|
Security Quarterly 1: Security information management
Enterprises are looking into a fire hose of data as they attempt to monitor and react to security threats. Every application and piece of network gear contributes to the flood of security event data. An entire industry has sprung up to support security analysts lost in this overwhelming data flow. That industry is in flux.
This report takes an in-depth look at the source of the problem, which begins with the proliferation of log data from the likes of firewalls, virtual private networks (VPNs), intrusion-prevention systems (IPS), intrusion-detection systems (IDS) and anti-malware. It then looks at the technologies and products offered to relieve the strain.
The report concludes that what began as an approach to address the fact that security analysts must view logs from a wide range of devices to get context about what's happening on the network has evolved into a technology that can bridge communication gaps between network and security operations.
Buy this report
|