Security Information and Event Management (SIEM)
|
|
|
- Reginald Gervase Dickerson
- 10 years ago
- Views:
Transcription
1 NEbraskaCERT 2005: Security Information and Event Management (SIEM) Matt Stevens Chief Technology Officer Network Intelligence Corporation
2 Security Information/Events = Logs Logs are audit records generated by any software component running on your IT infrastructure Log records cover: Normal activity Error conditions Configuration changes Policy changes User access to assets Incident alerts Unauthorized use of resources Non-privileged access to files User behavior patterns Clearing of sensitive data Access to audit trails Logs provide feedback on the status of IT resources and all activity going through them
3 Example Logs Sample Operating System Logs Windows2K Server 2005/05/17 12:59: EDT %NICWIN-4Security_529_Security: Security, ,Tue May 17 12:58: , 529,Security,NT AUTHORITY/SYSTEM,Failure Audit,WA1-MASTERFDC,Logon/Logoff,,Logon Failure: Reason: Unknown user name or bad password User Name: PIQA Domain: Ntoss Logon Type: 3 Logon Process: NtLmSsp Authentication Package: NTLM Workstation Name: UpTime-HA 2005/05/17 12:59: EDT %NICWIN-4Security_560_Security: Security, ,Tue May 17 12:58: , 560,Security,NTOSS/ashtylla,Failure Audit,WA1-MAS90-DC,Object Access,,Object Open: Object Server: SC Manager Object Type: SC_MANAGER OBJECT Object Name: ServicesActive New Handle ID: - Operation ID: {0, } Process ID: 784 Primary User Name: C:\WINNT\system32\services.exe Primary Domain: WA1MAS90-DC$ Primary Logon ID: NTOSS Client User Name: (0x0,0x3E7) Client Domain: ashtylla Client Logon ID: NTOSS Accesses (0x0,0xF8EAAF4) Privileges READ_CONTROL Connect to service controller Enumerate services Query service database lock state
4 Traditional Interest in Event Logs Point security solutions provide log messages about critical network events Main focus on firewalls and IDS/IPS devices Correlation of events from multiple security points reduces false positives
5 Insider Threat Study Paper: Insider Threat Study: Computer System Sabotage in Critical Infrastructure Sectors Published by: U.S Secret Service and CERT Coordination Center/SEI Date: May 2005 From Section3 Detecting the attack: In general, 75% of the insiders were identified through manual procedures only, and 19% were identified using a combination of automated and manual procedures. The various mechanisms used to identify the perpetrators included system logs (70%) insider s own source IP address (33%) phone records (28%) username (24%) auditing procedures (13%) In those cases in which system logs were used to identify the insider as the perpetrator, the following logs were used remote access logs (73%) file access logs (37%) system file change logs (37%) database/application logs (30%) logs (13%)
6 But That Is Just The Beginning Event log data is the single most underutilized source of information within the organization.
7 Capacity Planning Compute Resources Network Bandwidth LAN & WAN Disk space consumption Servers Clients
8 Performance & Uptime Where events happen When they occur Who is affected What sub-systems are involved Identify common elements
9 Legal & Human Resources Accurate, detailed audit trail Enforce acceptable use policies A report sitting on your chair Monday AM is a powerful deterrent to further abuse Provides supporting evidence Can link human assets to IT assets
10 Incident Investigation & Forensics A strong historical record is your best friend What seems benign today can turn out to be harmful tomorrow Logs can quickly narrow down the search Similar incidents become easier to resolve
11 Help Limit Corporate Liability Determined abuse is hard to stop An effective policy that is actively monitored proves corporate responsibility It s hard to intimidate an event log
12 Detect & Prevent I.P. Theft Makes spotting unusual patterns easier Proper resource access can be monitored An effective logging policy can serve as a strong deterrent to casual I.P. theft Supports efficient prosecution
13 Audit & Enforce Employee Productivity I.T. resources are expensive and budgets are tight Maintaining peak competitive stature is key to corporate entity survival 1% increase in information worker productivity can net nearly a 5% increase in corporate profits* *Source: 2003 McKinsey report on global competition
14 Troubleshoot System and Network Problems The original reason for logging Over 30% of the code in 1969 version of UNI was dedicated to logging support* Can be extended to support internal application development Logs tell the story that other debugging techniques miss *Source: Ken Thompson and Dennis Ritchie, Bell Labs
