Orange County NC Website
Statement of Work <br />Orange County NC <br />v20221005 March 8, 2023 p. 10 of 26 <br />• Automated investigation and remediation including Microsoft Power Automate <br />playbooks. <br />• Security information and event management (SIEM) or API integration (including <br />Azure Sentinel). <br /> <br />Microsoft 365 Defender <br />Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that natively <br />coordinates detection, prevention, investigation, and response across endpoints, identities, email, <br />and apps to provide integrated protection against sophisticated attacks. We provide remote <br />guidance for: <br />• Providing an overview of the Microsoft 365 security center. <br />• Reviewing cross-product incidents, including focusing on what's critical by ensuring the <br />full attack scope, impacted assets, and automated remediation actions that are grouped <br />together. <br />• Demonstrating how Microsoft 365 Defender can orchestrate the investigation of assets, <br />users, devices, and mailboxes that might have been compromised through automated self- <br />healing. <br />• Explaining and providing examples of how customers can proactively hunt for intrusion <br />attempts and breach activity affecting your email, data, devices, and accounts across <br />multiple data sets. <br />• Showing customers how they can review and improve their security posture holistically <br />using Microsoft Secure Score. <br /> <br />The following is out of scope: <br /> <br />• Project management of the customer's remediation activities. <br />• Ongoing management, threat response, and remediation. <br />• Deployment guidance or education on: <br />o How to remediate or interpret the various alert types and monitored activities. <br />o How to investigate a user, computer, lateral movement path, or entity. <br />• Custom threat hunting. <br />• Supporting GCC-High or GCC-DoD (Office 365 US Government). <br />• Security information and event management (SIEM) or API integration (including Azure <br />Sentinel). <br /> <br />Microsoft Defender for Office 365 <br />Microsoft Defender for Office 365 safeguards your organization against malicious threats posed by <br />email messages, links (URLs), and collaboration tools. Defender for Office 365 includes: <br />• Threat protection policies: Define threat-protection policies to set the appropriate level of <br />protection for your organization. <br />• Reports: View real-time reports to monitor Defender for Office 365 performance in your <br />organization. <br />• Threat investigation and response capabilities: Use leading-edge tools to investigate, <br />understand, simulate, and prevent threats. <br />• Automated investigation and response capabilities: Save time and effort investigating and <br />mitigating threats. <br />We provide remote guidance for: <br />• Reviewing Defender for Office 365 Recommended Configuration Analyzer <br />(ORCA). <br />• Setting up evaluation mode. <br />DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6