Event Management
With some subtle differences, there are four major functions of SIEM
(Security Information and Event Management) solutions:
- Log Consolidation - centralized logging to a server
- Threat Correlation - the artificial intelligence used to sort
through multiple logs and log entries to identify attackers
- Incident Management - workflow - What happens once a threat is
identified? (link from identification to containment and eradication).
- Notification - email, pagers, informs to enterprise managers
(MOM, HP Openview™)
- Trouble Ticket Creation
- Automated responses - execution of scripts (instrumentation)
- Response and Remediation logging
- Reporting
- Operational Efficiency/Effectiveness
- Compliance / SOX, HIPAA, FISMA...
- Ad Hoc / Forensic Investigations
