Lacework - Cloud Security, Polygraph Data Platform
Lacework offers automated anomaly detection providing consistent visibility, context, and security across cloud environments, providing customers with the ability to detect attack activity stemming from known and unknown threats. Lacework uses data and automation facilitating the security of multi-cloud environments, helping customers prioritise risk, so they can innovate with confidence.
Features
- Cloud Security
- Threat Detection
- Vulnerability Management
- Cloud Security Posture and Compliance
- Infrastructure as Code Scanning
- Attack Path Analysis
- Cloud Infrastructure Entitlement Management
- Behaviour based network traffic analysis
- Available on AWS Marketplace
Benefits
- Improve productivity by providing a unified and collaborative security dashboard
- Eliminate risk found throughout your development pipeline
- Reduce costs through preemptive security
- Enhance Cloud Visibility with a plethora of relevant dashboards
- Eliminate need for rule-writing with pre-built use cases
- Meet rigorous compliance standards through industry-standard framework compliance reporting
- Consolidate security tooling and prevent tool sprawl
- Reduce security alert volume
- Reduce security alert investigation time
Pricing
£41.32 a unit a year
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
6 3 5 7 7 4 5 2 2 4 4 8 9 4 1
Contact
Somerford Associates Limited
Penny Harrison
Telephone: 07897075103
Email: penny.harrison@somerfordassociates.com
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Not applicable
- System requirements
- Supported operating systems: https://docs.lacework.com/supported-operating-systems
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- Mon-Fri 9am-5:30pm excl bank holidays customers receive an initial response within one business hour
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- We provide support from priority 1 to priority 4 cases on any existing configuration or part of the platform that is in total or partial failure as well as not working as expected. We also provide configuration guidance and recommendations for use cases. Each customer receives their own Account Manager who works closely with Support and ensures that cases can be followed up. Somerfords Support desk is available as a value added service in addition to the maintenance and support purchased alongside the license.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Getting started documentation is available at https://docs.lacework.com/
Lacework also provides a Customer Success program to ensure successful adoption of the Polygraph Data Platform, as well as training from our Professional Services function. An onboarding wizard is also available. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Customers can access their data throughout the contract via REST API. Additionally, S3 export and Snowflake data share options are available throughout the duration of the contract. Please see https://docs.lacework.com/category/data-shares--export
- End-of-contract process
- All customer data is deleted in accordance with the standard retention policies.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Form factor differences when accessing web-page.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Accessible via web browser. Allows for interaction with your Lacework deployment/environment. Contains multiple different dashboards on reporting, configuration, code security, attack path analysis, vulnerability management and compliance management.
- Accessibility standards
- None or don’t know
- Description of accessibility
- The UI/UX team has been investing in efforts to meet accessibility standards with Section 508 to ensure that the Lacework platform is usable, comprehensible, and resilient for all individuals, regardless of their abilities or disabilities. 70% of the product (in light mode) meets WCAG level AA standards, with a slight lower adoption rate in dark mode. The team is working on migrating a new color tokenization library across the product, improving our contrast standards to 100%. Also, the team will be continuously constructing improvements to our security workflows in regard to error recognization, text legibility and localization, and keyboard navigation.
- Accessibility testing
- Unknown
- API
- Yes
- What users can and can't do using the API
-
The Lacework API documentation is available directly from your Lacework application. Logging in to the Lacework Console is not required. There are, however, links to the Lacework API documentation from the Lacework Console. From the Help drop-down, select API Documentation or API 2.0 Documentation.
You can run the Lacework APIs using your favorite REST API tools such as curl or Postman. Example curl commands are listed in the API documentation provided by the Help > API Documentation or API 2.0 Documentation menu options in the Lacework Console.
You can also run the Lacework API from the Lacework CLI. For more information, see https://docs.lacework.com/cli - API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Dark mode is available.
Scaling
- Independence of resources
- Lacework's platform is designed to auto-scale based on defined thresholds to ensure sufficient capacity at all times.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Each month, Lacework calculates the 95th percentile of hourly agent counts for each Lacework account. The amount billed for the month is the sum of all 95th percentile values across all Lacework accounts that belong to you. The number of agents purchased determines the subscribed quantity.
Lacework calculates the average number of cloud resources for selected resource types (as defined in Terminology). These averages are calculated for each Lacework account and cloud account. The amount billed for the month is the sum of all average cloud resources across all Lacework accounts that belong to you. For more information, see: https://docs.lacework.com/usage#terminology - Reporting types
- Real-time dashboards
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Lacework
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a Tigerscheme qualified provider or a CREST-approved service provider
- Protecting data at rest
-
- Scale, obfuscating techniques, or data storage sharding
- Other
- Other data at rest protection approach
-
Lacework leverages AES-256 for encryption at rest.
