SIM and Log Management
Must read
- How to collect Windows Event logs to detect a targeted attackTip - Targeted attacks are growing, and eventually your enterprise will be a target. Expert Richard Bejtlich covers how to collect Windows Event logs to detect an intrusion.
- Get actionable results from a security information management systemMagazine - In order to get the best results, you need to limit your goals for SIM.
- Exploring SIM architecture options for virtual data center securityTip - To be successful in securing the virtual data center, security information management (SIM), a key element for effective data center security, must virtualize and become virtualization-aware. In this tip, we’ll discuss some of the options enterprises must consider regarding SIM architecture and virtual data center security.
Security Event Management from searchSecurity.com
-
SIEM vs. DAM technology: Enterprise DAM implementation best practices
Answer -Mike Cobb analyzes the differences between a SIEM and DAM implementation and how to successfully configure an enterprise DAM.
-
TIBCO to acquire SIEM vendor LogLogic
News -TIBCO, an integration software company with little security experience, will purchase one of the few remaining viable standalone SIEM vendors. Terms were not disclosed.
-
Security information management systems aspire to real-time security
News -Today’s security information management systems (SIM) are excellent forensics tools, but they haven’t yet achieved status as effective real-time security tools.
Monitoring Network Traffic and Network Forensics from searchSecurity.com
-
Hardening the network against targeted APT attacks
Tip -Mike Chapple offers best practices to defend your network against the latest threat to the security landscape, targeted APT attacks.
-
Can a malware 'pressure chamber' provide effective malware containment?
Answer -Infosec threats expert Nick Lewis discusses the viability of an antimalware "pressure chamber: to help bolster enterprise malware containment.
-
Print-management software security starts with a private IP address
Answer -Print-management software shouldn’t provide a great risk to a company provided it uses a private IP address, says expert Mike Chapple.
Security Management Strategies for the CIO