CrowdStrike Falcon Next-Gen SIEM Added to CISA-Funded Federal Service

Summary
Eligible federal agencies using CrowdStrike EDR can access Falcon Next-Gen SIEM through CISA’s DEFEND F shared service, extending security operations without using agency program funding.
Key points
- Falcon Next-Gen SIEM has joined CISA’s SIEM-as-a-service technology stack through the CDM DEFEND F shared service.
- Access is limited to eligible federal civilian agencies that use CrowdStrike EDR and participate in CISA’s Persistent Access Capability program.
- The service is delivered through CGI Federal and the FedRAMP High-authorized CrowdStrike Falcon platform in GovCloud.
- It combines CrowdStrike and third-party security telemetry, including endpoint, identity, cloud, network, and edge data, with threat intelligence and behavioral detections.
- Participating agencies can obtain the SIEM through the shared-service mechanism without using their own program funding.
Article Details
- Event Type
- Falcon Next-Gen SIEM added to CISA’s SIEMaaS technology stack through the CDM DEFEND F shared service.
- Impact
- Eligible federal civilian agencies already using CrowdStrike EDR modules can obtain Falcon Next-Gen SIEM without using their own program funding. CrowdStrike says the offering can unify security data and accelerate investigations; the article does not report outcomes for participating agencies.
Vendors
CGI FederalFalcon Next-Gen SIEM is available through CGI Federal’s CDM DEFEND F SIEMaaS shared service to eligible federal civilian agencies that use CrowdStrike EDR modules and participate in CISA’s CDM Persistent AccessCrowdStrikeCrowdStrike Expands Federal SOC Modernization Through CISA-Funded SIEMaaS
Products
CrowdStrike Falcon® platformFalcon Next-Gen SIEM, delivered through the FedRAMP High-authorized CrowdStrike Falcon® platform in GovCloud, creates a unified security data layer across CrowdStrike and third-party telemetry.Falcon Next-Gen SIEMFalcon Platform IOAs Arrive in Falcon Next-Gen SIEM to Identify New Threats