Security Informaiton Management: An introduction

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Favorites, Groups & Events

    Security Informaiton Management: An introduction - Presentation Transcript

    1. Implementing SIM Today Security Information Management Revealed
    2. Managing Security Data Today…
      • Hundreds of streams of data
      • Stored and transmitted using different formats
      • Scattered through out the organizations IT environment
      • Not viewed, correlated or verified…
    3. We are losing the battle…
      • Technical attacks going unnoticed
      • Fraud and abuse unrestricted within the organization
      • Loss of critical forensic data
    4. Our capabilities are limited…
      • Ability to handle wide spread incidents
      • Ability to diagnosis large environment issues
      • Ability to detect and deter fraud
      • Ability to maintain compliance
    5. Security Data is useless.
      • Data must be translated into relevant knowledge regarding our environment and risk levels.
      • Automation of data gathering, filtering and reporting is needed to create useful information sets.
      • Information must be escalated and responded to by trained staff.
    6. Introduction
      • Michael Legary
      • Founder, Seccuris Inc.
      • CISSP, CISA, CISM, GCIH, CCSA
    7. Overview
      • What is SIM & SEM?
      • SEM Architecture & Design
      • SIM Processes & Procedures
      • Implementation Considerations
      • Available Solutions
      • The future of SIM
    8. What is SIM?
      • Security Information Management (SIM)
      • An systems management framework facilitating the collection, retention and translation of security control data into relevant risk management information.
      • People and processes supported by automated systems
    9. What is SEM?
      • Security Event Management (SEM)
      • Security Information & Event Management (SIEM)
      • An information system providing consolidation, management and archival of security event data
      • Automated systems supporting people
    10. The Value of SIM & SEM
      • Technical
        • Single repository for correlation, analysis & escalation
        • Enable Incident Response and Forensic Programs
        • Streamline troubleshooting and diagnosis of technical environment
    11. The Value of SIM & SEM
      • Audit
        • Enable & Monitor Compliance
        • Manage risk from control breaches
        • Reduce risk from technical control failures
    12. The Value of SIM & SEM
      • Business
        • Create efficiencies within asset protection
        • Facilitate Business Intelligence programs
        • Deter & Identify Corporate Espionage
    13. Overview
      • What is SIM?
      • SEM Architecture & Design
      • SIM Processes & Procedures
      • Implementation Considerations
      • Available Solutions
      • The future of SIM
    14. SEM Architecture & Design
      • Event Consolidation
      • Event Management
      • Event Archiving
    15. SEM Architecture & Design
    16. SEM Architecture & Design
      • Event Consolidation
        • Collection
        • Normalization
        • Correlation
      • Event Management
      • Event Archiving
    17. SEM Architecture & Design
      • Event Collection
        • Data Sources such as:
          • Firewalls
          • OS Events
          • Network Devices (Routers, VPNs, Sniffers)
          • IDS / IPS (Network & Host)
          • Anti-virus
          • Proxy & Usage Monitoring Systems
          • Vulnerability Management Systems
          • Databases & SANs
          • Unique Application Controls
    18. SEM Architecture & Design
      • Event Collection
    19. SEM Architecture & Design
      • Event Collection
        • Communication methods
          • SNMP
          • Syslog
          • Telnet / SSH Transfers
          • Proprietary
    20. SEM Architecture & Design
      • Things to think about in Event Collection
        • Avoid systems that only have limited input methods!
        • Ask specifics about capacity
          • Events Per Second
          • Bandwidth Usage
          • Average Storage Requirements
    21. SEM Architecture & Design
      • Event Consolidation
        • Collection
        • Normalization
        • Correlation
      • Event Management
      • Event Archiving
    22. SEM Architecture & Design
      • Event Normalization
        • Standardize data for input into central repository
        • Handle unknown or incomplete data streams
        • Translate data types to increase efficiency
    23.  
    24. SEM Architecture & Design
      • Things to think about in Event Normalization
        • Not all “Normalization” is created equal
        • Avoid systems that
          • Simplify
          • Modify
          • Re-encode
    25. SEM Architecture & Design
      • Event Consolidation
        • Collection
        • Normalization
        • Correlation
      • Event Management
      • Event Archiving
    26. SEM Architecture & Design
      • Event Correlation
        • Examination of existing data sets to determine if an attack has occurred
        • Attempts to reduce false positives
        • Functionality offered by SIM systems varies widely
    27. SEM Architecture & Design
      • Event Correlation
        • Rule Based
          • Some pre-existing finite knowledge of the attack
          • Tied-in with historical data to minimize false positives
        • Statistical (Algorithmic)
          • Relies on the knowledge and recognition of normal activity over time
          • Calculates threat levels though weighting of real-time & historical data about the asset and the attack.
    28. SEM Architecture & Design
      • Things to think about in Event Correlation
        • When evaluating a system you need a good understanding of what data will be going in.
        • Some systems misinterpret / discount intrusion prevention data (IPS)
        • False Accept rates vary widely in large scale implementations
    29. SEM Architecture & Design
      • Event Consolidation
      • Event Management
        • Analysis
        • Reporting
        • Tracking & Escalation
      • Event Archiving
    30. SEM Architecture & Design
    31. SEM Architecture & Design
      • Event Analysis
        • Real-time Monitoring
          • Active
          • Passive
        • Historical Event Analysis
          • High & Wide
          • Deep & Narrow
    32. SEM Architecture & Design
      • Thinks to look for in Event Analysis
        • Select a system that is consistent with your capabilities and requirements
