Skip to content

Armis Federal LLC: Armis FedRAMP Edition (AFE)

FedRAMP AuthorizedRev5Moderate · since January 9, 2023

What its stage means

An agency or the FedRAMP program authorized it. Agencies can reuse that authorization.

See it on the FedRAMP Marketplace

Share this page:LinkedInXEmail

The provider's description

Armis FedRAMP Edition (AFE) is an agentless, enterprise-class security platform built off of the Armis Centrix™ engine to help organizations discover and secure managed, unmanaged, and IoT devices, including medical devices and industrial control systems (ICS). Armis discovers every managed, unmanaged, and IoT device in any environment, analyzes device behavior to identify risks, vulnerabilities or attacks, and protects critical business information and systems. Armis easily integrates with existing security products. AFE passively monitors wired and wireless traffic in the environment to identify every device and to understand its behavior without disruption. AFE analyzes this data in the AFE Risk Engine which uses device profiles and characteristics from the AFE Device Knowledgebase to identify each device, assess its risks & vulnerabilities, detect threats, and recommend remediation actions.

Visibility:

AFE closes the Continuous Diagnostic and Mitigation Dashboard visibility gap with unmanaged and IoT devices. AFE discovers and classifies every managed, unmanaged, and IoT device in the environment including servers, laptops, smartphones, VoIP phones, smart TVs, IP cameras, printers, 5G, HVAC controls, medical devices, industrial controls, and more. AFE can even identify off-network devices using Wi-Fi, Bluetooth, and other protocols in any environment. The comprehensive device inventory that AFE generates includes critical information such as device manufacturer, model, serial number, location, username, operating system, installed applications, and connections made over time. In addition to discovering and classifying a device, AFE calculates its risk score based on factors such as vulnerabilities, known attack patterns, as well as the behaviors observed of each device in the environment. This risk score helps security teams understand their attack surface and meet compliance with regulatory frameworks that require identification and prioritization of vulnerabilities.

Insights:

The AFE Risk Engine continuously monitors the behavior of every device in the environment for behavioral anomalies. Working with the AFE Device Knowledgebase, AFE compares the real-time behavior of each device with: ● Historical device behavior ● Behavior of similar devices in the Customer's environment ● Behavior of similar devices in other environments ● Common attack techniques ● Information from threat intelligence feeds

Actions:

With these types of critical device and behavioral insights, AFE is able to identify threats and attacks. When AFE detects a threat, it can alert security teams and trigger automated action to stop an attack. Through integrations with network infrastructure, as well as the Customer's existing security enforcement points like Cisco and Palo Alto Networks firewalls, and network access control (NAC) products such as Cisco ISE and Aruba ClearPass, AFE can restrict access or quarantine suspicious or malicious devices.

Easy Integration:

AFE requires no agents or additional hardware to deploy. AFE integrates with existing firewalls or NAC, security management systems such as SIEM, ticketing systems, and asset databases. These integrations allow AFE to leverage existing investments to achieve greater value and more automated response.

VIPR Pro:

Armis Centrix™ for VIPR Pro delivers a FedRAMP-authorized cyber exposure management solution that helps federal agencies bridge the gap between fragmented security data and actionable risk reduction. Built to solve extreme alert fatigue, VIPR Pro acts as a centralized aggregator that ingests, correlates, and de-duplicates static security findings; including traditional vulnerabilities, cloud misconfigurations, and application security flaws - from across an agency’s existing security stack.

Rather than hunting for active threats, the platform applies machine learning to consolidate disparate scan data, reducing finding volumes by up to 50-

What FedXchange has recorded

  1. Armis FedRAMP Edition (AFE) from Armis Federal LLC gained an agency authorization, 11 in all.

  2. Armis FedRAMP Edition (AFE) from Armis Federal LLC gained an agency authorization, 10 in all.

  3. Armis FedRAMP Edition (AFE) from Armis Federal LLC gained an agency authorization, 9 in all.

  4. Armis FedRAMP Edition (AFE) from Armis Federal LLC gained an agency authorization, 8 in all.

  5. Armis FedRAMP Edition (AFE) from Armis Federal LLC gained an agency authorization, 7 in all.