Data Protection: SIEM use up in midsized orgs, surveys say
- 03 June, 2010 03:28
- Comments
IT security practitioners typically greet vendor-based studies with skepticism because they come off as a sales pitch for whatever products that vendor sells. People become especially leery when a study leads to the predicted death of a particular security tool. But when looked at cumulatively, such studies offer small snapshots of why companies are making certain security decisions.
Two newly released studies aiming to do just that looked at how security information event management (SIEM) and other log management tools are being used in mid-sized companies.
The take-away of these studies, conducted by RSA and the SANS Institute, is that midmarket organizations are moving beyond the technology as a mere compliance checklist item to build security programs more commonly found at the enterprise level.
The first survey -- conducted by SANS Institute in partnership with RSA -- is a sampling of data from the SANS Sixth Annual Log Management Survey Report focused on small and mid-sized organizations with less than two thousand employees. More than 200 people took the survey, which found, among other things:
- Almost 80 percent rank detection and prevention highest in criticality.
- The top of mind critical issue is detection and prevention suggesting this segment of users need their log management solutions to handle more than just compliance and reporting.
- respondents reported logs are most useful for forensic analysis and correlation followed by detection and prevention, both at over 90 percent, suggesting the needs of mid-sized organizations are becoming more sophisticated and they are demanding more value from their log management systems.
"Up until now, compliance to regulations has been a catalyst, enabling log management to grow and mature as never before," said Sam Curry, RSA's chief technologist. "Now that this technology is in place there is the option to better take advantage of some of the more sophisticated SIEM tools designed to support the evolving security needs of mid-sized organizations."
SANS Senior Analyst Jerry Shenk believes, based on the data, that midmarket organizations increasingly crave the "efficiency of a log management solution to move beyond compliance to security detection, reaction and prevention as well as augment effective IT and network operations."
In the second survey, RSA conducted a separate study of mid-sized organizations to better understand the market for log management and SIEM. The results confirm suspicions that security is moving up as a top priority in this market, Curry said. Almost 90 percent of respondents said the primary use for their SIEM tools is for security operations functions while 54 percent cited compliance.
Meanwhile, 66 percent of respondents ranked real-time monitoring as most important when evaluating a SIEM vendor. More than 75 percent said that in their minds, real-time monitoring is essential.
For this survey, RSA polled about 50 IT executives from organizations of up to 10,000 employees. It was conducted online in Q1 2010 and included such industries as financial services, healthcare, high-tech, manufacturing and retail. Respondents were from more than 15 countries, including the U.S., Argentina, UK, India, South Africa, Canada, Brazil, Pakistan, Egypt, Turkey, Poland, France, Macedonia, Australia, Thailand, Japan, and Netherlands.
Read more about data protection in CSOonline's Data Protection section.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Get Control: make document management an integral part of your overall IT strategy
- Cost Effective Security and Compliance with Oracle Database 11g Release 2
- Simplifying branch office security
- Magic Quadrant for Enterprise Disk-Based Backup/Recovery
- Using Application Control to Reduce Risk with Endpoint Security
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Phones are distractions during catch-ups
-
Google's Sidewiki lets people post comments about Web pages
-
Transforming Software Delivery: An IBM Rational Case Study
The IBM Rational® software development organization consists of more than 2000 analysts, architects, project managers, developers, and quality professionals distributed over 15 locations on six continents. Our mission is to ensure the success of our customers through the development of a robust portfolio of software and systems delivery products. We create and maintain 57 product families that span distributed, System z®, and Power® operating environments. -
Case Study: Svenska Kraftnät safeguards web and ensures communication security with Clearswift
Energy producers from surrounding countries load power onto the Swedish National Grid’s network, with energy suppliers then paying the Swedish National Grid to load onto their grids for them to sell-on to customers. Using Clearswift’s Email Appliance, and MIMEsweeper for SMTP means that the organisation has safe and resilient email helping them to meet their goal of providing a safe, robust, cost-effective and environmentally sound energy transmission system. -
Magic Quadrant for Managed Print Services, Worldwide
Gartner's managed print services (MPS) Magic Quadrant is a useful starting point for identifying and evaluating MPS providers. It is intended for Gartner's client base of mainly midsize and large organisations, many of which operate throughout two or more regions, and some of which are truly global. Although not all MPS projects are multiregional or global at the outset, customers often choose to scale up one region at a time. In this way, they can manage their office printing in a unified manner globally. Read more.
-
Office 2007 for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Teach Yourself Visually Windows 7
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Windows 7 for Dummies®
-
MYOB Software for Dummies 6E Australian Edition








Comments
Post new comment