This website uses cookies. By continuing to browse the site, you confirm your consent to the use of these files.

Security Vision — Information Security Management and SOC Platform

Software

Security Vision is a Russian company and developer of its namesake platform for information security management, event monitoring (SIEM), and security operations center (SOC) building. The company was founded in 2016 and is headquartered in Moscow. Security Vision is one of the leading Russian developers in the field of information security, offering comprehensive solutions for threat monitoring, incident management, and security process automation. The company's product is included in the Unified Registry of Russian Software of the Ministry of Digital Development (entry No. 10124 dated 15.11.2021) and meets the requirements for use in government agencies and critical information infrastructure (CII) facilities.

Official website: securityvision.ru

About Security Vision

Security Vision was founded in 2016 and is headquartered in Moscow. Since its founding, the company has specialized in developing software solutions for information security management, event monitoring, and SOC building.

Security Vision has its own R&D center, which enables a full development and release cycle — from architecture design to final testing and deployment. The company holds FSTEC Russia certificates confirming that its products meet information security requirements.

The Security Vision portfolio includes over 10 products and modules for information security. The products are used by major companies, banks, government agencies, and CII facilities across Russia.

Security Vision Product Categories

1. Security Vision — Information Security Management Platform

The company's core product is the Security Vision platform, which combines event monitoring (SIEM), incident management (IRM), vulnerability management (VM), and security process automation capabilities.

Architecture and Technology Stack

  • Architecture: client-server, modular, with support for distributed installations.
  • Technology stack: Java, Python, PostgreSQL, Elasticsearch, Kafka, Docker, Kubernetes.
  • Integration: support for over 200 integrations with security systems, network equipment, operating systems, and cloud services.

Security Vision Functional Capabilities

  • Event Monitoring (SIEM): centralized collection and analysis of security events from various sources — firewalls, intrusion detection systems, antivirus solutions, access control systems, servers, network equipment, and cloud services. Support for event correlation to detect complex attacks and automatic incident detection using rules and ML algorithms.
  • Incident Management (IRM): full incident lifecycle management — from detection to investigation and closure. Automatic incident classification by severity, support for playbooks for rapid response, integration with ticketing systems (ServiceNow, Jira, OTRS) for automatic ticket creation.
  • Vulnerability Management (VM): centralized management of the vulnerability identification, assessment, and remediation process. Integration with security scanners (MaxPatrol, XSpider, Nessus, Qualys), automatic assignment of vulnerability remediation owners, tracking remediation status, and report generation.
  • Asset Management (CMDB): maintaining an information asset registry with detailed information on each item — software, versions, installed updates, criticality level. Automatic asset discovery through integration with inventory and network scanning systems.
  • Risk Management and Compliance: protection level assessment based on asset, vulnerability, and incident data. Support for regulatory requirements (152-FZ, 187-FZ, 242-FZ, FSTEC Russia orders) and industry standards (PCI DSS, ISO 27001). Automatic report generation for regulators and management.
  • Security Process Automation (SOAR): automation of routine incident response tasks. Support for playbooks (automated response scenarios) for IP address blocking, notification sending, artifact collection. Integration with over 50 security systems for automatic action execution.
  • Visualization and Dashboards: interactive control panels for real-time security status monitoring. Customizable widgets for displaying key performance indicators (KPIs) — number of incidents, vulnerabilities, remediation status. Support for geographic maps for visualizing attack sources.

2. Security Vision Extension Modules

Security Vision offers extension modules for addressing specific tasks.

Extension Modules

  • Security Vision GRC: module for managing regulatory compliance, including 152-FZ, 187-FZ, 242-FZ, and FSTEC Russia orders. Automation of audit preparation and report generation processes.
  • Security Vision Threat Intelligence: module for collecting and analyzing threat information from open and commercial sources. Automatic event enrichment with threat data to improve detection accuracy.
  • Security Vision Vulnerability Management: module for automated vulnerability management with SLA control and report generation.
  • Security Vision Asset Discovery: module for automatic network asset discovery.

3. Security Vision Services

Security Vision offers services for platform implementation and support.

Services

  • Security Vision Implementation: full implementation cycle — from requirements gathering to commissioning and staff training. Support for both on-premise and cloud deployment.
  • Integration with Customer Systems: configuration of integration with existing security systems, network equipment, and operating systems. Development of custom event collectors for non-standard sources.
  • Correlation Rule Configuration: development and configuration of correlation rules for detecting specific threats tailored to the customer's infrastructure.
  • Staff Training: training for platform administrators and SOC analysts on working with Security Vision.
  • Technical Support: around-the-clock technical support (24/7) with guaranteed response times (SLA). Remote and on-site support available.

