26.04.2015 Views

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Determine how you intend to staff SIEM monitoring and<br />

alerting functions<br />

"Once there is seeing, there must be acting. Otherwise, what is the use of<br />

seeing?” (Thich Nhat Hanh, Vietnamese Zen Buddhist Monk)<br />

• Real-time event monitoring can be a huge cost driver for<br />

SIEM:<br />

◦ For organizations lacking a dedicated <strong>Security</strong><br />

Operations Center (SOC), adding a dedicated 24/7<br />

monitoring capability could equate to an increase of 5<br />

Full Time Equivalents.<br />

◦ Consider adding a “best effort” event monitoring<br />

responsibility to existing security staff – a 10-20% rise in<br />

staffing levels could enable much better incident<br />

response outcomes.<br />

• Alternatively, consider a Managed <strong>Security</strong> Service<br />

Provider (MSSP) approach to staffing your SIEM solution:<br />

◦ MSSPs can provide 24/7/365 monitoring and alerting at<br />

a fraction of the cost of providing the service yourself.<br />

◦ Many MSSPs also provide incident response services<br />

that can supplement on-staff personnel during off hours.<br />

◦ The trade-off: your SIEM data is either stored off-site<br />

(with associated bandwidth impacts), or accessible to<br />

3 rd parties, or both. Be sure to address these security<br />

and confidentiality issues in your MSSP contract.<br />

Info-Tech Insight<br />

SIEM monitoring through an MSSP can<br />

provide cost-effective alternatives for<br />

real-time event monitoring:<br />

• MicroAge, an IT services firm, opted<br />

for an MSSP to provide on-premise<br />

SIEM equipment and remote<br />

monitoring services.<br />

• For a monthly fee, MicroAge avoided<br />

the capital cost of a SIEM solution<br />

supporting 120 log sources.<br />

• In the same monthly fee, MicroAge<br />

receives 24/7 real-time event<br />

monitoring, with serious events<br />

escalated to internal IT staff, at a<br />

small fraction of the cost of staffing<br />

such a capability internally.<br />

You get an alarm system for your<br />

network, but you don't get the cops to<br />

go with it.<br />

- Perry Kuhnen, IT Manager, MicroAge<br />

(about SIEM without real-time monitoring)<br />

Info-Tech Research Group<br />

57

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!