Security Information Management

There are many existing requirements and new consistently being added for enterprise security staffs. From information-assurance initiatives to security operations to regulatory compliance, managing and verifying security controls has become incredibly complex. One critical component of the job is gathering, storing and processing data that provides situational awareness--visibility into security postures. A challenge is to collect this information from myriad sources, including network devices, systems, applications and vulnerability scanners, and logging efforts.

Organizations that take the time to understand the policy, process and technology behind the technology have a greater chance at keeping up with the large amounts of log-data. Creating a workable plan and the correct selection of technology and process strategy is critical. The same is products, technology, and solutions are not the same for everyone, but all companies and organizations should have a policy in place to manage log data; those without plans will not be able to effectively help prevent the threat information from their logs being unused and overlooked -- a serious weakness in business.