|
| 1 | +--- |
| 2 | +title: Review security initiatives with Microsoft Defender for IoT in the Defender portal |
| 3 | +description: This article describes how to review security initiatives with Microsoft Defender for IoT in the Defender portal. |
| 4 | +ms.service: defender-for-iot |
| 5 | +author: limwainstein |
| 6 | +ms.author: lwainstein |
| 7 | +ms.localizationpriority: medium |
| 8 | +ms.date: 11/17/2024 |
| 9 | +ms.topic: how-to |
| 10 | +--- |
| 11 | + |
| 12 | +# Review security initiatives |
| 13 | + |
| 14 | +[Security initiatives](/security-exposure-management/exposure-insights-overview#security-initiatives) offer a focused, metric-driven way of tracking exposure in specific security areas using security initiatives. |
| 15 | + |
| 16 | +Microsoft Defender for IoT in the Defender portal allows you to review Microsoft Security Exposure Management security initiatives dedicated to OT and enterprise IoT device protection. |
| 17 | + |
| 18 | +In this article, you learn how to review security initiatives so that your security teams can prioritize, discover, and validate OT-related security findings across your sites. |
| 19 | + |
| 20 | +[!INCLUDE [defender-iot-preview](../includes//defender-for-iot-defender-public-preview.md)] |
| 21 | + |
| 22 | +## OT Security initiative |
| 23 | + |
| 24 | +The **OT Security** initiative improves your OT site security posture by monitoring and protecting OT environments in the organization, and employing network layer monitoring. This initiative identifies devices and ensures that systems are working correctly, and data is protected. |
| 25 | + |
| 26 | +Your security teams can use the **OT Security** initiative to: |
| 27 | + |
| 28 | +- Identify unprotected devices. |
| 29 | +- Harden posture across sites through vulnerability assessments, with actionable guidance to help remediate at-risk devices. |
| 30 | + |
| 31 | +## Enterprise IoT Security initiative |
| 32 | + |
| 33 | +The **Enterprise IoT Security** initiative allows you to identify unmanaged IoT devices and enhance your organization's security. With continuous monitoring, vulnerability assessments, and tailored recommendations specifically designed for enterprise IoT devices, you gain comprehensive visibility into the risks posed by these devices. This initiative not only helps you understand the potential threats but also strengthens your organization's resilience in mitigating them. |
| 34 | + |
| 35 | +Review the full [security initiatives catalog](/security-exposure-management/initiatives-list). |
| 36 | + |
| 37 | +## Prerequisites |
| 38 | + |
| 39 | +- Review the Defender for IoT [prerequisites](prerequisites.md). |
| 40 | +- Review the [prerequisites for the **OT Security** initiative](#prerequisites-for-ot-security-initiative). |
| 41 | + |
| 42 | +### Prerequisites for OT Security initiative |
| 43 | + |
| 44 | +When you view the **OT security** initiative, if you haven't yet onboarded Defender for IoT and set up sites, the **More data is required to support this initiative** section is displayed. |
| 45 | + |
| 46 | +:::image type="content" source="media/review-security-initiatives/more-data-required.png" alt-text="Screenshot showing the **More data is required to support this initiative** section in Microsoft Defender for IoT in the Microsoft Defender portal."::: |
| 47 | + |
| 48 | +If the **More data is required to support this initiative** section is displayed: |
| 49 | + |
| 50 | +1. Review the **Unprotected OT devices** metric to understand the impact on your network. For example, the **Unprotected OT devices** metric shows 24 affected assets. |
| 51 | + |
| 52 | + :::image type="content" source="media/review-security-initiatives/unprotected-ot-devices.png" alt-text="Screenshot showing the Unprotected OT devices metric **Overview** tab in Microsoft Defender for IoT in the Microsoft Defender portal."::: |
| 53 | + |
| 54 | +1. Select **Get started with Microsoft Defender for IoT** and follow the procedure to [onboard Defender for IoT in the Defender portal](get-started.md). |
| 55 | + |
| 56 | +1. Select **create new sites** to [set up sites](set-up-sites.md). |
| 57 | + |
| 58 | +## Review initiatives |
| 59 | + |
| 60 | +1. Follow the procedure to [open the Initiatives page and review an initiative](/security-exposure-management/initiatives#view-initiatives-page). |
| 61 | +1. For the **OT Security** initiative, if you haven't yet onboarded Defender for IoT and set up sites, the **More data is required to support this initiative** section is displayed. In this case, see the [prerequisites for the OT Security initiative](#prerequisites-for-ot-security-initiative). |
| 62 | + |
| 63 | +1. Review the data in the initiative page, including the initiative score, top metrics, and more (learn more about [initiatives](/security-exposure-management/exposure-insights-overview)). For example, this **OT Security** initiative page shows an initiative score of 83%, and shows that 61.9% of the detected OT devices are protected. |
| 64 | + |
| 65 | + :::image type="content" source="media/review-security-initiatives/ot-security-initiative.png" alt-text="Screenshot showing the OT Security initiative in Microsoft Defender for IoT in the Microsoft Defender portal." lightbox="media/review-security-initiatives/ot-security-initiative.png"::: |
| 66 | + |
| 67 | +1. Select the metric from the **Top metrics** area in the initiative page or from the **Related metrics** area in the small overview. |
| 68 | + - Review the **Overview** tab to drill down into additional security data and recommendations, including the weight of the metrics, affected assets, and score impact. For example, the **Unprotected OT devices** metric shows 24 affected assets, and 3.81 score impact. |
| 69 | + |
| 70 | + :::image type="content" source="media/review-security-initiatives/unprotected-ot-devices.png" alt-text="Screenshot showing the Unprotected OT devices metric **Overview** tab in Microsoft Defender for IoT in the Microsoft Defender portal."::: |
| 71 | + |
| 72 | + - Review the recommendations in the **Security recommendations** tab. For example, for the **Site-linked devices using insecure protocols** metric, you're recommended to disable the Telnet administration protocol, and remove the SNMP V1 and SNMP V2 administration protocols. |
| 73 | + |
| 74 | + :::image type="content" source="media/review-security-initiatives/security-recommendations.png" alt-text="Screenshot showing the **Security recommendations** tab for a metric in Microsoft Defender for IoT in the Microsoft Defender portal."::: |
| 75 | + |
| 76 | + Learn more about [working with metrics](/security-exposure-management/exposure-insights-overview#working-with-metrics). |
| 77 | + |
| 78 | +## Next steps |
| 79 | + |
| 80 | +[Learn about vulnerabilities](discover-vulnerabilities-overview.md) or proceed to [investigate and remediate vulnerabilities](prioritize-vulnerabilities.md). |
0 commit comments