Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 22513

Re: So Good They Can't Ignore SIEM

$
0
0

deverts

 

Your statement above about the "S" in SIEM equates to "$" is not highlighted enough, the "S" really equates to "$$$$$$." And the amount of personnel to maintain the data becomes exponential if you add more than a couple systems and network devices to it.

 

I remember many years ago a SIEM vendor that you didn't mentioned came for a presentation. We were interested in the product, but it would cost us millions of dollars for everything we wanted to feed to the SIEM. A few years later that SIEM company was acquired and changed their licensing model. Finally we purchased the product, but it's still not cheap.

 

So, I guess the real question is, how much $ can you afford for a false sense of security? You can collect the data, but if you don't act on it immediately, it's too late. You can automate, but the second you prevent a C-Level from accessing data, you are shutting it down. And no matter what, a hacker is going to find his/her way around the system.

 

I wouldn't say SIEM contributes a false sense of security. Yes, it takes a lot of $$$ and resources to make it right and there is always something more to be desired. A properly set up SIEM has its vital function in an organization. See below.

 

Security is not 1 layer of protection and you are secure. Security is multiple layers, and a SIEM is just the component that provides visibility.

 

The multiple layers of security can also be known as defense in depth. Any organization got burnt before would add more layers of defense and this would require multiple disciplines within the organization. SIEM, being a component of the defense in depth, is absolutely necessary as visibility is critical.


Viewing all articles
Browse latest Browse all 22513

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>