Vendor Landscape: Security Information & Event Management
Vendor Landscape: Security Information & Event Management
Vendor Landscape: Security Information & Event Management
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Advanced Features are the capabilities that allow for granular<br />
market differentiation<br />
Scoring Methodology<br />
Info-Tech scored each vendor’s features<br />
offering as a summation of their individual<br />
scores across the listed advanced features.<br />
<strong>Vendor</strong>s were given 1 point for each feature<br />
the product inherently provided. Some<br />
categories were scored on a more granular<br />
scale with vendors receiving half points.<br />
Feature<br />
Log Data<br />
Enrichment<br />
Advanced<br />
Correlation<br />
Advanced Alerting<br />
Advanced Features<br />
What we looked for:<br />
Advanced CAN from Net Flow, Identity, Database,<br />
Application, Config & File Integrity data sources.<br />
Advanced canned policies, user-defined policies, &<br />
adaptive/heuristic policies.<br />
Programmable/customizable alerting responses &<br />
injection into native or third-party workflow tools.<br />
Advanced Reporting<br />
Forensic Analysis<br />
Support<br />
Data <strong>Management</strong> -<br />
<strong>Security</strong><br />
Data <strong>Management</strong> -<br />
Retention<br />
Unified Compliance<br />
Framework<br />
MITRE Common<br />
<strong>Event</strong> Expression<br />
Flexible dashboards, custom reporting capabilities, &<br />
ability to export to external reporting infrastructure.<br />
Ability to generate custom data queries with flexible<br />
drill-down capabilities.<br />
Granular access controls to system & log data,<br />
encryption of SIEM data (in storage & transmission).<br />
Notable storage capacity, data compression, &<br />
inherent hierarchical storage management.<br />
Solution leverages the UCF to enable advanced<br />
compliance reporting.<br />
Solution supports Common <strong>Event</strong> Expression log<br />
formatting.<br />
For an explanation of how Advanced Features are determined, please see <strong>Vendor</strong> <strong>Landscape</strong> Methodology: <strong>Information</strong> Presentation in the Appendix.<br />
Info-Tech Research Group<br />
21