15 Support Compliance Regulations Applies to both Gov t and industry regs All regulations are based upon similar principles: Establish controls Monitor the controls Report on the trends and monitoring efforts We all know today s list of regulations An effective event log platform prepares you for tomorrow
16 Audit & Enforce IT Security Policy Apply risk metrics to IT processes Finding breakdowns in IT security policy faster reduces IT risk Only effective way to validate point source security technologies
17 Event Log Data Creators Web server activity Web cache & proxy logs VA Scan logs IDS/IDP logs Router logs Windows logs Client & file server logs Content management logs Switch logs Firewall logs Wireless access logs VPN logs Windows domain logins Linux, Unix, Windows OS logs DHCP logs NAS Access Logs VLAN Access & Control logs Mainframe logs Oracle Financial Logs Database Logs
18 Event Log Information Consumers Finance Marketing Sales Customer Legal Service Human Resources Operations Engineering
19 Event Log Information Mapping Consumers to Use Cases Capacity Perform. Legal/HR Incidents Corp. Planning & Uptime Action Forensics Liability I.P. Theft Regulatory Employee Trouble- I.T. Prod. Shooting Security Compliance Marketing Legal Sales Customer Service Finance Human Resources Operations Engineering
20 Many Consumers & Use Cases Silos of Redundant Information Management
21 How to Avoid Silos? Deploy an Enterprise-class SIEM Solution Collect All the Data. Broad device support: network, security, infrastructure, & applications Agent-less, multi-protocol, non-normalized (no filtering) data capture 100% raw data capture Deep source device coverage. Not a subset of events, all of the known events into a Scalable Enterprise Platform Modular growth to expand with business initiatives Price/performance for enterprise-class deployments Efficient storage and personnel utilization that Provides Powerful Analysis for Compliance Violations and Security Threats Multiple views into the data Targeted reports for security, SO, HIPAA, etc Correlation results between device types Baseline of workflows Detailed forensic analysis Guaranteed, real-time alert performance under load
22 Security Information and Event Management (SIEM) 3 Data Analysis 2 Data Management 1 Data Collection
23 Collection: Of Strategic Importance It All Starts Here Goal: Capture 100% of the Data But still be able to make use of it Requirements: Scalable system Must be able to meet the accumulating collection rates Wide device support Analysis capabilities for many device types No filtering or normalization of data All data is important - normal activity included. Robust data management tools Raw data collection High data compression rates Encryption of stored data Authentication of stored data Agents vs. Agent-less
24 Collection: Implementing the Strategy Roll the device collection by types of devices or by departments Focus on the most critical assets first Turn on auditing features on your critical assets Leverage SIEM to transform the data into information that in turns drives knowledge
25 Collection: Source Device Protocols Syslog Syslog-NG SNMP Windows event logging API CheckPoint LEA FTP Formatted log files comma/tab/space delimited, other ODBC connection to remote databases Push/pull ML files via HTTP Cisco IDS POP/RDEP/SDEE
26 Collection: Open Device Support Architecture should be open and permit in-field addition and updates of source device(s). Uses existing source device collection protocols Should not require changes to core product Treat devices as added content that can be distributed without interruption to production systems Automatically identify unknown events, yet still permit intelligent analysis later if required
27 Analysis: Real-time Correlation Easy to Use GUI Rule-based Correlation Anomaly-based Correlation In-line Analysis Variable Decay-time Taxonomy-Driven Baselines 3D Asset Awareness Scalable Performance All the Data Delivers Efficient and Effective Security Operations. Correlation Logic can be Managed Online or Offline. Advanced Boolean Logic Driven Correlation Enables Real-time Evaluation Against Corporate Policies Detects and Alerts on Variations from Automatically Computed Baselines of both Events and Alerts. REAL Real-Time Analysis with Consistent High Performance Alerting, Independent of Incoming EPS. Permits Sophisticated Correlation Logic to Detect and Alert on Multi-Vector Fast Attack & Low and Slow Auto Calculation of Normal for All Events, Devices and Alerts. 100% Mapped via Extensible Taxonomy Intelligent Alert Ranking Via Automatic Gathering Of Asset Vulnerability, Value, & Type K Sustained EPS from up to 30K Source Devices with 100% Data Capture Provides Best TCO Accuracy Assured Regardless of Event Format Changes. Huge Device Breadth & Depth. No Agents.
28 Analysis: Vulnerability Data VA tools provides a known list of hosts and detected vulnerabilities. Analysis can leverage this data to score threats based on asset vulnerabilities All rules evaluate vulnerability data of all the target assets. Higher vulnerability values of attacked assets escalate the severity level Customized rules should be able to evaluate individual assets or asset groups and alert when their vulnerabilities exceed a certain level
29 Analysis: Threat Scoring Alerts are grouped into alert categories All alert categories have (5) alert severity levels that default to US Homeland Security levels Internal scoring algorithm automatically computes alert severity levels based upon event contents, rates, baselines and asset values Incorporates asset attributes, including frequency of asset in event payload, importance and vulnerability Automatic ranking of all alerts contained in a view to focus security administrators on most critical incidents first
30 Analysis: Event Classification All events should be classified using a global taxonomy structure thus providing a standard to the myriad of non-standard log events from all source device vendors Leveraging taxonomy to evaluate events by category, regardless of source device permits correlation to stay current and relevant far easier Event classification should be fully exposed to the user. Users should be able to create new categories and assign new messages to any level in the taxonomy tree
31 Analysis: Baseline Data Baselines should be created automatically learned from the actual network activity Minute, hour, day and week baselines permit tracking of spikes as well as low and slow patterns Baselines are aware of normal activity pattern changes over the course of the day, week and month. Correlation engines can use baseline data to detect anomalies based on activity percent change from normal behavior
32 Analysis: Baselines Score over time Score Value Time (in Minutes) Current Score Score Baseline %Difference % Difference 60 80
33 Analysis: Baselines Score over time Score Value Time (in Minutes) Current Score Score Baseline % Difference
34 Analysis: Baselines Score over time % % % % 18% 16% % 50 10% % 2% 20-5% Time (in Minutes) Current Score Score Baseline % Difference % Difference Score Value Severity Levels Calculation 78
35 Analysis: Baselines Score over time % % % % 18% 16% % 50 10% % 2% 20-5% Score Baseline 5 < or = 10% = Low 6 >10% higher than Score Baseline = Guarded >25% higher than Score Baseline = Elevated >50% higher than Score Baseline = High >75% higher than Score Baseline = Severe Time (in Minutes) Current Score Score Baseline % Difference 12 % Difference Score Value Severity Levels Calculation 78
36 Analysis: Correlation Example Worm Detection Correlation Rule Name: W32.Blaster Worm The goal of this rule is to detect Blaster worm variants as well as other malicious code by analyzing network traffic patterns. 13
37 Analysis: Correlation Example Website Attack Correlation Rule Name: SQL Injection Attack The goal of this rule is to detect information theft from E-Commerce websites through the exploitation of the trusted connection between the web server and the database. 14
38 Analysis: Real-time Threat Analysis 27
39 Analysis: Real-time Threat Analysis 28
40 Analysis: Reporting User Activity from External Domains
41 Analysis: Reporting Operational Change Control
42 Analysis: Reporting Password Changes and Expirations
43 Analysis: Reporting Top 20 Denied Inbound 31
44 Analysis: Reporting Top 20 Firewall Categories (Taxonomy) 32
45 Analysis: Reporting Scheduled Reports 30
46 Analysis: Real-time Event Viewer Data Mining in Real-time or Historically 29
47 An Enterprise Platform for Compliance and Security SIEM
48 Example SIEM Architecture Patent-pending scaleable, distributed architecture for enterprises and global organizations. Local collection and storage of event data with true global analysis across multiple DBs. Leveraging local and remote collectors and a distributed DB, global organizations can collect and process over 300,000 EPS from up to 30,000 devices. Capture, analyze, and manage >26 Billion events per day per distributed DB.
49 ISO 17799: A Content Framework for IT Compliance SIEM SIEM 16
50 Best Practices Don t Try to filter the logs at the source Predicting what is useful or not is like playing Russian Roulette It s much easier to purge information you don t need vs. never having it Good event logging systems will capture 100% and let you purge later Determine Reporting Time Periods 1 week, 1 month, 90 days - more? Reporting Periods will drive event data retention policies. Plan to store data at least 2 complete reporting intervals If you purge old data be sure you have proper archives Archive Key Logs to Long Life Media CD-ROM, DVD-RW, etc Use a centralized, standard time source When event logs are time aligned life is much easier Be cautious of sensitive event log content Many logs are sent in the clear leverage a VPN for WANs Be sure that centralized logging facility is secure
51 Best Practices Don t Alert on Everything Take it Slow Prioritize on what You REALLY want to be alerted on Leverage Correlation to Weed Out False Positives Rules-based correlation techniques can reduce the chatter Correlated reporting will let get a more holistic view of the network Test Your Logging Facility Are you REALLY capturing all the logs? REALLY? Encourage Your Teams to Analyze the Data Determine your standard reports develop baselines look for exceptions If You Didn t Log It, Then It Never Happened
SANS Top 20 Critical Controls for Effective Cyber Defense
WHITEPAPER SANS Top 20 Critical Controls for Cyber Defense SANS Top 20 Critical Controls for Effective Cyber Defense JANUARY 2014 SANS Top 20 Critical Controls for Effective Cyber Defense Summary In a
NitroView Enterprise Security Manager (ESM), Enterprise Log Manager (ELM), & Receivers
NitroView Enterprise Security Manager (ESM), Enterprise Log Manager (ELM), & Receivers The World's Fastest and Most Scalable SIEM Finally an enterprise-class security information and event management system
Concierge SIEM Reporting Overview
Concierge SIEM Reporting Overview Table of Contents Introduction... 2 Inventory View... 3 Internal Traffic View (IP Flow Data)... 4 External Traffic View (HTTP, SSL and DNS)... 5 Risk View (IPS Alerts
LOG AND EVENT MANAGEMENT FOR SECURITY AND COMPLIANCE
PRODUCT BRIEF LOG AND EVENT MANAGEMENT FOR SECURITY AND COMPLIANCE The Tripwire VIA platform delivers system state intelligence, a continuous approach to security that provides leading indicators of breach
Global Partner Management Notice
Global Partner Management Notice Subject: Critical Vulnerabilities Identified to Alert Payment System Participants of Data Compromise Trends Dated: May 4, 2009 Announcement: To support compliance with
How To Manage Security On A Networked Computer System
Unified Security Reduce the Cost of Compliance Introduction In an effort to achieve a consistent and reliable security program, many organizations have adopted the standard as a key compliance strategy
QRadar SIEM 6.3 Datasheet
QRadar SIEM 6.3 Datasheet Overview Q1 Labs flagship solution QRadar SIEM is unrivaled in its ability to provide an organization centralized IT security command and control. The unique capabilities of QRadar
An Introduction to SIEM & RSA envision (Security Information and Event Management) January, 2011
An Introduction to SIEM & RSA envision (Security Information and Event Management) January, 2011 Brian McLean, CISSP Sr Technology Consultant, RSA Changing Threats and More Demanding Regulations External
ARS v2.0. Solution Brief. ARS v2.0. EventTracker Enterprise v7.x. Publication Date: July 22, 2014
Solution Brief EventTracker Enterprise v7.x Publication Date: July 22, 2014 EventTracker 8815 Centre Park Drive, Columbia MD 21045 About EventTracker EventTracker delivers business critical solutions that
Guideline on Auditing and Log Management
CMSGu2012-05 Mauritian Computer Emergency Response Team CERT-MU SECURITY GUIDELINE 2011-02 Enhancing Cyber Security in Mauritius Guideline on Auditing and Log Management National Computer Board Mauritius
Clavister InSight TM. Protecting Values
Clavister InSight TM Clavister SSP Security Services Platform firewall VPN termination intrusion prevention anti-virus anti-spam content filtering traffic shaping authentication Protecting Values & Enterprise-wide
FISMA / NIST 800-53 REVISION 3 COMPLIANCE
Mandated by the Federal Information Security Management Act (FISMA) of 2002, the National Institute of Standards and Technology (NIST) created special publication 800-53 to provide guidelines on security
How To Manage Sourcefire From A Command Console
Sourcefire TM Sourcefire Capabilities Store up to 100,000,000 security & host events, including packet data Centralized policy & sensor management Centralized audit logging of configuration & security
RSA envision. Platform. Real-time Actionable Security Information, Streamlined Incident Handling, Effective Security Measures. RSA Solution Brief
RSA Solution Brief RSA envision Platform Real-time Actionable Information, Streamlined Incident Handling, Effective Measures RSA Solution Brief The job of Operations, whether a large organization with
IBM QRadar Security Intelligence April 2013
IBM QRadar Security Intelligence April 2013 1 2012 IBM Corporation Today s Challenges 2 Organizations Need an Intelligent View into Their Security Posture 3 What is Security Intelligence? Security Intelligence
When it Comes to Monitoring and Validation it Takes More Than Just Collecting Logs
White Paper Meeting PCI Data Security Standards with Juniper Networks SECURE ANALYTICS When it Comes to Monitoring and Validation it Takes More Than Just Collecting Logs Copyright 2013, Juniper Networks,
Effective Use of Security Event Correlation
Effective Use of Security Event Correlation Mark G. Clancy Chief Information Security Officer The Depository Trust & Clearing Corporation DTCC Non-Confidential (White) About DTCC DTCC provides custody
