security information management (SIM)
Home > Security Definitions - Security information management (SIM)
SearchSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

security information management (SIM)


Show me everything on Security Event Management


Word of the Day


DEFINITION - What is security information management (SIM)?

Security information management (SIM) is the practice of collecting, monitoring and analyzing security-related data from computer logs. A security information management system (SIMS) automates that practice. Security information management is sometimes called security event management (SEM) or security information and event management (SIEM).

Security information includes log data generated from numerous sources, including antivirus software, intrusion-detection systems (IDS), intrusion-prevention systems (IPS), file systems, firewalls, routers, servers and switches.

Security information management systems may:

  • Monitor events in real time.
  • Display a real-time view of activity.
  • Translate event data from various sources into a common format, typically XML.
  • Aggregate data.
  • Correlate data from multiple sources.
  • Cross-correlate to help administrators discern between real threats and false positives.
  • Provide automated incidence response.
  • Send alerts and generate reports.

Commercial SIM products include ArcSight ESM, nFX's SIM One, Network Intelligence's enVision, Prism Microsystems' EventTracker, Trigeo, Symantec's Security Information Manager, Cisco Security MARS and Snare. Open source SIM products include OSSIM, a product of the Open Source Security Information Management initiative, and Prelude, from PreludeIDS.

Although SIM products can automate many tasks around security information gathering and processing, they can't operate effectively without significant effort and investment on the part of the organization in question. According to Neil Roiter, Senior Technology Editor of Information Security magazine, "Security information and event management (SIEM) products are only as good as the policies and processes they support, and the analyst resources that a company can pour into them."

Learn More About IT:
> Adrian Lane explains mining enterprise SIM logs for relevant security event data.
> Network World Buyers Guide provides an overview of security information management and compares SIM products.
> Neil Roiter explains why security information management is not for small businesses -- or the faint of heart.

Learn more about Security Event Management
Quiz: Getting the most out of your SIM deployment: With this five-question quiz, test your knowledge of Adrian Lane's SIM deployment Security School lesson.
Quiz: Securing your network: Test your knowledge of network security.
Understanding PCI DSS compliance requirements for log management: Proper PCI DSS compliance requires effective event log management, but many enterprises fail to not only gather all the relevant data, but also analyze and remediate the results.
Review system event logs with Splunk: Splunk is a free tool that provides log review and management. From parsing files to triggering alerts and scripts, Splunk can greatly reduce the amount of time spent on logs.
Mining enterprise SIM logs for relevant security event data: Adrian Lane explains how to get the most valuable data from a security information management system.

LAST UPDATED: 21 Sep 2009

Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com





FILE EXTENSION AND FILE FORMAT LIST
File Extension and File Format List:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #


RELATED CONTENT
Network traffic collection, analysis helps prevent data breaches
Companies get serious collecting massive amounts of network packets to investigate alerts and speed digital forensics.
Best Security Information and Event Management Products
Readers vote on the best security information and event management and log management software, appliances and managed services.
Understanding PCI DSS compliance requirements for log management
Proper PCI DSS compliance requires effective event log management, but many enterprises fail to not only gather all the relevant data, but also...




Get More security information management (SIM) Answers
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts