Service Content | Service Content | Delivery Standard |
Security Assessment Service | Comprehensively assesses the security status of users' cloud-based hosts through security specifications, a policy library, and an assessment analysis engine, identifies risks in users' hosts, networks, applications, and data, and the assessment includes: Internet-facing risk assessment: It identifies and assesses the exposure surfaces and security risks on the internet side, and categorizes them based on risk levels. Cloud asset security assessment: It analyzes the software composition of cloud-based hosts (this service item requires the host to have CWPP installed), evaluates the cloud network architecture and security group segmentation, and identifies security risks. Security product policy optimization: It evaluates the coverage and policies of the cloud security products used by the customer, including WAF, CWPP, and CFW, to identify security risks. Security risk detection: It detects cloud-specific security risk items, such as COS bucket policy configurations and AK key leaks, to identify security risks. Attention: Due to the complexity of computer systems and the limitations of network security technology, Tencent Cloud cannot guarantee that all security risks will be identified during the security assessment process. | Once per quarter. Deliver the Security Assessment Report. |
Risk Management Service | Performs weekly risk checks on host security baselines, configuration policies, and cloud accounts, and assists in risk management: Baseline verification service: It analyzes the security baselines of user hosts, and assesses and reports on items such as weak passwords and unauthorized access. Configuration policy verification: It evaluates and reports on items such as security protection coverage, security product policies, and cloud product configurations. Cloud account verification: It evaluates and reports on items such as multi-factor authentication for cloud accounts, inactive accounts, and AK keys. | Continuous service. Deliver the Risk Tracking Report and update it weekly. |
Threat Management Service | Continuously monitors alarm events from users' cloud-based host security products, analyzes, responds to, and operationally optimizes security events, and the service includes: Security monitoring and analysis: It monitors the network security status in real-time 5*8, and promptly conducts analysis and provides alerts. Security incident analysis and handling: It performs traceability analysis on compromised security incidents. AK key leak detection: It detects AK key leak incidents for user cloud accounts on code platforms such as GitHub. | Continuous daily monitoring. Deliver the Service Operations Weekly Report. |
Security Hardening Service | Notifies and assists users in conducting response and remediation for severe or high-risk security events identified during various stages such as assessment, monitoring, and detection, including: Security hardening recommendations: It provides vulnerability and risk remediation solutions, as well as security hardening guidance. | Continuous service. Service outcomes are included in the Security Assessment Report and the Risk Tracking Report. |
CIRS | Provides timely incident response analysis and professional remediation when user operations encounter abnormal situations such as hacker attacks, reducing losses from unexpected events: CIRS: It handles incidents such as mining viruses, file tampering, trojan backdoors, and botnets using tools and methods, helping customers quickly restore business operations and eliminate or mitigate the impact. Attention: Prerequisite for CIRS provision: Purchase MSS for a minimum of three months or more in a single transaction. The scope of CIRS does not include tracing attacker identities. | Provided on demand, at most once per quarter. Provide the Emergency Response Report upon service completion. Trigger conditions include two scenarios: . 1. The user proactively requests emergency response support. 2. The MSS service team detects an anomaly and initiates emergency response. |
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback