Home > Information Security Magazine > Hot Pick & Product Reviews > TriGeo Network Security's TriGeo Security Information Manager 3.0
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

TriGeo Network Security's TriGeo Security Information Manager 3.0
Issue: Jun 2005
printer-friendly
TriGeo Network Security's TriGeo Security Information Manager 3.0
TriGeo Network Security
Price: Starts at $19,820

[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE] [IMAGE] TriGeo Network Security's TriGeo Security Information Manager 3.0 [IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE]
Turning data from multiple network and security devices into actionable information...


BROWSE BY TAG
Hot Pick & Product Reviews,   Network Intrusion Detection and Analysis,   Security Event Management,   Enterprise Network Security,   VIEW ALL TAGS


isn't just a headache for Fortune 1000 companies--SMBs with limited staff need to know quickly when their networks are threatened.

TriGeo Network Security's TriGeo Security Information Manager (TriGeo SIM) 3.0 fills this niche as a highly flexible, easy-to-manage appliance that's designed to support 50 to 5,000 active devices.

It also adds automated remediation, a plus for any organization. TriGeo SIM can issue policy-based commands to block IP addresses and ports, and shut down or reboot users through Cisco Systems, Check Point Software Technologies, Juniper Networks, WatchGuard Technologies, SonicWALL, TopLayer Networks and Fortinet devices.

Like other SIMs, the appliance gathers data--typically logs--from devices and applications via agents or remote logging from firewalls, routers and switches. Data is normalized and processed by the policy engine, which initiates remediation action and/or an alert via e-mail, SMS, pagers and handheld devices.

The sweet spot for TriGeo, though, is its interface and management. TriGeo has hundreds of prebuilt correlation filters and rules that are as easy to use as LEGOs.

You can create filters based on alert types, and then operate the filters based on any of the data contained within the alert. For example, you can create a "VPN Alerts" tab that can be used to show only the alerts from a Cisco VPN Concentrator. Other custom filters might show modifications to user accounts or changes to do-main properties.

The appliance ships with more than 500 predefined rules. For example, change management rules can identify when users, groups, domains or policies are manipulated. Rules can apply to a specific group of devices, be time-dependent and have easily modifiable thresholds. One drawback is the lack of directory support; users and groups have to be manually created.

[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE] [IMAGE] Exec Summary [IMAGE]
[IMAGE] [IMAGE] [IMAGE] [IMAGE]
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] Prebuilt rules, easily modified
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] Automated remediation
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] Good "live" dashboard
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] Device support just OK
[IMAGE]
[IMAGE] [IMAGE] [IMAGE] No directory support

[IMAGE]

Device support isn't as broad as some enterprise-level SIMs: about 100, with a hefty Cisco representation. We used the appliance to monitor events from Juniper's NetScreen firewalls, Snort IDS sensors, Cisco routers and switches, Norton Anti-Virus CE software, and Win- dows and Linux workstations.

Event storage capacity runs from 73GB, to 3x73GB RAID5 arrays, depending on purchase level. The Data Warehouse function can support additional storage to a second database (MS SQL server).

The live console dashboard is very good, giving security managers easy access to alerts and agent status, with the ability to drill down for detail. The Crystal Reports are acceptable; out-of-the box reports are static--unlike the live dashboard, you can't review these reports' graphical data in real time or drill down for more detail to investigate interesting patterns. This can be remedied with a third-party tool.

With its ease of use and automated remediation features, TriGeo SIM is a sensible option for organizations that don't quite need the muscle--or the cost--of a large enterprise product.

-SCOTT SIDEL





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts