Security Validation Quick-Start Workbook

To help you with your Validation Platform deployment, we've created this workbook. It will help you identify your requirements and who you need to work with within your company during deployment. If you are using the SaaS version of Security Validation, some of the Director information will not be pertinent. 

Modules Purchased

ModulePurchased (y/n)
AEDA
Cloud Theater (Mandiant-hosted Actor)
Email Theater
Premium Content
Protected Theater
TAAM

Interested Parties

RoleAccess to Security Validation (y/n)Contact information
Sponsor

Manager

Primary Admin

Secondary Admin

Super User

Receives Reports

Required Installation Information

All Directors

DescriptionValue
Director host informationHostname:
IP address:
Designated interface for Director to listen for connectionsInterface:
License fileLocation of license file: 
Postgres database password

Changing/Setting the password is part of the software install, but a separate step for virtual appliances

Contact for Opening required Ports

Software Directors

DescriptionValue
Director host informationHostname:
Privileged user accountUsername:
Designated services groupGroup:
Check Point integration?Specify: Yes or No
Online repositoryRepository:

All Actors

RequirementData
Designated interface for Director to listen for connections (management Interface)*Interface:

Note: If you only have 1 Actor, you can use DHCP.

Test interface (optional)

Interface:

IP address:
netmask:
gateway:
DNS:
Monitoring interface (optional)

Interface:

IP address:
netmask:
gateway:
DNS:
Contacts for Opening required Ports

NOTE: * You must configure the networking outside of the Validation Platform for Actors on RHEL 8 /CentOS 8

Linux Software Actors

RequirementData
Privileged user accountUsername:
Designated services groupGroup:
Online repository location (optional)Repository:

Network Zones

Zone NameDefended by which Security ToolsActor Type
(endpoint/network/both)

DMZ



Internet



Desktop



Server









Certificates

If self-signed certificates aren't supported, identify the components that need custom certificates and who you need to contact to get those certs. You can use the Director to generate the Certificate Signing Request and apply the certificate to the Director. If you need custom certifications for Actors, there are instructions in the Admin and install guides on how to apply them.

NOTE: Custom certificates can be required in various situations, such as when your Actor is in AWS.

Security Validation ComponentLocation of Component (Zone)POC EmailPOC Department

Director




Actor




Actor




Actor












Network & Endpoint Technologies

To help you identify what technologies you are expecting to see when you run security technology and who you need to contact for more information, populate the following tables.

SIEMs

SIEMVersionIntegration point
(Correlation Engine/ Indexer/Search head)
Brief Architecture Description













SIEMRequired ConnectionsPOC EmailPOC Department













Proxy

ProxyVersionIntegrate with DirectorAuthentication Schema









Proxy continued

ProxyRequired ConnectionsPOC EmailPOC Department









Endpoint Security Technologies

TypeManufacturerVersionEvents to SIEM (y/n)Director Integration (y/n)

AV





DLP





EDR





HIDS/HIPS





EndPoint Security Technologies continued

TypeManufacturerRequired ConnectionsPOC EmailPOC Department

AV





DLP





EDR





HIDS/HIPS





Network Security Technologies

TypeManufacturerVersionEvents to SIEM (y/n)Director Integration (y/n)
Firewall





IDS/IPS





WAF





Malware





Other





Other





Other





Other





Network Security Technologies continued

TypeManufacturerRequired ConnectionsPOC EmailPOC Department
Firewall





IDS/IPS





WAF





Malware





Other





Other





Other





Other





  • May 20, 2022
  • October 31, 2023
In This Article