide single point of control.
- FortiSOAR resolves collaboration complexities by providing teams with a comprehensive war room, module builder, granular RBAC, Segmenting Teams , duties and process . Seamless connecting all an organization s team together .
Cons
- Training Services- Fortinet offers courses geared towards administration and designed and development of FortiSOAR , Which required multiples access , we need all training services with self pace basis , I think here Fortinet need to improve.
- Licensing Model- Being as a new technology Licensing model should be crystal & Clear, be it Concurrent Users or The number of FortiSOAR nodes there should be no ambiguity .
Likelihood to Recommend
Most organization with medium & maturity SOC struggle with alert fatigue & false positives with addressing alert volume is result in increasing risk of critical alerts being masked by trivial one , in this situation FortiSOAR help in case management : rapidly response in case of crises also.
FortiSOAR is designed very well where Fortinet have other stack of security component also like Fortinet NGFW & Forti SIEM etc.. Fortinet NGFW can and generate the FortiSOAR instance through FortiCloud for Customer .
However In absence of FortiFabric it require lot of connectors to work well the solution.