26.04.2015 Views

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

Vendor Landscape: Security Information & Event Management

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Start modestly, but keep the final objective in mind<br />

Don’t try to execute the whole SIEM vision at once. Learn from early stages,<br />

and build capabilities & benefits incrementally.<br />

• Embarking on a SIEM initiative requires a serious investment of time and money. Implementation can be phased in two<br />

distinct, but complementary, ways.<br />

◦ Phased by SIEM function:<br />

– Start with a compliance management focus, but explore the benefits of enhanced event visibility or<br />

– Start with an event management focus, but take advantage of compliance reporting for internal purposes.<br />

– Once both are implemented, look at continuous risk management opportunities – demonstrated benefits from past<br />

experiences might even outweigh the cost of adding 24/7 monitoring.<br />

◦ Phased by source system:<br />

– Start with the most critical systems (key applications, core infrastructure, regulated environments).<br />

– Expand to other log data sources as the benefits of SIEM are demonstrated for those key assets.<br />

• Mix and match these approaches to minimize initial costs, maximize the benefits delivered, and build additional support for<br />

broader SIEM deployments:<br />

◦ Later stages may not deliver the same magnitude of benefits, but they involve lower equipment and configuration costs,<br />

as they leverage initial investments made in earlier stages.<br />

Info-Tech Research Group<br />

59

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!