Upwind Q&A

Potentially outdated

This page was last updated 14 months ago (on 2025-01-23). Verify the information is still accurate before relying on it.

We have surface level action items unfolding and have been since December 2024 and as we unwrap this quarter, we have deeper, more vivid points to consider ensuring operational efficiencies and also technical and secure solutions.

I am listed the following talking points which I believe warrant a discussion and consensus among the groups/product owner e.g. rass/cass/empi

  1. Onboarding/Offboarding - Is UPWIND going to sync up with Microsoft ENTRA and thus allows Single Sign On(SSO) ?

A. Does IT have this instruction set defined or how will they “know” to enable this?

B. If unmanaged by IT (via MS Entra), who and how is user lifecycle management going to be managed?

C. Do we have a license and or user count limitation e.g. based on seat/licenses to consider?

D. Access to the platform – I presume product owner will own/manage their own “portal” however, do we need to consider other departments e.g. Support team?

  1. License/UPWIND Package Details?

A. What service/package do we have?

B. Will the vendor provide training/support on “how to use/implement etc?”

C. What is our support contact model? ( we are relating the AWS ENTERPRISE SUPPORT as a comparison )

  1. UPWIND use case?

A. What functionality does Upwind have in our Cloud Security Stack?

B. What is the overlap with Sentinel One? e.g. Vulnerability Management overlap.

C. I have become aware that a team member will be forwarding CRITICAL CVE notices to a given product owner; how will notices come forward? What is our expected “response time”? How do we handle exclusions – self declared or N/A scenarios or common “mistakes” in which they are not applicable.

  1. UPWIND uniform policies/unified settings

A. Do we have a global ( all product) usage model for tagging schema or naming conventions?

B. For specific settings such as the “SENSOR”, are we unifying the settings – update lifecycle based on “x” time, check in, and “EXCLUSIONS”?

  1. UPWIND Alerts/Monitor Configurations

    1. In satisfying the question of “are we safe/secure”, Do we have a baseline of alerts based on a framework e.g. MITRE? Similar to AWS GuardDuty/Security Hub having a “percentage” compliant per a framework i.e. Cloud Security Posture Management – AWS Security Hub Features – Amazon Web Services

    2. Uniform ALERTS e.g. unencrypted S3 buckets with “open to the internet” ?

  2. UPWIND - Communication of progress

    1. We are aware of a “SLACK” channel that is being used as a medium to collaborate.

      1. Can EMPI team(everyone) be included?

      2. Do we have a list of support contacts, methods and phone numbers?

  3. a

  4. a

9.