|
|
|
There will always be more people out there working against your security measures than you have staff to fight against them. Security Information & Event Management (SIEM) is your weapon to even the battlefield.
This is what your SIEM weapon will do for you:
- Log Consolidation – centralized logging to a server
- Threat Correlation – the artificial intelligence used to sort through multiple logs and log entries to identify attackers
- Incident Management – workflow – What happens once a threat is identified?
- Notification – email, pagers, informs to enterprise managers (MOM, HP Openview…)
- Trouble Ticket Creation
- Automated responses – execution of scripts (instrumentation)
- Response and Remediation logging
- Reporting
- Operational Efficiency/Effectiveness
- Compliance / SOX, HIPPA, FISMA….
- Ad Hoc / Forensic Investigations
|
|
 |
|