Platform component

ShieldCRS

Detection of insider activity: who touched which file, when, and whether that pattern is consistent with the work they do.

For an independent reference point, see Cloud Security Alliance Cloud Controls Matrix.

What it is

Who touched which file, and whether that is normal

Detection built on file-level activity: the access, the copy, the rename, the volume, and the pattern against what that person's role usually looks like.

What it will not do

Two things we will not build and will not advise on

Covert monitoring. Watching people without telling them is unlawful in many jurisdictions, it destroys the trust an organisation runs on when discovered, and it is discovered. We do not supply it.

Judgement about intent. A tool can establish that a file was copied at an unusual hour. It cannot establish why, and a system presented as identifying malicious insiders is overstating what any detection can do.

What it produces is a signal for a person to look at, and the entry on false positives is about what happens when that person is given too many.

Elsewhere

The other components

ACE

Alchemi Compliance Enclave

A governed environment for controlled unclassified information, built on infrastructure that inherits a documented set of controls rather than reimplementing them.

What this does →

AXE

Alchemi Execution Environment

Control over what runs, where, and against which files, applied at the machine on the shop floor rather than at the network edge.

What this does →