Through a secure-by-design approach, Lacework builds security into
its products and services throughout the development lifecycle and layers security throughout its architecture to protect its corporate assets, supply chain, software, and customer-facing services.
Lacework implements people, process, and technical controls designed to manage cybersecurity risks. These controls include physical, technical, and or administrative in their operation and their intent may be detective, corrective, deterrent, or recovery focused. These controls are reviewed no less than annually to ensure continued appropriateness and effectiveness. - Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- Lacework supports two export mechanisms—data share via Snowflake and data export via Amazon S3. Both tools are used to export Lacework-processed data to either report/visualize alone or combine with other data to gain insights and make meaningful business decisions. These tools offer long-term data retention and encompass all of Lacework’s data—including alerts, DNS lookups, IP connections, process attributions, etc.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- Snowflake Data Share
- S3 Data Export
- Data import formats
- Other
- Other data import formats
- Not applicable
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
-
All customer data is considered Confidential and is encrypted at rest and in transit over untrusted networks. Customer data is stored only in the Lacework production environment. All communication across the Internet between users and the Lacework Service is secured and
encrypted using TLS 1.2 (or stronger) protocol. - Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- All customer data is considered Confidential and is encrypted at rest and in transit over untrusted networks. Customer data is stored only in the Lacework production environment. All communication across the Internet between users and the Lacework Service is secured and encrypted using TLS 1.2 (or stronger) protocol.
Availability and resilience
- Guaranteed availability
- Lacework has set an SLA of 99.9% availability.
- Approach to resilience
- Available on request
- Outage reporting
- Lacework customers can subscribe to email notifications for availability incidents via the “Subscribe to Updates” button on https://status.lacework.net.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
-
All management and support access to Lacework's SaaS platform is backed by single-sign-on with MFA and subject to management approval which is reviewed and tested regularly.
For additional information please see the Lacework Security and Privacy Standard at https://www.lacework.com/legal/security-standard/. - Access restriction testing frequency
- At least once a year
- Management access authentication
- 2-factor authentication
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 1 month and 6 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 1 month and 6 months
- How long system logs are stored for
- Between 1 month and 6 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Schellman
- ISO/IEC 27001 accreditation date
- 15/02/2024
- What the ISO/IEC 27001 doesn’t cover
- The scope of the ISO/IEC 27001:2013 certification is limited to the information security management system (ISMS) supporting Lacework’s Polygraph Data Platform, in accordance with the statement of applicability, version 1.3, dated December 13, 2023, and aligned to meet the control implementation guidance and additional control sets of ISO/IEC 27017:2015 and ISO/IEC 27018:2019.
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- Yes
- Any other security certifications
-
- ISO9001:2015
- SOC2 type 2
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Lacework undergoes annual SOC 2 Type II audits and has achieved ISO 27001, ISO 27017, and 27018 certification.
- Information security policies and processes
- Lacework has a comprehensive set of information security policies and procedures that have been audited as part of Lacework's ISO 27001 certification. For additional information please see the Lacework Security and Privacy Standard at https://www.lacework.com/legal/security-standard/.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All changes to Information Systems by Lacework Personnel in production environments, including network and other infrastructure, are authorized, tracked, tested, and monitored.
For additional information please see the Lacework Security and Privacy Standard at https://www.lacework.com/legal/security-standard/. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
Lacework follows a risk-based methodology leveraging relevant industry standards, such as CVSS, to prioritize security issues based on their impact severity and likelihood of exploitation. Lacework aims to release patches or remediate issues in a reasonable period of time commensurate with the results of the risk assessment. Generally, higher-impact issues will be prioritized and fixed sooner than lower-impact issues. However, the amount of time required to fix a vulnerability is unique to each finding and depends on a set of factors, including the complexity of the issue, the number of components impacted, and any third-party dependencies.
For additional information: https://www.lacework.com/legal/security-standard/. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
-
Lacework monitors the Information Systems as well as the underlying infrastructure on a 24x7x365 basis and maintains an on-call rotation of information security and operations personnel who are notified immediately of any security event that requires additional investigation.
For additional information please see the Lacework Security and Privacy Standard at https://www.lacework.com/legal/security-standard/. - Incident management type
- Supplier-defined controls
- Incident management approach
-
Lacework maintains an Incident Response Policy and trains all personnel identified in the policy of their responsibilities on a regular basis. In the event of a suspected incident the incident response team is notified and immediately begins a reasonable investigation as to whether a breach has occurred. In the event of a reasonably suspected breach, Lacework will use commercially reasonable efforts to contain, mitigate, and resolve the breach as well as put in place additional controls to prevent further breaches of a similar type.
