12.07.2015 Views

NitroView Enterprise Security Manager

NitroView Enterprise Security Manager

NitroView Enterprise Security Manager

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Powerful <strong>Security</strong> Information and Event ManagementUnbeatable Performance<strong>NitroView</strong>'s patented data management engineprocesses and analyzes security information andprovides it back to you as actionable securityintelligence. Unlike most SIEM reports, however, theresults are produced in a fraction of the time. Evenduring periods of peak event collection, on systemsstoring billions of records, <strong>NitroView</strong> can producesecurity and compliance information in just a fewminutes, rather than hours or even days.Massive Data CollectionWhether using a single, entry-level appliance or a fullydistributed implementation of our flagship ESM X5,you'll appreciate the industry's highest event and flowcollection rates, from a wide range of data sources. Asingle <strong>NitroView</strong> Receiver can collect over 20,000 eventsper second. The ESM itself can support multipledistributed receivers, and is able to handle hundreds ofthousands of events per second without compression oraggregation. With aggregation, a single appliance cansupport tens of millions of events per second—enoughfor almost any network.Long-term Data Retention<strong>NitroView</strong> is able to store billions of events and flows,keeping all information available for immediate analysis,investigation and reporting. That's important wheninvestigating low-and-slow attacks, searching forindications of advanced persistent threats, orattempting to remediate a failed compliance audit—allof which require looking at years of data, and having fullaccess to the complete details of specific events.<strong>NitroView</strong> ESM’s dynamic baselinesprovide at-a-glance indication ofnetwork and event anomalybehaviorDynamic, Real-Time BaselinesWhether its network traffic, user activity, or trends inapplication use, any variation from normal activity couldindicate that a threat is imminent. Normal event activitycan also be a clue to a larger threat or incident. Nitro-View calculates real-time baseline activity for allcollected information and alerts you of potential threatsbefore they occur, while at the same time analyzing thatdata for patterns that could indicate a larger threat.Content Awareness<strong>NitroView</strong>'s scalability and performance enables moreevents to be collected, from more sources. All informationis heavily indexed, normalized, and correlatedtogether to detect a wider range of risks and threats.When contextual information is available from vulnerabilityscanners, identity & authentication managementsystems, or privacy solutions, each event is enrichedwith that context for•a better understanding of howevents correlate to real business processes and policies.Policy-aware Compliance ManagementCompliance management requires more than simpleevent logging. It requires an understanding of networkdevices and their vulnerabilities, users and their roles,allowed applications and their use, and the business andoperational policies that tie it all together. <strong>NitroView</strong>makes compliance management easy, and provideshundreds of pre-built dashboards and reports forPCI-DSS, HIPAA, NERC-CIP, FISMA, GLBA, SOX, and others.Integrated Tools for Improved <strong>Security</strong> Workflow<strong>NitroView</strong> ESM gets to the heart of security operationswith integrated tools for configuration and changemanagement, case management, and centralized policymanagement needed to improve workflow and facilitatedaily information security operations.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!