NitroView. Content Aware SIEM TM. Unified Security and Compliance Unmatched Speed and Scale. Application Data Monitoring. Database Monitoring
NitroView Unified Security and Compliance Unmatched Speed and Scale Application Data Monitoring Database Monitoring Log Management Content Aware SIEM TM IPS Today s security challenges demand a new approach
Scalability in Log Management
Whitepaper Scalability in Log Management Research 010-021609-02 ArcSight, Inc. 5 Results Way, Cupertino, CA 95014, USA www.arcsight.com [email protected] Corporate Headquarters: 1-888-415-ARST EMEA Headquarters:
CLOUD GUARD UNIFIED ENTERPRISE
Unified Security Anywhere CLOUD SECURITY CLOUD GUARD UNIFIED ENTERPRISE CLOUD SECURITY UNIFIED CLOUD SECURITY Cloudy with a 90% Chance of Attacks How secure is your cloud computing environment? If you
INTRUSION DETECTION SYSTEMS and Network Security
INTRUSION DETECTION SYSTEMS and Network Security Intrusion Detection System IDS A layered network security approach starts with : A well secured system which starts with: Up-to-date application and OS
Passive Logging. Intrusion Detection System (IDS): Software that automates this process
Passive Logging Intrusion Detection: Monitor events, analyze for signs of incidents Look for violations or imminent violations of security policies accepted use policies standard security practices Intrusion
LOG MANAGEMENT AND SIEM FOR SECURITY AND COMPLIANCE
PRODUCT BRIEF LOG MANAGEMENT AND SIEM FOR SECURITY AND COMPLIANCE As part of the Tripwire VIA platform, Tripwire Log Center offers out-of-the-box integration with Tripwire Enterprise to offer visibility
White Paper: Meeting and Exceeding GSI/GCSx Information Security Monitoring Requirements
White Paper: Meeting and Exceeding GSI/GCSx Information Security Monitoring Requirements The benefits of QRadar for protective monitoring of government systems as required by the UK Government Connect
The Value of Vulnerability Management*
The Value of Vulnerability Management* *ISACA/IIA Dallas Presented by: Robert Buchheit, Director Advisory Practice, Dallas Ricky Allen, Manager Advisory Practice, Houston *connectedthinking PwC Agenda
The Comprehensive Guide to PCI Security Standards Compliance
The Comprehensive Guide to PCI Security Standards Compliance Achieving PCI DSS compliance is a process. There are many systems and countless moving parts that all need to come together to keep user payment
Using Ranch Networks for Internal LAN Security
Using Ranch Networks for Internal LAN Security The Need for Internal LAN Security Many companies have secured the perimeter of their network with Firewall and VPN devices. However many studies have shown
Cisco Remote Management Services for Security
Cisco Remote Management Services for Security Innovation: Many Take Advantage of It, Some Strive for It, Cisco Delivers It. Cisco Remote Management Services (RMS) for Security provide around the clock
Company Co. Inc. LLC. LAN Domain Network Security Best Practices. An integrated approach to securing Company Co. Inc.
Company Co. Inc. LLC Multiple Minds, Singular Results LAN Domain Network Security Best Practices An integrated approach to securing Company Co. Inc. LLC s network Written and Approved By: Geoff Lacy, Tim
LOG INTELLIGENCE FOR SECURITY AND COMPLIANCE
PRODUCT BRIEF uugiven today s environment of sophisticated security threats, big data security intelligence solutions and regulatory compliance demands, the need for a log intelligence solution has become
Information Technology Policy
Information Technology Policy Security Information and Event Management Policy ITP Number Effective Date ITP-SEC021 October 10, 2006 Category Supersedes Recommended Policy Contact Scheduled Review [email protected]
Ovation Security Center Data Sheet
Features Scans for vulnerabilities Discovers assets Deploys security patches transparently Allows only white-listed applications to run in workstations Provides virus protection for Ovation Windows workstations
FIVE PRACTICAL STEPS
WHITEPAPER FIVE PRACTICAL STEPS To Protecting Your Organization Against Breach How Security Intelligence & Reducing Information Risk Play Strategic Roles in Driving Your Business CEOs, CIOs, CTOs, AND
Meeting and Exceeding GSI/GCSx Information Security Monitoring Requirements with Enterasys SIEM
Meeting and Exceeding GSI/GCSx Information Security Monitoring Requirements with Enterasys SIEM The benefits of Enterasys SIEM for protective monitoring of government systems as required by the UK Government
Meeting PCI Data Security Standards with
WHITE PAPER Meeting PCI Data Security Standards with Juniper Networks STRM Series Security Threat Response Managers When it Comes to Monitoring and Validation it Takes More Than Just Collecting Logs Copyright
Introduction to Network Discovery and Identity
The following topics provide an introduction to network discovery and identity policies and data: Host, Application, and User Detection, page 1 Uses for Host, Application, and User Discovery and Identity
What is Security Intelligence?
