セキュリティセンターとの統合

表示されるデータ Salesforce Security Center を利用して組織のセキュリティシグナルを監視している場合、Cloud Protection for Salesforce のデータ…

表示されるデータ

Salesforce Security Center を利用して組織のセキュリティシグナルを監視している場合、Cloud Protection for Salesforce のデータをダッシュボードに直接統合できるようになりました。

ファイルスキャン結果、URL スキャンアクティビティ、隔離アクション、アイデンティティ侵害アラートを Security Center 内の「カスタムメトリクス(Custom Metrics)」として登録することで、Cloud Protection for Salesforce が検知した脅威アクティビティを他のセキュリティデータと並べて確認できます。

以下のデータタイプについてカスタムメトリクスを登録可能です。

  • アラート: 設定変更、検知、ジョブステータス、例外、およびグループ化された侵害イベント
  • ファイルスキャンログ: 個別のファイルスキャン結果と判定
  • URL スキャンログ: 個別の URL スキャン結果と判定
  • 侵害ログ: 個別のユーザーアイデンティティ侵害レコード

登録後、各メトリクスは Security Center ダッシュボードに表示され、長期的な履歴トレンドの分析が可能になります

設定手順 

セキュリティセンターへの権限の割り当て

Salesforce の設定で、「セキュリティセンターの管理」へのシステム権限を有効にした新しい権限セットを作成します。この権限セットを適切な管理者ユーザーに割り当てます。アプリケーションランチャーから セキュリティセンター を開きます

カスタム指標の登録

設定 > Security Center > 設定 > カスタムメトリクス > 新規カスタムメトリクス の順に移動し、データタイプごとに1つのメトリクスを作成します。各メトリクスで以下の項目を設定します。

  • データを取得する Salesforce オブジェクト: 「WithSecure File scan logs」、「URL scan logs」、「Breaches」、または「Alerts」を選択します。
  • 表示する項目: 関連する項目を選択します(詳細は下記の「推奨表示項目」をご参照ください)。
  • テナント ID & レコード作成日項目: (組織の識別および履歴トレンドの生成に使用されます)。

各メトリクスの設定が完了したら、保存して有効化します。

メトリクスごとの推奨表示項目

Alerts — AFSC__FS_Alert__c (5 fields)

LabelAPI nameNotes
RecordProductionDateAFSC__RecordProductionDate = CreatedDateThe RecordProductionDate will be auto filled with the created date.
SeverityAFSC__Severity__cInformation / Important / Critical
ReasonAFSC__Reason__cFree-text alert description
SourceAFSC__Source__cScanner that generated the alert
UserAFSC__User__cLinked user or “N users affected”
TenantIdAFSC__TenantId__c15 digit Org Id
File Scan Logs — AFSC__FSFileScanLog__c (9 fields)

LabelAPI nameNotes
Date/TimeAFSC__RecordProductionDate AFSC__Date_Time_Scanned__cScan timestamp; default sort
VerdictAFSC__Verdict__cSafe / Unsafe / Disallowed / Unknown / Error
ActionAFSC__Action__cBlocked / Removed / Passed / Notified
ReasonAFSC__Reason__cFree-text description
Full File NameAFSC__Full_File_Name__cLinks to content document or record
DirectionAFSC__Direction__cUpload / Download / Scan Job
LocationAFSC__Source__cFiles / Attachments / Notes / etc.
UserAFSC__User__cLinked user
IP AddressAFSC__Ip_address__cCaptured at scan time
TenantIdAFSC__TenantId__c15 digit Org Id
RecordProductionDateAFSC__RecordProductionDate = CreatedDateThe RecordProductionDate will be auto filled with the created date and could be different than the scan date time.
URL Scan Logs — AFSC__FS_URL_Scan_Log__c (9 fields)

LabelAPI nameNotes
Date/TimeAFSC__Date_Time_Scanned__cScan timestamp
VerdictAFSC__Verdict__cSafe / Unsafe / Disallowed / Unknown
ActionAFSC__Action__cBlocked / Removed / Passed / Notified
ReasonAFSC__Reason__cFree-text description
URLAFSC__URL__cThe scanned URL
DirectionAFSC__Direction__cOpen / Post / Internal or External Conversation
LocationAFSC__Location__cCases / Chatter / Email / Lead / Task / Field Value
UserAFSC__User__cLinked user
IP AddressAFSC__IP_Address__cCaptured at scan time
TenantIdAFSC__TenantId__c15 digit Org Id
RecordProductionDateAFSC__RecordProductionDate = CreatedDateThe RecordProductionDate will be auto filled with the created date and could be different than the scan date time.
Breach Logs — AFSC__FS_Breach__c (14 fields)

LabelAPI nameTypeNotes
RecordProductionDateAFSC__RecordProductionDate = CreatedDateDateTimeThe RecordProductionDate will be auto filled with the created date.
Publish DateAFSC__PublishDate__cDateTimeWhen the breach was originally published by the breach source.
RiskAFSC__Risk__cPicklistLow / Medium / High / Critical
SeverityAFSC__Severity__cNumberNumeric severity score for the breach.
ReasonAFSC__Reason__cPicklistBreached information / Breached plaintext password.
Plaintext PasswordAFSC__IsPlainTextPassword__cPicklist (Yes / No)Whether the leaked password was exposed in plaintext.
Password TypeAFSC__PasswordType__cText (255)Type/format of the leaked password (e.g. hashed, plaintext).
EmailAFSC__Email__cText (255)Email address tied to the breached account.
UsernameAFSC__UserName__cText (255)Username associated with the breached credentials.
ProfileAFSC__UserProfile__cText (255)Salesforce profile of the breached user.
RoleAFSC__UserRole__cText (255)Salesforce role of the breached user.
UserAFSC__User__cLookup (User)Linked Salesforce user record for the breached account.
Target URLAFSC__TargetUrl__cText (255)Source site/service where the breached data was found.
TenantIdAFSC__TenantId__cText (15)15 digit Org Id

ダッシュボードの確認

設定が完了したら、Security Center ダッシュボードを開き、各メトリクスが表示され、データが正常に更新されていることを確認します。

ノート: メトリクスが空に見える場合は、データの更新(Update Data) をクリックしてください。Security Center は独自の更新サイクルで動作しているため、初期データの読み込みに数分かかる場合があります。

過去データのバックフィル(追記処理)

デフォルトでは、Security Center の必須項目はアップグレード後に作成されたレコードにのみ適用されます。トレンドグラフに過去のレコードも表示させたい場合は、Salesforce Data Loader を使用して最大6ヶ月分のデータをバックフィルできます。この手順は任意です。将来のデータのみが必要な場合は、スキップしても問題ありません。

Before setting up the Security Centre, do I need to configure anything in Cloud Protection for Salesforce?

No additional configuration is required in Cloud Protection for Salesforce. The fields required by Security Center have been automatically included since Release 3.3. You simply need to complete the configuration steps in your Salesforce settings.

Can I choose the type of data displayed in the Security Centre?

Yes. As each data type is registered as a separate custom metric, you have complete control over which metrics are displayed on the Security Centre dashboard.

Will the scan data and alert data I currently have on file be displayed automatically in the Security Center?

By default, only records created after the upgrade to Release 3.3 are displayed in the Security Centre. If you wish to display historical data on trend charts, you can use Salesforce Data Loader to import records dating back up to six months.