26.04.2015 Views

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Advanced Features are the capabilities that allow for granular<br />

market differentiation<br />

Scoring Methodology<br />

Info-Tech scored each vendor’s features<br />

offering as a summation of their individual<br />

scores across the listed advanced features.<br />

<strong>Vendor</strong>s were given 1 point for each feature<br />

the product inherently provided. Some<br />

categories were scored on a more granular<br />

scale with vendors receiving half points.<br />

Feature<br />

Log Data<br />

Enrichment<br />

Advanced<br />

Correlation<br />

Advanced Alerting<br />

Advanced Features<br />

What we looked for:<br />

Advanced CAN from Net Flow, Identity, Database,<br />

Application, Config & File Integrity data sources.<br />

Advanced canned policies, user-defined policies, &<br />

adaptive/heuristic policies.<br />

Programmable/customizable alerting responses &<br />

injection into native or third-party workflow tools.<br />

Advanced Reporting<br />

Forensic Analysis<br />

Support<br />

Data <strong>Management</strong> -<br />

<strong>Security</strong><br />

Data <strong>Management</strong> -<br />

Retention<br />

Unified Compliance<br />

Framework<br />

MITRE Common<br />

<strong>Event</strong> Expression<br />

Flexible dashboards, custom reporting capabilities, &<br />

ability to export to external reporting infrastructure.<br />

Ability to generate custom data queries with flexible<br />

drill-down capabilities.<br />

Granular access controls to system & log data,<br />

encryption of SIEM data (in storage & transmission).<br />

Notable storage capacity, data compression, &<br />

inherent hierarchical storage management.<br />

Solution leverages the UCF to enable advanced<br />

compliance reporting.<br />

Solution supports Common <strong>Event</strong> Expression log<br />

formatting.<br />

For an explanation of how Advanced Features are determined, please see <strong>Vendor</strong> <strong>Landscape</strong> Methodology: <strong>Information</strong> Presentation in the Appendix.<br />

Info-Tech Research Group<br />

21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!