Critical Analysis needed. Please follow the instructions on the paper. Thank you

profileJohn_matt
case_study_1.docx

While your business may have enjoyed adequate protection from your current security parameters in place, its success is dependent strictly on the consistent ability of each security product to effectively recognize and defeat every threat. New threats and attacks methods are created each day. It is important to study our past in order to effectively prepare for our protection needs of the future. Monitoring and analyzing each individual security platform can be an exhausting venture affecting monetary resources as well as staffing for network security personnel. Your company needs a unified approach for security event management and analysis that can be readily implemented with the strategies and systems already in place.

            Service Information and Event Management provides a collaborative platform that facilitates tracking, management and investigation of all current information security products running on a network. It provides analyst with the essential tools for a full spectrum oversight of all network security and access logs. Logs are gathered from all network devices and services and are comprised as a single presentation on a designated management machine. Constantine’s study depicts “SIEM as mapping information, infrastructure and business processes to logs, empowering security analysts to make reasoned, informed investigations into activities on the network to determine their impact on security integrity and business continuity,” (2014). A Service Information and Event Management (SIEM) tool provides real time alerts and response capabilities for all network security platforms already in place on the network as well as facilitating auditing of all historic events.

            I recommend IBM’s Security QRadar tool for effective security event management services for your network. QRadar is comprised of five major components including a log manager, SIEM, vulnerability scanner & management, network data flow, and incident forensics, (Kavanagh, K. & Rochford, O., 2015). Log manager collects all event and access logs from all network devices storing them onto a designated SIEM management machine. This application provides the ability customize tolerance yields that can differentiate from actionable events and false positives. Vulnerability scanner and management tool facilitates network scans for potentials vulnerabilities. It provides a historic report of all scans for auditing purposes. The network data flow tools, QFlow and vFlow, provide live feeds and snapshots of all network traffic. This application enables compartmentalization of network data used to identify known and potential attacks to the network. The Incident forensics platform provides in depth historic information on all known security violations. This tool facilitates investigate into the root cause of the breach in efforts to prevent similar breaches in the future. A key opportunity for QRadar is scalability, as it currently only allows a single SIEM management machine on the network, (InfoSec Nirvana, 2013). This may create an issue with cost within larger companies as they will require additional SIEM management consoles as well as additional administrators for multiple sub networks.

            IBM’s Security QRadar offers a simple installation process and can be deployed as physical application or through a cloud based management framework. QRadar comes standard with over 1500 categorized reports that can be ran immediately to manage potential threats, (InfoSec Nirvana, 2013). Its network data flow tool collaborates with incident forensics to provide improved real time protection against network threats. QRadar’s vulnerability scanner will identify significant areas of concern. Administrators can use this information to make necessary modifications to mitigate risk, such as restricting external email senders and email attachments from entering the network firewall. “IBM’s SIEM effectively collects and analyzes log data to identify malicious activity so it can be stopped quickly, preventing or minimizing damage to the organization,” (Scarfone, 2015).

References

Constantine, C. (2014, March 7). SIEM and log management – everything you need to know but

            were afraid to ask, part 1. Retrieved from https://www.alienvault.com/blogs/security-

            essentials/everything-you-wanted-to-know-about-siem-and-log-management-but-were-

            afraid

InfoSec Nirvana. (2013, October 3). Punching hard – Qradar Security Intelligence Platform

            Retrieved from http://infosecnirvana.com/qradar-security-intelligence-platform

Kavanagh, K. & Rochford, O. (2015, July 20). Magic Quadrant for Security Information and

            Event Management. Retrieved from file:///C:/Users/hasan/AppData/Local/Microsoft/

           

            Windows/INetCache/IE/L9BGN0DE/Gartner%20-%20Magic%20Quadrant%

            20for%20SIEM%20-%202015.pdf

Scarfone, K. (2015, November). IBM Security QRadar: SIEM product overview. Retrieved from

           http://searchsecurity.techtarget.com/feature/IBM-Security-QRadar-SIEM-product-

            overview