2 What is Security Intelligence? Security Intelligence --noun 1. the real-time collection, normalization, and analytics of the data generated by users, applications and infrastructure that impacts the
How To Create Situational Awareness
SIEM: The Integralis Difference January, 2013 Avoid the SIEM Pitfalls Get it right the first time Common SIEM challenges Maintaining staffing levels 24/7 Blended skills set, continuous building of rules
CorreLog Alignment to PCI Security Standards Compliance
CorreLog Alignment to PCI Security Standards Compliance Achieving PCI DSS compliance is a process. There are many systems and countless moving parts that all need to come together to keep user payment
FREQUENTLY ASKED QUESTIONS
FREQUENTLY ASKED QUESTIONS Secure Bytes, October 2011 This document is confidential and for the use of a Secure Bytes client only. The information contained herein is the property of Secure Bytes and may
Vulnerability Management
Vulnerability Management Buyer s Guide Buyer s Guide 01 Introduction 02 Key Components 03 Other Considerations About Rapid7 01 INTRODUCTION Exploiting weaknesses in browsers, operating systems and other
Q1 Labs Corporate Overview
Q1 Labs Corporate Overview The Security Intelligence Leader Who we are: Innovative Security Intelligence software company One of the largest and most successful SIEM vendors Leader in Gartner 2011, 2010,
CS 356 Lecture 17 and 18 Intrusion Detection. Spring 2013
CS 356 Lecture 17 and 18 Intrusion Detection Spring 2013 Review Chapter 1: Basic Concepts and Terminology Chapter 2: Basic Cryptographic Tools Chapter 3 User Authentication Chapter 4 Access Control Lists
Meeting PCI Data Security Standards with Juniper Networks Security Threat Response Manager (STRM)
White Paper Meeting PCI Data Security Standards with Juniper Networks Security Threat Response Manager (STRM) When It Comes To Monitoring and Validation It Takes More Than Just Collecting Logs Juniper
Log Management How to Develop the Right Strategy for Business and Compliance. Log Management
Log Management How to Develop the Right Strategy for Business and Compliance An Allstream / Dell SecureWorks White Paper 1 Table of contents Executive Summary 1 Current State of Log Monitoring 2 Five Steps
Secure Networks for Process Control
Secure Networks for Process Control Leveraging a Simple Yet Effective Policy Framework to Secure the Modern Process Control Network An Enterasys Networks White Paper There is nothing more important than
ForeScout CounterACT. Device Host and Detection Methods. Technology Brief
ForeScout CounterACT Device Host and Detection Methods Technology Brief Contents Introduction... 3 The ForeScout Approach... 3 Discovery Methodologies... 4 Passive Monitoring... 4 Passive Authentication...
TABLE OF CONTENT. Page 2 of 9 INTERNET FIREWALL POLICY
IT FIREWALL POLICY TABLE OF CONTENT 1. INTRODUCTION... 3 2. TERMS AND DEFINITION... 3 3. PURPOSE... 5 4. SCOPE... 5 5. POLICY STATEMENT... 5 6. REQUIREMENTS... 5 7. OPERATIONS... 6 8. CONFIGURATION...
Automate PCI Compliance Monitoring, Investigation & Reporting
Automate PCI Compliance Monitoring, Investigation & Reporting Reducing Business Risk Standards and compliance are all about implementing procedures and technologies that reduce business risk and efficiently
Information Security Basic Concepts
Information Security Basic Concepts 1 What is security in general Security is about protecting assets from damage or harm Focuses on all types of assets Example: your body, possessions, the environment,
CHANGING THE SECURITY MONITORING STATUS QUO Solving SIEM problems with RSA Security Analytics
CHANGING THE SECURITY MONITORING STATUS QUO Solving SIEM problems with RSA Security Analytics TRADITIONAL SIEMS ARE SHOWING THEIR AGE Security Information and Event Management (SIEM) tools have been a
By: Gerald Gagne. Community Bank Auditors Group Cybersecurity What you need to do now. June 9, 2015
Community Bank Auditors Group Cybersecurity What you need to do now June 9, 2015 By: Gerald Gagne MEMBER OF PKF NORTH AMERICA, AN ASSOCIATION OF LEGALLY INDEPENDENT FIRMS 2015 Wolf & Company, P.C. Cybersecurity
Ranch Networks for Hosted Data Centers
Ranch Networks for Hosted Data Centers Internet Zone RN20 Server Farm DNS Zone DNS Server Farm FTP Zone FTP Server Farm Customer 1 Customer 2 L2 Switch Customer 3 Customer 4 Customer 5 Customer 6 Ranch
Business white paper. Missioncritical. defense. Creating a coordinated response to application security attacks
Business white paper Missioncritical defense Creating a coordinated response to application security attacks Table of contents 3 Your business is under persistent attack 4 Respond to those attacks seamlessly
Analyzing Logs For Security Information Event Management Whitepaper
ADVENTNET INC. Analyzing Logs For Security Information Event Management Whitepaper Notice: AdventNet shall have no liability for errors, omissions or inadequacies in the information contained herein or
Architecture Overview
Architecture Overview Design Fundamentals The networks discussed in this paper have some common design fundamentals, including segmentation into modules, which enables network traffic to be isolated and
Analyzing Security for Retailers An analysis of what retailers can do to improve their network security
Analyzing Security for Retailers An analysis of what retailers can do to improve their network security Clone Systems Business Security Intelligence Properly Secure Every Business Network Executive Summary
Operationalizing Information Security: Top 10 SIEM Implementer s Checklist
Operationalizing Information Security: Top 10 SIEM Implementer s Checklist www.accelops.com Table of Contents Executive Summary.................................................................... 3 SIEM
March 2012 www.tufin.com
SecureTrack Supporting Compliance with PCI DSS 2.0 March 2012 www.tufin.com Table of Contents Introduction... 3 The Importance of Network Security Operations... 3 Supporting PCI DSS with Automated Solutions...
How To Buy Nitro Security
McAfee Acquires NitroSecurity McAfee announced that it has closed the acquisition of privately owned NitroSecurity. 1. Who is NitroSecurity? What do they do? NitroSecurity develops high-performance security
Compliance and Security Information Management for PCI DSS Requirement 10 and Beyond
RSA Solution Brief Compliance and Security Information Management for PCI DSS Requirement 10 and Beyond Through Requirement 10, PCI DSS specifically requires that merchants, banks and payment processors
What IT Auditors Need to Know About Secure Shell. SSH Communications Security
What IT Auditors Need to Know About Secure Shell SSH Communications Security Agenda Secure Shell Basics Security Risks Compliance Requirements Methods, Tools, Resources What is Secure Shell? A cryptographic
LogRhythm and PCI Compliance
LogRhythm and PCI Compliance The Payment Card Industry (PCI) Data Security Standard (DSS) was developed to encourage and enhance cardholder data security and facilitate the broad adoption of consistent
Everything You Always Wanted to Know About Log Management But Were Afraid to Ask. August 21, 2013
Everything You Always Wanted to Know About Log Management But Were Afraid to Ask August 21, 2013 Logging and Log Management Logging and Log Management The authoritative Guide to Understanding the Concepts
Privileged. Account Management. Accounts Discovery, Password Protection & Management. Overview. Privileged. Accounts Discovery
Overview Password Manager Pro offers a complete solution to control, manage, monitor and audit the entire life-cycle of privileged access. In a single package it offers three solutions - privileged account
INFORMATION SECURITY GOVERNANCE ASSESSMENT TOOL FOR HIGHER EDUCATION
INFORMATION SECURITY GOVERNANCE ASSESSMENT TOOL FOR HIGHER EDUCATION Information security is a critical issue for institutions of higher education (IHE). IHE face issues of risk, liability, business continuity,
The Fundamental Difference Between SIEM & Log Management Solutions: State vs. Event Data
The Fundamental Difference Between SIEM & Log Management Solutions: State vs. Event Data An EiQ Networks White Paper The Fundamental Difference Between SIEM & Log Management Solutions: State vs. Event
Achieving SOX Compliance with Masergy Security Professional Services
Achieving SOX Compliance with Masergy Security Professional Services The Sarbanes-Oxley (SOX) Act, also known as the Public Company Accounting Reform and Investor Protection Act of 2002 (and commonly called
ARE YOU REALLY PCI DSS COMPLIANT? Case Studies of PCI DSS Failure! Jeff Foresman, PCI-QSA, CISSP Partner PONDURANCE
ARE YOU REALLY PCI DSS COMPLIANT? Case Studies of PCI DSS Failure! Jeff Foresman, PCI-QSA, CISSP Partner PONDURANCE AGENDA PCI DSS Basics Case Studies of PCI DSS Failure! Common Problems with PCI DSS Compliance
How To Control Vcloud Air From A Microsoft Vcloud 1.1.1 (Vcloud)
SOC 1 Control Objectives/Activities Matrix goes to great lengths to ensure the security and availability of vcloud Air services. In this effort, we have undergone a variety of industry standard audits,
with Managing RSA the Lifecycle of Key Manager RSA Streamlining Security Operations Data Loss Prevention Solutions RSA Solution Brief
RSA Solution Brief Streamlining Security Operations with Managing RSA the Lifecycle of Data Loss Prevention and Encryption RSA envision Keys with Solutions RSA Key Manager RSA Solution Brief 1 Who is asking
Unified Threat Management, Managed Security, and the Cloud Services Model
Unified Threat Management, Managed Security, and the Cloud Services Model Kurtis E. Minder CISSP Global Account Manager - Service Provider Group Fortinet, Inc. Introduction Kurtis E. Minder, Technical
Best Practices for Log File Management (Compliance, Security, Troubleshooting)
Log Management: Best Practices for Security and Compliance The Essentials Series Best Practices for Log File Management (Compliance, Security, Troubleshooting) sponsored by Introduction to Realtime Publishers
Network Security Administrator
Network Security Administrator Course ID ECC600 Course Description This course looks at the network security in defensive view. The ENSA program is designed to provide fundamental skills needed to analyze
Secospace elog. Secospace elog
Secospace elog Product Overview With the development of networks, security events continually occur on hosts, databases, and Web servers. These range from Trojans, worms, and SQL injections, to Web page
CyberArk Privileged Threat Analytics. Solution Brief
CyberArk Privileged Threat Analytics Solution Brief Table of Contents The New Security Battleground: Inside Your Network...3 Privileged Account Security...3 CyberArk Privileged Threat Analytics : Detect
Analyzing Logs For Security Information Event Management
ZOHO Corp. Analyzing Logs For Security Information Event Management Whitepaper Notice: ManageEngine shall have no liability for errors, omissions or inadequacies in the information contained herein or
SIEM Optimization 101. ReliaQuest E-Book Fully Integrated and Optimized IT Security
SIEM Optimization 101 ReliaQuest E-Book Fully Integrated and Optimized IT Security Introduction SIEM solutions are effective security measures that mitigate security breaches and increase the awareness
PCI Compliance - A Realistic Approach. Harshul Joshi, CISM, CISA, CISSP Director, Information Technology CBIZ MHM [email protected]
PCI Compliance - A Realistic Approach Harshul Joshi, CISM, CISA, CISSP Director, Information Technology CBIZ MHM [email protected] What What is PCI A global forum launched in September 2006 for ongoing enhancement
SECURITY BEST PRACTICES FOR CISCO PERSONAL ASSISTANT (1.4X)
WHITE PAPER SECURITY BEST PRACTICES FOR CISCO PERSONAL ASSISTANT (1.4X) INTRODUCTION This document covers the recommended best practices for hardening a Cisco Personal Assistant 1.4(x) server. The term
1 Attack Top Attackers Report, Top Targets Report, Top Protocol Used by Attack Report, Top Attacks Report, Top Internal Attackers Report, Top External Attackers Report, Top Internal Targets Report, Top
Lumeta IPsonar. Active Network Discovery, Mapping and Leak Detection for Large Distributed, Highly Complex & Sensitive Enterprise Networks
IPsonar provides visibility into every IP asset, host, node, and connection on the network, performing an active probe and mapping everything that's on the network, resulting in a comprehensive view of
IBM Tivoli Compliance Insight Manager
Facilitate security audits and monitor privileged users through a robust security compliance dashboard IBM Highlights Efficiently collect, store, investigate and retrieve logs through automated log management
Secret Server Qualys Integration Guide
Secret Server Qualys Integration Guide Table of Contents Secret Server and Qualys Cloud Platform... 2 Authenticated vs. Unauthenticated Scanning... 2 What are the Advantages?... 2 Integrating Secret Server
How To Connect Log Files To A Log File On A Network With A Network Device (Network) On A Computer Or Network (Network Or Network) On Your Network (For A Network)
SIEM FOR BEGINNERS EVERYTHING YOU WANTED TO KNOW ABOUT LOG MANAGEMENT BUT WERE AFRAID TO ASK www.alienvault.com A Rose By Any Other Name SLM/LMS, SIM, SEM, SEC, SIEM Although the industry has settled on
UNDERSTANDING EVENT CORRELATION AND THE NEED FOR SECURITY INFORMATION MANAGEMENT
UNDERSTANDING EVENT CORRELATION AND THE NEED FOR SECURITY INFORMATION MANAGEMENT Enormous logs are produced by various network devices like IDS or Firewall, Webserver, applications and databases which
We are Passionate about Total Security Management Architecture & Infrastructure Optimisation Review
We are Passionate about Total Security Management Architecture & Infrastructure Optimisation Review The security threat landscape is constantly changing and it is important to periodically review a business
Top 10 SIEM Implementer s Checklist
Top 10 SIEM Implementer s Checklist Operationalizing Information Security Compliments of AccelOps www.accelops.com Table of Contents Executive Summary....................................................................
End-to-end Solutions to Enable Log Management Best Practices
White paper End-to-end Solutions to Enable Log Management Best Practices Deploying a Comprehensive Security Information and Event Management Platform Executive Summary More and more organizations today
USM IT Security Council Guide for Security Event Logging. Version 1.1
USM IT Security Council Guide for Security Event Logging Version 1.1 23 November 2010 1. General As outlined in the USM Security Guidelines, sections IV.3 and IV.4: IV.3. Institutions must maintain appropriate
GMI CLOUD SERVICES. GMI Business Services To Be Migrated: Deployment, Migration, Security, Management
GMI CLOUD SERVICES Deployment, Migration, Security, Management SOLUTION OVERVIEW BUSINESS SERVICES CLOUD MIGRATION Founded in 1983, General Microsystems Inc. (GMI) is a holistic provider of product and
About Network Data Collector
CHAPTER 2 About Network Data Collector The Network Data Collector is a telnet and SNMP-based data collector for Cisco devices which is used by customers to collect data for Net Audits. It provides a robust
Boosting enterprise security with integrated log management
IBM Software Thought Leadership White Paper May 2013 Boosting enterprise security with integrated log management Reduce security risks and improve compliance across diverse IT environments 2 Boosting enterprise