Certification and Compliance

  • Security Vision is included in the Unified Registry of Russian Software of the Ministry of Digital Development (entry No. 10124 dated 15.11.2021).
  • The platform is certified by FSTEC Russia for use in systems with high information security requirements.
  • Complies with the requirements of 152-FZ (personal data), 187-FZ (critical information infrastructure), 242-FZ (information protection in government information systems).
  • Complies with the requirements of 44-FZ and 223-FZ for government procurement.

Enterprise Deployment

  • CII Facilities: Security Vision for building security operations centers at critical information infrastructure facilities.
  • Government Agencies: platform for ensuring regulatory compliance and protecting government information systems.
  • Financial Sector: solutions for threat monitoring and incident management in banks and financial organizations.
  • Industry and Energy: platform for protecting industrial control systems (SCADA) and industrial networks.
  • Telecommunications Companies: network security monitoring and incident management.

Technical Support

Security Vision provides warranty and post-warranty maintenance through its own technical support service. Remote support, on-site engineer visits, version updates, and update delivery are available. The warranty period for software is 12 months with the option to extend.

Key Components of the Security Vision Platform

1. Security Event Monitoring (SIEM)

Centralized collection and analysis of security events from various sources — firewalls, intrusion detection systems, antivirus solutions, access control systems, servers, network equipment, and cloud services.

Event Sources

  • Network Equipment: switches, routers, firewalls (Cisco, Check Point, Fortinet, Qtech, Eltex).
  • Operating Systems: Windows, Linux (Astra Linux, RED OS, Alt Linux).
  • Applications and Services: web servers, databases, mail servers, cloud platforms (AWS, Azure, Yandex Cloud, VK Cloud).

Event Correlation

  • Correlation Rules: detection of complex attacks based on combinations of events from different sources.
  • ML Algorithms: automatic anomaly detection and identification of new threat types.

2. Incident Management (IRM)

Full incident lifecycle management — from detection to investigation and closure.

Incident Classification

  • Automatic Classification: by severity and threat type.
  • Manual Classification: ability for analyst-driven manual refinement.

Playbooks

  • Standard Playbooks: response templates for typical incidents.
  • Custom Playbooks: creation of custom response scenarios tailored to specific customer tasks.

Ticketing System Integration

  • ServiceNow: automatic creation of incident remediation tickets.
  • Jira: integration with project management systems for remediation tracking.
  • OTRS: support for open-source ticketing systems.

3. Vulnerability Management (VM)

Centralized management of the vulnerability identification, assessment, and remediation process.

Security Scanner Integration

  • MaxPatrol: integration with the Positive Technologies vulnerability scanner.
  • XSpider: vulnerability scanner support.
  • Nessus: integration with the popular vulnerability scanner.
  • Qualys: cloud-based vulnerability scanner.

Remediation Management

  • Owner Assignment: automatic assignment of vulnerability remediation owners.
  • Status Tracking: monitoring of remediation deadlines and progress.
  • Reporting: vulnerability reports for management and regulators.

4. Asset Management (CMDB)

Maintaining an information asset registry with detailed information on each item.

Asset Inventory

  • Hardware: servers, storage systems, network equipment, workstations.
  • Software: operating systems, applications, versions, installed updates.
  • Criticality: assessment of asset criticality to the business.

Automatic Discovery

  • Inventory System Integration: data import from asset management systems.
  • Network Scanning: automatic discovery of new network assets.

5. Risk Management and Compliance

Protection level assessment based on asset, vulnerability, and incident data.

Regulatory Requirement Support

  • 152-FZ: personal data protection requirements.
  • 187-FZ: critical information infrastructure protection requirements.
  • 242-FZ: government information system protection requirements.
  • FSTEC Russia Orders: information protection tool requirements.

Industry Standards

  • PCI DSS: payment card data protection requirements.
  • ISO 27001: information security management standard.

Report Generation

  • For Regulators: reports for FSTEC, Ministry of Digital Development.
  • For Management: dashboards and reports on key performance indicators.

6. Security Process Automation (SOAR)

Automation of routine incident response tasks.

Standard Actions

  • IP Address Blocking: automatic blocking of suspicious IP addresses.
  • Notification Sending: alerting responsible persons via SMS, email, and messengers.
  • Artifact Collection: automatic data collection for investigation.

Security System Integration

  • Over 50 integrations for automatic action execution.
  • API support for integration with any system.