26.04.2015 Views

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Understand the ongoing staffing impacts, both positive and<br />

negative<br />

Examine compliance and incident management savings against increased<br />

monitoring costs.<br />

• For incident response staff and supporting system administrators, SIEM is a<br />

double-edged sword:<br />

◦ Increased incident response efficiencies are countered by increased<br />

event visibility, until and unless SIEM-driven improvements are made to<br />

key security and system controls.<br />

◦ In the short term, this typically means a greater burden on security staff.<br />

• Organizations facing regular and/or diverse regulatory requirements can<br />

reduce their associated reporting burdens substantially:<br />

◦ In many cases, required reports can be generated automatically and<br />

consistently across multiple systems, without burdening the system<br />

admins.<br />

◦ Many SIEM solutions offer reports on internal SIEM activity. Such reports<br />

can be used to demonstrate compliance with various regulatory log<br />

review requirements.<br />

– If this capability is needed, make sure to configure your SIEM system<br />

to send links to the reports that will be viewed by system<br />

administrators, as opposed to sending the entire report.<br />

– This forces sysadmins to log into the SIEM solution directly to access<br />

reports, which in turn generates the audit record necessary for<br />

demonstrating that the logs have been reviewed.<br />

Info-Tech Research Group<br />

56

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!