          • Who are the main users?
          • Are there other audiences using the system?
          • What are their responsibilities?
        • Is the event analysis system auditable?
          • Different levels of access? Logging?
    33. SIM Architecture & Design
      • Event Consolidation
      • Event Management
        • Analysis
        • Reporting
        • Tracking & Escalation
      • Event Archiving
    34. SIM Architecture & Design
      • Event Reporting
        • Real-time or Historical
        • Multiple Views
          • Management, Audit, Technical
        • Integration with Incident Management & Forensics
    35. SEM Architecture & Design
      • Things to look for in Event Reporting
        • Ease-of-use
        • Performance
        • Customization
    36. SEM Architecture & Design
      • Event Consolidation
      • Event Management
        • Analysis
        • Reporting
        • Tracking & Escalation
      • Event Archiving
    37. SEM Architecture & Design
      • Event Tracking & Escalation
        • Ticketing System
          • Integrated, Add-on or External
        • Alerting Mechanisms
          • Integrated, Add-on or External
    38. SEM Architecture & Design
      • Things to look for in Tracking & Escalation
        • Ticketing System
          • Ease-of-use, Performance, Customization
          • Control and Audit
        • Alerting Mechanisms
          • Encryption
          • Redundancy
          • Expandability
    39. SEM Architecture & Design
      • Event Consolidation
      • Event Management
      • Event Archiving
        • Storage
    40. SEM Architecture & Design
    41. SEM Architecture & Design
      • Event Archiving
        • On-Line Storage
        • Near-Line Storage
        • Off-Line Storage
    42. SEM Architecture & Design
      • Things to look for in Event Archiving
        • Technologies used
        • Encryption
        • Compression
        • Automation of process
        • Reporting & Alerting of issues
    43. SEM Architecture & Design
      • Event Consolidation
        • Collection
        • Normalization
        • Correlation
      • Event Management
        • Analysis
        • Reporting
        • Tracking & Escalation
      • Event Archiving
        • Storage
        • Redundancy
        • Maintenance
    44. Overview
      • What is SIM?
      • SEM Architecture & Design
      • SIM Processes & Procedures
      • Implementation Considerations
      • Available Solutions
      • The future of SIM
    45. SIM Processes & Procedures
      • Core Processes
        • Identification
        • Collection
        • Analysis
        • Escalation
        • Reporting
        • Tracking & Workflow Management
        • Maintenance
    46. SIM Processes & Procedures
      • Tie core processes to existing ones
        • Incident Handling
        • Forensics
        • Network Health Monitoring
        • Active Systems Audits
      • Map back to security framework or best practice
        • SABSA
        • ISO / COBIT
    47. Overview
      • What is SIM?
      • SEM Architecture & Design
      • SIM Processes & Procedures
      • Implementation Considerations
      • Available Solutions
      • The future of SIM
    48. Implementation Considerations
      • Choosing an effective strategy
        • Available Resources
          • Skill Sets
        • Placement
          • Requirements (Application or Appliance)
          • Locations
          • Justifications
    49. Implementation Considerations
      • Choosing an effective strategy
        • Monitoring
          • Real-Time
          • Historical
        • Analysis
          • Involved Parties
          • Required SLAs
    50. Implementation Considerations
      • Choosing an effective strategy
        • Reporting
          • What are the needs of the target audience?
          • Canned Reports?
          • What customization is required?
        • Workflow Management
          • Integrated
          • Use existing
    51. Implementation Considerations
      • Capacity Planning
        • Performance Requirements
        • Storage Strategy
        • Caching, Failover & Redundancy
        • Back-end system compatibility
    52. Implementation Considerations
      • Justifying the complete investment
        • Initial needs assessment & workflow design
        • Up-front technology expenditure
        • Staff Education & Knowledge Transfer
        • On-going maintenance & Staffing
    53. Overview
      • What is SIM?
      • SEM Architecture & Design
      • SIM Processes & Procedures
      • Implementation Considerations
      • Available Solutions
      • The future of SIM
    54. Available Solutions
      • Applications
        • Minimum long term commitment
        • Maximum integration pain
      • Appliances
        • Turn-key solution
        • Limited customization
      • Managed Services
        • Facilitated Integration & SLA’s
        • Minimum retained knowledge
    55. Available Solutions Source: Security Event Management Gets Specialized Andrew Conry-Murray
    56. Available Solutions
    57. Available Solutions
      • Implementation Costs & Considerations
        • Needs Analysis
        • SIM Development
        • SEM Purchase
        • SEM Implementation
        • Maintenance
    58. Overview
      • What is SIM?
      • SEM Architecture & Design
      • SIM Processes & Procedures
      • Implementation Considerations
      • Available Solutions
      • The future of SIM
    59. The Future of SIM
      • The need for centralized data interpretation is not going away.
      • SIM will slowly become an accepted management framework in Information Assurance Programs
      • Smooth, Standardized Integration is on its way
    60. Conclusions
      • Security Information Management allows you to:
        • Manage & Reduce Risk
        • Enable Compliance
        • Facilitate Business Intelligence programs
    61. Conclusions
      • Invest in understanding your requirements
      • Potential for a white elephant is high
      • Commit to long term improvement of the chosen strategy
    62. Thank-you
      • Michael Legary
      • Founder, Seccuris Inc.
      • (204) 255-4490
      • [email_address]
      • www.seccuris.com

    + Michael LegaryMichael Legary, 10 months ago

    custom

    345 views, 0 favs, 0 embeds more stats

    Information Security managers have long been tasked more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 345
      • 345 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 30
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories