| CPC H04L 63/1416 (2013.01) [H04L 63/20 (2013.01)] | 20 Claims |

|
1. A system for collection of telemetry by an Information Handling System (IHS), the system comprising:
a policy decision point of a zero-trust computing environment that controls access to a plurality of protected resources, wherein the policy decision point is configured to:
receive notification of an indication of attack related to the IHS;
identify a telemetry definition specifying telemetry being collected by the IHS;
update the telemetry definition to specify a security delay for telemetry related to the indication of attack;
transmit the updated telemetry definition to the IHS; and
the IHS comprising a plurality of sensors, one or more processors, and a memory coupled to the processors, the memory storing program instructions that, upon execution by the processors, cause the IHS to:
identify telemetry that is ready for transmission by the IHS;
determine whether the telemetry is subject to a security delay specified in the updated telemetry definition;
when the telemetry is subject to a security delay, queue the telemetry that is ready for transmission; and
transmit the queued telemetry to one or more destinations specified in the updated telemetry definition upon expiration of the security delay.
|