Blumira detects different types of security events, which we call Findings. The following table describes the different types of Blumira Findings and how you can act on them.
Note: Findings trigger notifications that Blumira sends immediately and according to your users' notification settings. Ensure that your users are able to receive notifications from Blumira to handle findings in an appropriate timeframe.
Type | Description | Priority Level(s) |
Suspect |
Items that cannot be verified as being a threat due to lack of information surrounding the event. Suspect events require further investigation or additional information from you to determine whether to escalate them to a Threat Finding. We may request additional information via workflow questions within Blumira. We may also escalate suspect to a threat based on our professional analysis. Example finding:
|
P1: Respond immediately. P2: Respond within the next day. P3: Respond within the next few business days unless notified otherwise. |
Threat |
An event that we determined, with a high level of confidence, poses an immediate and real threat to the security of data or resources. We will present steps to mitigate or remediate the threat to you via workflow questions in the app. Example findings:
|
P1: Respond immediately. P2: Respond within the next day. P3: Respond within the next few business days unless notified otherwise. |
Risk |
Security events that we determined to be a risk to any organization. Because different organizations have different risk thresholds that rely on a large variety of situations, configurations, and technical controls, Blumira does not assign a risk severity to these Findings. Example findings:
|
Risks have equal priority. Respond according to your organization's assessment of the risk. |
Operational | Items that pertain to day-to-day operations. They are not necessarily security related, but Blumira detected them in our logs.
Example findings:
|
P3: Respond within the next few business days unless notified otherwise. |
System Notification |
Examples:
|
P3: Respond within the next few business days unless notified otherwise. |