- Kindle back orders stretch 3 months at Amazon
- Cisco shutting down between holidays
- Smartphone smackdown: Storm vs. iPhone
- 12 myths about how the Internet works
- Google layoffs: 10,000 jobs being cut
1. Start with a baseline understanding of your security events. "You have to do a risk assessment before choosing a tool to know what you need. Look at every event in your environment, ask if it's normal and then what the threshold is within a certain time frame," says Matt Roedell, vice president of infrastructure and information security at TruMark Financial Credit Union in Trevose, Pa. In addition, be sure you understand your alert and mitigation strategies, he says. Skipping this step will render your security information and event management (SIEM ) product useless, he adds. (Compare SIEM products.)
This story is part of a special Security Trend Watch issue, in PDF format. Download now.
2. Don't bite off more than you can chew. The "start slowly" advice for IT deployments definitely applies to SIEM, says Denis Hein, senior information security engineer for Wells Fargo Bank in Chandler, Ariz. "First, bring the product in-house and test it. How it looks on paper can be quite different than how it runs in your environment," he says. Next, tackle perimeter security, he advises: "Stay conservative to make sure it holds up as you scale and add in more endpoints."
3. Establish a system for dealing with alerts. "If you don't already have processes in place for dealing with logs, then SIEM will not improve your security posture," says Kelly Kavanagh, principal research analyst at Gartner. Unless you have a plan in place before deployment, you're sure to waste your SIEM investment, he adds.
4. Make sure executives are onboard. "Properly define your mandate and have your executives endorse it," says Arlan McMillan, global head of information security operations at ABN AMRO, a Chicago financial services giant. "IT teams will have to cross internal organizational borders to secure logs that might be sensitive or confidential, so you need all your governance issues clearly laid out before you start deployment."
- Sandra Gittlen
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment