January 08, 2008

Security information management

Buyers' Guide: Follow InfoWorld's expert advice before shopping for a SIM solution to monitor network security and compliance

Where will the information be processed? In a network of any size, the SIM will be dealing with a large quantity of data. Precisely where and how the data is processed will be key to knowing whether a particular SIM can keep up with the data generated by your network. Almost all SIMs have two primary components for the creation and presentation of information: the SIM appliance itself and a dashboard application running on a remote workstation. If all the information is processed in either the appliance or the dashboard workstation, performance can become an issue when either network traffic or incidents become high in density. Ask about where data is processed and whether the processing is split between two (or more) systems. Delayed security information can result in falling victim to an attack that you might have survived.

How will the information be correlated? All SIMs gather information from the sources within the network. Some will gather information from external sources as well, ranging from public threat identification services to proprietary correlation networks. Beyond eliminating the need for your security engineer to open 93 windows on his or her workstation just to keep up with log files, a SIM, to a great extent, adds value with its capability of finding patterns in network traffic. This activity requires two primary traits: the capability of gathering data from a various places and the intelligence to turn all that data into meaningful information. Both are critical. Just as the SIM must draw information from all of the important components of your network, the correlation data must come from sources you trust.

How are reports generated? It's one thing to be notified that unauthorized activities are happening on the network. It's another thing entirely to convince less security-savvy network management to do anything about it. You want your SIM to be capable of generating reports to support your call for action -- and to generate them quickly. If the product comes with prepackaged reports that you can modify to provide the information specific to your organization and incident, then you're way ahead of the game.

Prepackaged reports are critically important time-savers when it comes to regulatory-compliance audits. If you know the format your auditing agency requires, then by all means ask whether those reports are included with your candidate SIM. Regulatory compliance audit reports could, by themselves, justify the purchase of a SIM system.

How can you look at highlighted incidents? Reports are important in many situations, but for day-to-day security analysis, you'll spend much more time interacting with a security dashboard. A clean, well-organized dashboard and the ability to drill into reported incidents by time, severity, and type will mean the difference between productivity and frustration. How easily can you highlight a particular time period and analyze traffic by the criteria that you specify? How easy does the correlation engine within the client make it to look for patterns within a specified time? Is it effortless or difficult to look at traffic or interactions between specific addresses or types of clients?

With just about any product, you'll want a dashboard that has an initial set of analysis screens that get you started in a meaningful way. You'll also want something with easily customized screens and automated analysis runs to meet your needs.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.