Home > Security News > A new awareness for SIMs
Security News:
EMAIL THIS

A new awareness for SIMs

By Marcia Savage, Features Editor, Information Security magazine
05 Feb 2007 | SearchSecurity.com and Information Security magazine

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Organizations overwhelmed by a deluge of security data generated by their networks--and feeling the pressure of regulatory requirements--have turned to security information management (SIM) for relief.

SIM, also referred to as security event management (SEM) or a combination of the two (SIEM), automates the process of monitoring logs from firewalls, IDSes and other devices. SIM systems aggregate, correlate, analyze and store data to give organizations overall visibility into their network security and improve their incident response.

RSA Conference 2007

Can't make it to the show? SearchSecurity.com staff members are on the RSA floor, on hand to deliver the latest RSA Conference 2007 news and updates.
At the same time, SIMs can help satisfy auditors. Regulatory pressures--from Sarbanes-Oxley and HIPAA to individual industry requirements--make log management and visibility into user access of systems and applications critical.

In fact, compliance is making "identity awareness" an important feature for SIM technology, said Trent Henry, an analyst at the Burton Group.

"Past SIEM solutions were quite focused on perimeter infrastructure such as firewalls and IDSes, but with identity management a key component of internal controls, SIEM products are now looking more carefully at identity transactions," Henry said. "This can help organizations keep an eye on critical compliance-related controls, including SOX's requirement for appropriate segregation of duties."

A SIM appliance from Network Intelligence, which was acquired by EMC last September, helps the Independent Electricity System Operator (IESO) in Ontario, Canada, comply with industry security auditing requirements, said Dave Lewis, who heads security at the IESO. The technology demonstrates that IESO staffers are in fact reviewing the security logs.

"This gives us an audit trail," Lewis said. "We can see that they did review their logs and they're taking action on X, Y and Z."

For the Idaho State Tax Commission, SIM helps it to comply with Internal Revenue Service requirements and get a better handle on security events. The commission deployed a SIM appliance from High Tower Software that collects and correlates data from its vulnerability assessment, IDS and other systems, and boils down that information to "actionable items," said Glenn Haar, IT resource manager at the commission.

"Our goal was to get people to the point where they're not mechanics trying to keep the thing running but move them to where they're focusing on dealing with the security issues that are actually coming up," he said.

SIEM products are now looking more carefully at identity transactions. This can help organizations keep an eye on critical compliance-related controls.

Trent Henry
Analyst, Burton Group
Likewise, a SIM system has streamlined network security monitoring at PPD, a global contract research firm serving pharmaceutical and other organizations. Before installing the Q1 Labs product, tracking virus outbreaks required reviewing individual firewall and other security logs. Now, the company has a central repository that makes it easier to track and analyze an outbreak, said Dave Daniels, PPD network security engineer.

At Hackley Hospital, a SIM system from TriGeo Network Security allowed network technicians to quickly track down the source of a virus that was preventing users from accessing the Internet.

"It puts a lot of things into one interface," said Andy Busard, information security analyst at the Michigan health-care provider. "It allows us to do things we weren't able to do before."

HIPAA compliance was the initial reason the hospital bought a SIM, Busard said. TriGeo is helping it show auditors that activities such as users logging in remotely are being tracked.

While SIM technology can help on a lot of fronts, it's not without its drawbacks. SIMs can be complex to manage.

"At the end of the day, all they do is report and store data and generate reports and analytics against that data," said Amrit Williams, a former Gartner analyst, now CTO at BigFix. "If you don't have a mechanism for responding to that data, then the cost associated with deploying these technologies can be high and offer limited value." Burton Group's Henry said the problem with a SIM system "becomes the amount of customization required to get the most out of the tool."

Jim Granger, technical director at the Navy Cyber Defense Operations Command, said SIM--like other technologies--requires an initial up-front investment in time and resources but that the payoff is worth it.

"SIMs force you to understand what your business processes are and what your networks look like, but that in itself is a good thing," he said.

<< Return to our special coverage of RSA Conference 2007



Tags: Security Event ManagementSarbanes-Oxley ActHIPAAVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Event Management
Mature SIMs do more than log aggregation and correlation
SIMs tools and tactics for business intelligence
SIEM: Not for small business, nor the faint of heart
Should IDS and SIM/SEM/SIEM be used for network intrusion monitoring?
Tying log management and identity management shortens incident response
How to estimate log generation rates
SANS Log Management Survey is "Looking for the ROI"
Review system event logs with Splunk
Virtual network tool gives firm view into virtualized environment
Mining enterprise SIM logs for relevant security event data

Sarbanes-Oxley Act
Ex-SEC chief Pitt decries state of Sarbanes-Oxley, risk management
Information security book excerpts and reviews
Internal audits for Sarbanes Oxley and internal IT support
Internal auditors and CISOs mitigate similar risks
Implement security and compliance in a risk management context
Does password sharing in international branches violate SOX?
Consensus Controls project aims to set benchmarks for compliance
Security visualization helps make log files work
The Little Black Book of Computer Security, 2nd Edition
RSA attendees see data classification, rights management projects stumble
Sarbanes-Oxley Act Research

HIPAA
HIPAA compliance: New regulations change the game
HIPAA compliance manual: Training, audit and requirement checklist
Key elements of a HIPAA compliance checklist
Quiz: How to meet HIPAA compliance requirements
How to avoid HIPAA Social Security number compliance violations
HIPAA changes force healthcare to improve data flow
CVS pays $2.25 million HIPAA settlement
Is a lack of employee privacy a HIPAA violation?
Hacked dental school server compromises 300,000
What's the best strategy to catch up on HIPAA compliance quickly?
HIPAA Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts