OCM
The Unifying Control Engine
OCM links Defender and OMA — translating security events into operational responses and operational anomalies into security reinforcement, automatically.
Security Layer
Defender
Control Engine
OCM
Operations Layer
OMA
Result
Auto Response
SCENARIO 01
Operational Fault Response
OMA detects anomaly
→ OCM analysis script
→ OMA auto-heal executes
→ OCM analysis script
→ OMA auto-heal executes
SCENARIO 02
Security Threat Escalation
Defender detects threat
→ OCM event classification
→ Defender policy hardening
→ OCM event classification
→ Defender policy hardening
SCENARIO 03
Security Log Event Auto-Response
Security log event detected
→ OCM workflow engine
→ Unified auto-response
→ OCM workflow engine
→ Unified auto-response
4-Tier Event Severity
Level 1
Warning
Level 2
Minor
Level 3
Major
Level 4
Critical