Home > Midmarket IT Security Tips > Security Operations and Strategies > Selecting a SIM for a midmarket business
Midmarket IT Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY OPERATIONS AND STRATEGIES

Selecting a SIM for a midmarket business


Diana Kelley
04.20.2009
Rating: --- (out of 5)


Midmarket Security Strategies and Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


The term security information management (SIM) can evoke bad memories for security administrators. Many have spent large amounts of time and money installing and configuring a major enterprise SIM, only to find out it was too complex and heavy to manage. But times have changed.

Early SIM tools were, for the most part, aimed at large enterprise customers and often came with a high customization price tag that put them out of reach for smaller firms. A few SIM vendors, like eIQnetworks, e-Security (now Novell), and TriGeo have noticed the underserved market and introduced offerings aimed specifically at midmarket customers. The midmarket offerings have expanded functionality to support larger enterprises. Bigger, more established enterprise SIM vendors, like ArcSight Inc., netForensics Inc. and RSA, have introduced packages that are easier to install and manage in a midmarket organization.

Some companies have written their own log aggregation and correlation rules. Creating a small customized SIM can work for companies with plenty of developer resources available, but is too labor-intensive for many small to mid-size organizations. For companies that like the idea of a free SIM but don't have the developer resources, another option is the Open Source Security Information Management (OSSIM) tool compilation, which is available for download. OSSIM comprises a number of well-known, open source security tools, like Arpwatch, Nessus, Snort and Tcptrack, which have been integrated to provide a framework for security monitoring and an engine for information correlation. OSSIM also offers commercial support via Alienvault, a startup that manages the project. Alienvault also offers data feeds that update the various components of the OSSIM solution, plus training, certification and consulting.

To find the commercial SIM that best fits your enterprise, create a list of requirements before talking to vendors. From the business side, assess what kinds of reporting and policy information are required. Find out if the vendor product has pre-configured reporting templates that meet your company needs, or if it can be configured to meet them with minimal effort. Inquire about what correlation rules are included with the product for risk assessment and proactive monitoring. And how easy is it to add new rules? Create a list of devices, applications and operating systems that you want to have covered by the SIM and then compare this to the vendors' offerings. While most solutions allow for customized integration on unsupported targets, the cost to add this functionality could significantly impact the total project cost.

Differences in architecture can impact the deployment process. For some organizations, installing and managing agents on target devices is not an option. In these cases, agentless architecture SIMs are the best solution, but this doesn't mean agent-based SIMs are the wrong choice for all companies. Having an agent on a device provides an on-host monitor that may be better at identifying stealth changes and installations than an agentless solution that trusts the log data.

For those firms that want the functionality, but not the administrative overhead, SIM management can be outsourced to a managed security service provider (MSSP) like VeriSign Inc. or Cyberklix Inc.. For companies that prefer to install and manage security products themselves, it's good to know that products have matured and are easier to use out of the box. If you're a small to mid-size company that thought SIM was too expensive, it might be time to reconsider.

About the author:

Diana Kelley is a partner with Amherst, N.H.-based consulting firm SecurityCurve. She formerly served as vice president and service director with research firm Burton Group. She has extensive experience creating secure network architectures and business solutions for large corporations and delivering strategic, competitive knowledge to security software vendors.

Send comments on this technical tip to editor@searchmidmarketsecurity.com.


Rate this Tip
To rate tips, you must be a member of SearchMidmarketSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Security Operations and Strategies
How to choose an external compliance auditor
PCI DSS: Writing an information security policy
How to choose full disk encryption for laptop security, compliance
How to create a bit-image copy of a live server
PCI DSS requirement: Monitoring and testing security
Think about performance, data protection when choosing endpoint security suites
Start with centralized endpoint security management when buying suites
How to choose hosted Web security services
Get more out of your security event log data
PCI DSS requirement: Implement strong access control procedures

Integrated security appliances and systems
Think about performance, data protection when choosing endpoint security suites
How many firewalls do you need?
Making sense of basic unified threat management features
What are common (and uncommon) unified threat management features?
How to set up a managed unified threat management remote firewall/VPN appliance
Should UTM and Web security filtering software be used together?

Security Event Management
Get more out of your security event log data
How to use Excel for security log data analysis

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
unified threat management  (SearchMidmarketSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts