|
Log Management, Security Event Management,
and Security Information Management - making sense
of it all
Network and security events are produced once,
and if not properly captured, lost forever. Compounding
this is the fact that if organizations can't capture
and manage their logged events, then they lose
the ability to conduct real-time threat correlation
and analysis, report incidents to management,
or reference them historically.
Log retention and analysis is a core expectation
of the laws and regulations around network security,
including GLBA, HIPAA, SOX and others. Collecting
event log data from security and network devices
creates a complete picture of network usage, verifies
security against policy, generates alerts for
possible security breaches, and analyzes and reports
on network performance.
Enter Log Management, Security Event Management
(SEM), and Security Information Management (SIM).
All of these systems/methods are a way to deal
with the aforementioned problems. The problem
is, how do you determine what is the best fit
for you?
In this presentation, Accuvant and Network Intelligence
will discuss:
- How to baseline, correlate and aggregate network
data
- Learn how to map reports to specific regulations
and IT security, audits and real-time monitoring
- What to look for when evaluating a log management
and/or SIEM system
|