Skip to content

Commit 2368e14

Browse files
authored
Merge pull request #879 from tarTech23/amit
Site security updates
2 parents 2616228 + c00c1bd commit 2368e14

File tree

3 files changed

+12
-14
lines changed

3 files changed

+12
-14
lines changed

defender-for-iot/investigate-threats.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -11,19 +11,19 @@ ms.topic: how-to
1111

1212
# Investigate incidents and alerts
1313

14-
Microsoft Defender for IoT in the Microsoft Defender portal displays incidents and alerts, which enhance your network security and operations with real-time details about events logged in your operational technology (OT) network.
14+
Microsoft Defender for IoT in the Microsoft Defender portal displays incidents and alerts, which enhance your network security and operations with real-time details about events logged in your operational technology (OT) network.
1515

16-
Alerts are the basis of all incidents and indicate the occurrence of malicious or suspicious events in your environment. Within an incident, you analyze the alerts that affect your network, understand what they mean, and collate the evidence so that you can devise an effective remediation plan.
16+
Alerts are the basis of all incidents and indicate the occurrence of malicious or suspicious events in your environment. Within an incident, you analyze the alerts that affect your network, understand what they mean, and collate the evidence so that you can devise an effective remediation plan.
1717

1818
Learn more about [alerts](/defender-xdr/investigate-alerts) and [incidents](/defender-xdr/investigate-incidents) in the Defender portal.
1919

2020
In this article, you learn how to investigate a Microsoft Defender for IoT incident and its associated alerts, and how to remediate the security issues raised by the alert.
2121

22-
Alerts in the **Incidents** page uniquely combine IT and OT environment signals to detect potential threats and data leaks. The **Incidents** page displays:
22+
Alerts in the **Incidents** page uniquely combine IT and OT environment signals to detect potential threats and data leaks. The **Incidents** page displays:
2323

2424
- A history of the alerts connected to the incident and an incident graph. The graph shows other devices connected to the affected OT device that might also be compromised.
2525
- Alert descriptions, which explain the type of detected security issue.
26-
- Remediation options to solve the security problem.
26+
- Remediation options to solve the security problem.
2727

2828
> [!NOTE]
2929
> Incident and alert data for Defender for IoT only appear once you have a site set up and your devices are sending data to the Defender portal. Learn how to [set up a site](set-up-sites.md).

defender-for-iot/manage-sites.md

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -22,13 +22,11 @@ When you manage a site, you might need to edit or delete the site information li
2222
To edit or delete a site:
2323

2424
1. In the [Microsoft Defender portal](https://security.microsoft.com/machines) menu, select **Operational technology** > **Site security**.
25-
1. Select the ellipsis (:::image type="icon" source="media/manage-sites/menu-ellipsis.png" alt-text="menu vertical ellipsis button":::) to the right of the site name.
25+
1. Select the ellipsis (:::image type="icon" source="media/manage-sites/menu-ellipsis.png" alt-text="menu vertical ellipsis button":::) to the right of the site name.
2626
1. Select one of the following:
2727

28-
- Select **Edit site**.to open the **Site details** pane, where you can make changes to the site. For more information, see [Site details](set-up-sites.md).
29-
- Select **Delete site** to remove a site from the site list.
30-
31-
This deletes all site-related information for the associated devices.
28+
- Select **Edit site** to open the **Site details** pane, where you can make changes to the site. For more information, see [Site details](set-up-sites.md).
29+
- Select **Delete site** to remove a site from the site list. This deletes all site-related information for the associated devices.
3230

3331
## Add device group
3432

@@ -39,7 +37,7 @@ You can set up a device group at different stages:
3937
- To set up a device group as part of the site setup, see [Add a device group](set-up-sites.md#add-device-group).
4038
- To set up a device group after you set up a site, see [Create and manage device groups](/defender-endpoint/machine-groups).
4139

42-
To get the full benefit of the device group, you might need to create roles and permission settings. For more information, see:
40+
To get the full benefit of the device group, you might need to create roles and permission settings. For more information, see:
4341

4442
- [Role based access control in Microsoft Defender for Endpoint](/defender-endpoint/rbac)
4543
- [Create and manage roles in Microsoft Defender for Endpoint](/defender-endpoint/user-roles)

defender-for-iot/monitor-site-security.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.topic: how-to
1111

1212
# Monitor site security
1313

14-
Microsoft Defender for IoT in the Microsoft Defender portal includes the **Site security** page, which offers an overview of the security state of your entire OT/IoT network. Your organization's security team can use this page to regularly monitor the security status of your production sites.
14+
Microsoft Defender for IoT in the Microsoft Defender portal includes the **Site security** page, which offers an overview of the security state of your entire OT environment. Your organization's security team can use this page to regularly monitor the security status of your production sites.
1515

1616
In this article, you learn how to gain an overview of your site security, so your security team can decide how to prioritize and assign security issues.
1717

@@ -31,7 +31,7 @@ The **Site security** page gives you an overview of the security status of your
3131
- [Review the top **How protected are your sites** section](#review-site-protection-information) to get a general overview of your entire network, including sites with the highest number of devices that are exposed or at risk.
3232
- [Review the site list](#review-the-site-list) to monitor specific security information for each site.
3333

34-
The data displayed in the **Site security** page is the total aggregated data for the entire network, and might include data for sites that you don't have access to. When you drill down into device data from the [site list](#review-the-site-list), the **Device Inventory** page only displays data for devices you can access.
34+
The data displayed in the **Site security** page is the total aggregated data for the entire environment, and might include data for sites that you don't have access to. When you drill down into device data from the [site list](#review-the-site-list), the **Device Inventory** page only displays data for devices you can access.
3535

3636
## Review site protection information
3737

@@ -49,11 +49,11 @@ Review the top **How protected are your sites** section to get the following inf
4949

5050
Review the site specific data in the sites list table.
5151

52-
Note that the data displayed in this table is the total aggregated data for the entire network, and might include data for sites that you don't have access to. When you drill down into device data, the **Device Inventory** page only displays data for devices you can access.
52+
Note that the data displayed in this table is the total aggregated data for the entire environment, and might include data for sites that you don't have access to. When you drill down into device data, the **Device Inventory** page only displays data for devices you can access.
5353

5454
|Column | Description|Next steps |
5555
|----|----|----|
5656
|**Site name** |The site name and description. |- Select the **Site name** to open the **Insights** panel. This panel displays site details, such as total devices, site location, and site owners. You can also select **Edit site** to make changes to the site.<br>- Select the ellipsis (:::image type="icon" source="media/monitor-site-security/menu-ellipsis.png" alt-text="menu vertical ellipsis button":::) to the right of the site name to [manage the site](manage-sites.md).
5757
|**Critical devices** |The number of critical devices at this site. A critical device is a self assigned device that has extra importance to your business or system, such as a server that contains confidential data. |- Use this data to prioritize protection for sites with critical devices.<br>- Select the number to open the **Device Inventory** page, filtered according to the site name and criticality level. |
5858
|**Highly-exposed devices** |The number of highly exposed devices at this site. |Select the number to open the **Device Inventory** page, filtered according to the site name and high exposure level. |
59-
|**Devices with high risk** |The number of high risk devices at this site. |Select the number to open the **Device Inventory** page, filtered according to the site name and high risk level. |
59+
|**Devices with high risk** |The number of high risk devices at this site. |Select the number to open the **Device Inventory** page, filtered according to the site name and high risk level. |

0 commit comments

Comments
 (0)