Fortified's WISdom provides an agentless data collection service that efficiently gathers system, metadata, and runtime data from each system. Leveraging the robust capabilities of Microsoft Azure, WISdom ensures the secure transfer and storage of this data, both during transit and at rest. The data is processed by the WISdom service, which operates locally on virtual machines (VMs) to securely monitor and collect data from managed servers.
The local WISdom application communicates with the Fortified cloud to receive updates and serves as the ingestion point for your environment’s database statistics. PowerShell scripts are utilized to collect and store monitoring information, which is then sent to a dedicated Azure API for further processing and storage in the backend Azure Database.
Each client's data collector service is equipped with a unique key pair for secure data transfer and processing. All data is encrypted using this dedicated key pair, provided by Fortified, and is automatically updated on a weekly basis.
Additionally, WISdom's architecture includes several layers of security to ensure data integrity and confidentiality. These layers include advanced encryption standards, regular security audits, and compliance with industry best practices.
For comprehensive details, download the full WISdom Requirement Document.pdf, which contains all the information available in the Installation Requirements sections of this User Guide.
Security Protocols and Features
WISdom Services are meticulously designed to ensure optimal performance with minimal impact, while upholding stringent security standards. Below are the essential security protocols and features integrated into the WISdom application:
-
Data Collection: WISdom gathers metadata, runtime, and configuration data using WMI and SQL calls. Importantly, no sensitive data is transferred to the Fortified WISdom environment, ensuring privacy and security.
-
Frequency of Collection: To optimize resource usage, WISdom intelligently collects data based on necessity, ranging from once a minute to once a week, depending on the data type. This adaptive approach ensures efficient data management without overloading the system.
-
Upload Process: All uploaded information is encrypted using TLS and sent to the Azure API for processing. Once processed, the data is sent to each client's individual database, allowing for additional formatting and storage. This ensures the data is ready for display in the WISdom UI.
-
Access to Encrypted Data: Configuration updates are securely transmitted through an Azure API connection, encrypted using a certificate pair. This certificate pair is stored exclusively on our central server and the client's machine running the WISdom service. Access to the data and encryption keys is strictly limited to the client and Fortified, ensuring that only authorized parties can access sensitive information.
-
Additional Security Measures: WISdom's architecture includes several layers of security to ensure data integrity and confidentiality. These layers include advanced encryption standards, regular security audits, and compliance with industry best practices. Regular updates and patches are applied to maintain the highest level of security.