Security - Channel Insider
Empowering the next generation Channel

Putting Security Event Data Management to Work

By Ericka Chickowski on 2011-08-24



Mature organizations that utilize security information and event management (SIEM) tools want their technology to be more than just a fulfillment device. They want it to provide actionable data. But in making that transformation, they're running into the same data warehousing and data management problems that business intelligence professionals face. "The intersection of SIEM, data warehousing, and business intelligence resonates throughout the IT organization and is driven by three powerful forces: vast amounts of data being generated by IT systems; sophisticated and difficult to discover new threats; and the added complexity from mobile device proliferation, IT consumerization and cloud computing requirements. This combination creates a perfect storm for even the most advanced IT organization," wrote experts from Forrester Consulting, which recently released a study commissioned by data warehouse software provider Sensage that examined the practices of 60 SIEM-wielding enterprises. Of the organizations that responded, 95 percent pointed to one or more areas where they’d like to see more advanced analytics capabilities from their SIEM tool, including greater flexibility to pursue non-standard analysis and a more sophisticated correlation across siloed processes.

  • of
The most commonly asked for advancement of features is the ability to analyze data in multiple ways and for non-standard data analysis, named by 62 percent of respondents.

When they initially started their deployments, only 47 percent of organizations used SIEM for real-time monitoring and 55 percent used it for risk management.

Now that they've had time to settle in with their SIEM solutions, 82 percent use it for real-time monitoring and 78 percent for risk management.

Even more striking, only 27 percent of organizations used SIEM for operational visibility and intelligence upon deployment, but now 62 percent use it to improve operations.

From a security standpoint, 83 percent of organizations that use SIEM reported using data warehousing tools to store event data.

80 percent said they use data integration tools to create consistency between all of the event data types.

Nearly three-quarters of enterprises using SIEM use business intelligence tools in conjunction with them to provide users with self-serve access to the event data.

  • More slideshows

 
CHANNEL RESOURCE CENTER
 
 
 

Intel Technology Provider Program

Intel Technology Provider Program (ITP) helps resellers better understand Intel products which power the technology they sell, and enables value-add services such as remote manageability or anti-theft tracking.
Learn More
 
WindowsForDevices.com
WindowsForDevices.com is the comprehensive news site covering Windows embedded technologies. Visitors get news, technical white papers, opinion columns and extensive directories covering the products and companies in the marketplace.
Click Here
 
Check out our top five picks for technologies that will change the game in enterprise computing.
Learn MoreClick Here