Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Security/SIEM Text on Kibana Home #67460

Closed
MikePaquette opened this issue May 27, 2020 · 19 comments
Closed

Update Security/SIEM Text on Kibana Home #67460

MikePaquette opened this issue May 27, 2020 · 19 comments
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM v7.9.0

Comments

@MikePaquette
Copy link

Issue: The text under the Security section of the Kibana Home pages needs to be updated in time for the 7.9 Stack release.

Screen Shot:
image

Current Text: SIEM
Centralize security events for interactive investigation in ready-to-go visualizations.

Proposed Text (Option 1): Security
Investigate security events, hunt threats, automate detections, create cases, manage endpoint security.

Proposed Text (Option 2): - [Expand the Security section from 25% of the page width (1 of 4 columns) to 40% of the page width (2 of 5 columns) by adding a second column under security]. SIEM
Analyze security information and events, hunt threats, automate detections, create cases.

Endpoint Security
Manage endpoint security policy, analyze endpoint alerts with global context, create cases.

cc: @lindseypoli @XavierM @spong @bradenlpreston

@MikePaquette MikePaquette added Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! Team:SIEM v7.9.0 labels May 27, 2020
@elasticmachine
Copy link
Contributor

Pinging @elastic/kibana-security (Team:Security)

@elasticmachine
Copy link
Contributor

Pinging @elastic/siem (Team:SIEM)

@MikePaquette MikePaquette removed the Team:Security Team focused on: Auth, Users, Roles, Spaces, Audit Logging, and more! label May 27, 2020
@lindseypoli
Copy link

@MikePaquette @bradenlpreston

Here is what Option 1 looks like:
Screen Shot 2020-06-30 at 1 48 11 PM
Wondering if it's strange to see "Security" in there twice? Because of that I'm leaning toward Option 2, but how do we feel about breaking out the SIEM and Endpoint use cases so explicitly?

Also, wanted to pull in here @jmikell821 to review the language.

@bradenlpreston
Copy link

bradenlpreston commented Jul 1, 2020

Option 2. I think breaking the 2 use cases our separately is ok. Our website will have those 2 use cases under security as well.

If we can't get the extra space perhaps something to the effect of:

Solution Name: Security
Sub-heading: SIEM + Endpoint Security (Or SIEM + EPP/EDR)
Description: A single application to protect hosts, analyze security information and events, hunt threats, automate detections, and create cases.

@lindseypoli
Copy link

@bradenlpreston Sounds great to me! 👍 Just checked with @XavierM and he will plan to make this change along with the changes we discussed for "Detections" https://github.com/elastic/endpoint-app-team/issues/412#issuecomment-652028915

@lindseypoli
Copy link

@bradenlpreston @MikePaquette @XavierM

FYI I just learned that the updated design for the Kibana homepage may be introduced in 7.9 (though it's not 100% guaranteed and may slip to 7.10).

This is the updated design: #25734 | Figma Mocks

Screen Shot 2020-07-02 at 8 59 18 AM

Are there changes that we want to make to this copy?

Security
Protect & prevent →
Detect critical security events.
Investigate incidents and collaborate.
Prevent threats autonomously.

@bradenlpreston
Copy link

CCing @jae-elastic and @MarkSettleES

I dont think we need "Protect and Prevent" Can we change this to just "Protect" or "Protect your Environment"

For the 3 bullets, can we use our 3 core value props:

Eliminate Blind Spots
Stop Threats at Scale
Arm Every Analyst

Alternate Suggestion
Prevent Threats Autonomously
Detect and Respond to critical security events
Investigate incidents

@caitlinbetz
Copy link

caitlinbetz commented Jul 14, 2020

Wanted to bump this to make a final decision on this as we want this in before feature freeze - (today :) )

Current Kibana homepage design —
Sub-heading option # 1: SIEM + Endpoint Security
Sub-heading option # 2: SIEM + EPP/EDR

Description option # 1: A single application to protect endpoints, analyze security information and events, hunt threats, automate detections, and create cases.
Description option # 2: Standardize data collection and manage/ensure endpoint security with integrated protection.

Updated Kibana homepage design —
Option # 1:
Eliminate Blind Spots
Stop Threats at Scale
Arm Every Analyst

Option # 2
Prevent Threats Autonomously
Detect and Respond to critical security events
Investigate incidents

@bradenlpreston @MikePaquette @jae-elastic Could we get your thoughts on the above so we can finalize this language?

@lindseypoli
Copy link

We confirmed that the updated homepage design will not make it into 7.9, so we just need to finalize the language we want to use for the current homepage design.

@bradenlpreston
Copy link

Solution Name: Security
Sub-heading: SIEM + Endpoint Security
Description: A single application to protect hosts, analyze security information and events, hunt threats, automate detections, and create cases.

@alexfrancoeur
Copy link

It won't make 7.9, but we will have it for 7.10 and @cqliu1 is progressing nicely (#70571). We're in the process of iterating through the text now and I see some brainstorming happening in this issue. Please feel free to drop a comment in the PR or related issue with any thoughts. cc: @gchaps

@gchaps
Copy link
Contributor

gchaps commented Jul 16, 2020

@bradenlpreston For consistency with the other descriptions, it would be better to start the description with a verb. Also is "single-app" needed?

So maybe

Protect hosts, analyze security information and events, hunt threats, automate detections, and create cases.

If "single app" is needed:

Protect hosts, analyze security information and events, hunt threats, automate detections, and create cases, all within a single app.

Which three bullet points did you prefer? For option #2, the second bullet point is too long for the space.

@bradenlpreston
Copy link

Good with this - "Protect hosts, analyze security information and events, hunt threats, automate detections, and create cases."

Update to bullet 2 - "Detect and Respond"

@XavierM
Copy link
Contributor

XavierM commented Jul 16, 2020

here we go <3

image

@gchaps
Copy link
Contributor

gchaps commented Jul 16, 2020

Thanks, @bradenlpreston. For the 7.10 home page, can you let me know whether you want Option 1 or Option 2 for the bulleted list. If option 1, how about using "Investigate incidents" instead of "Arm every analyst".

Option # 1:
Eliminate blind spots
Stop threats at scale
Arm every analyst

Option # 2
Prevent threats autonomously
Detect and respond
Investigate incidents

@bradenlpreston
Copy link

Let's go with this:
Option # 2
Prevent threats autonomously
Detect and respond
Investigate incidents

@bradenlpreston
Copy link

@XavierM and @MikePaquette General question: Can we change the "Add Events" under security to - "Add Security" - like under APM. We do more than just events now.

@gchaps
Copy link
Contributor

gchaps commented Jul 20, 2020

@bradenlpreston Can we use this or something similar?

"Detect and respond to events"

ML landed on this text, and I don't want them to sound too similar

"Model, predict, and detect behavior"

@bradenlpreston
Copy link

bradenlpreston commented Jul 20, 2020

@gchaps - I prefer to keep it as "Detect and Respond" - while everything at its core is an event, I dont want to make it sound generic. We can build complex rules to detect behaviors an other unwanted activity that expand beyond events.

@MindyRS MindyRS added the Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. label Oct 27, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Team: SecuritySolution Security Solutions Team working on SIEM, Endpoint, Timeline, Resolver, etc. Team:SIEM v7.9.0
Projects
None yet
Development

No branches or pull requests

9 participants