For additional information please see https://www.lacework.com/legal/security-standard/.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
As an organisation that works closely with the public sector, Somerford is keen to demonstrate our commitment to supporting the achievement of the Net Zero target of greenhouse gas emissions by 2050.
Management and staff at Somerford have been conscious of our impact upon the environment even before the Climate Change Act was introduced, and we’ve adopted environmentally friendly practices as the business has grown. Consequently, Somerford ‘s business already has a reasonably low carbon footprint, and will continue to strive for further reductions wherever possible because this is beneficial for our business, our stakeholders and the environment.
We will use our influence as a value added reseller of leading edge software products and supporting professional services to select supplier-partners whose own carbon reduction philosophy and plans are aligned with ours, and who can show commitment to the Net Zero target. In practical terms, this means we participate in a carbon-net-zero supply chain in the delivery of the solutions from our supplier-partners to our customers.
For further details, please see our Carbon Reduction Plan online at https://www.somerfordassociates.com/carbon-reduction-policy-and-plan/ As an organisation that works closely with the public sector.Covid-19 recovery
During the Covid-19 pandemic, our robust business continuity measures, prudent fiscal policy, and the benefits of a highly flexible team, meant we were well prepared for the difficulties ahead.
Staff wellbeing has been at the forefront of our Covid-19 recovery plans, taking care of their physical and mental health, including;
* home working to avoid unnecessary exposure to the virus
* providing safe office space where staff personal circumstances dictated
* regular contact, albeit remotely, to prevent isolation
* organised e-based social events to maintain interaction;
As a result we have been able to:
* give uninterrupted service to our customers
* move our staff to home working
* avoid compulsory redundancies and minimised furlough
* in 2020, gain an 11% increase in revenues
* continue to grow the workforce by over 10% in the same year
* take on new partners to enhance our solutions portfolio
* invest in staff education to meet future customer needs.
Changes in business practices due to Covid-19 have shown that flexible work patterns can be very effective, and we’re unlikely to fully return to our previous style of working.
Our solutions have also helped customers to cope with their changing work patterns too - supporting their Covid recovery by providing the infrastructure, tooling and monitoring to support their own remote, flexible and sustainable ways of working.Tackling economic inequality
Somerford is a healthily growing business, and actively strives to create employment opportunities that are inclusive of all socio-economic groups. For example:
* 47% of our staff joined us as junior.
* 17 of our team have joined us as apprentices or graduated from our in house technical academy
* We actively participate in the Armed Forces Covenant Scheme and help to redeploy and re-skill leavers from the Armed Forces. So far, 18 staff have joined us in this way;
Strong technical skills are key to the delivery of services to our customers, so we’ve invested heavily in staff training, as is demonstrated by 47% of our staff starting with us as juniors.Equal opportunity
Somerford is an equal opportunities employer and does not discriminate on the grounds of gender, sexual orientation, marital or civil partner status, pregnancy or maternity, gender reassignment, race, colour, nationality, ethnic or national origin, religion or belief or age.
We do not discriminate on the grounds of disability. We take particular care to respect the rights of those with disabilities, throughout all stages of recruitment and employment. We make reasonable adjustments to ensure those with disabilities are not disadvantaged in the workplace, eg. adjusting working hours or providing special equipment to help to do their job.Wellbeing
Somerford is committed to promoting and supporting the wellbeing of all of its staff. We aim to create a culture which focuses on prevention of issues in the workplace that can adversely affect staff health and wellbeing, and where issues are identified, they are managed promptly before they can have a detrimental impact.
This includes:
* providing staff with clarity and purpose regarding their job role;
* ensuring staff have the capability, training, support and encouragement to conduct their role confidently and effectively;
* providing a physical working environment that is suitable for the work to be carried out effectively;
* encouraging staff to maintain a sensible work-life balance;
* minimising the stressful impacts of work;
* ensuring bullying and harassment have no place in the working environment;
* managing sickness and absence effectively;
* considering requests for career breaks and sabbaticals;
* providing medical assistance to staff;
* encouraging employee fitness;
* promoting dignity at work.
Pricing
- Price
- £41.32 a unit a year
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
-
Lacework can provide proof of value (PoV). Lacework is installed & configured in your production environment at scale. Success criteria and proper testing methodology will be agreed before POV.
Lacework can offer Cloud Security Assessment's to assist organisations in accelerating cloud account audits and reduce risk.