Critical Analysis needed. Please follow the instructions on the paper. Thank you

profileJohn_matt
case_study_2.docx

Companies need to rely on more than just antiviruses and firewalls to protect their assets. They need real time collection of data and access to information from past attacks that may or may not have happened to them. This security solution is call a Security Information and Event Management (SIEM). (Gartner, N.D.) A SIEM supports compliance reporting and incident investigation through historical data from real time or historical analysis. (Gartner, N.D.) SIEM’s collects data from multiple sources such as security devices, network infrastructure, systems, and applications. The data that the solution gathers can be used for incident reports and forensics. The security information and event management (SIEM) market is defined by the customer's need to apply security analytics to event data in real time for the early detection of targeted attacks and data breaches, and to collect, store, analyze and report on log data for incident response, forensics and regulatory compliance. (Kavangh, Rochford, 2015) This product is essential to a companies continued monitoring of their assets and networking systems. This security solution helps maintain the integrity and availability of the company’s software by ensuring logs, and events are categorized and can be analyzed in the future. With any company that is highly mobile a SIEM is a great way to keep track of events and management of logs because most SIEM software can be accessed on the go.

            One of the leaders in the field of SIEM software is Splunk Enterprise. A leader in this field means that they have the vision of what a security solution mean and the ability to get the solution to multiple companies. “Splunk is widely deployed by IT operations and application support teams for log management, analytics, monitoring, and advanced search and correlation.” (Kavangh, Rochford, 2015) Splunk has been designed for an enterprise size company but can support any size business. “Splunk can be deployed on Splunk can be deployed for SIEM as on­premises software, in a public or private cloud, as a SaaS offering from Splunk (Splunk Cloud), or in any combination (hybrid).” (Kavangh, Rochford, 2015) “Organizations that require an SIEM platform that can be customized to support extensive analytics functions and a variety of log formats, and those with use cases that span security and IT operations support, should consider Splunk.” (Kavangh, Rochford, 2015) The strengths of Splunk Enterprise software is that the solution supports a large number of external threat intelligence feeds from multiple sources. The solution is very easy to use and the speed and scalability of the software is not limited to SQL databases. “Easy to create new reports or modify existing ones. Data can be visualized in many ways including tables, charts or scatterplots” (Splunk, N.D.) Most SIEM solutions only focus on the known threats when it comes to detection but Splunk Enterprise uses “‘Known threat’ detection, and can also index “nonsecurity” data to identify the outliers that may be “unknown threats”” (Splunk, N.D.) Splunk Enterprise has enterprise level availability and scale to accommodate terabytes of data per day. “The High Performance Analytics Store and other acceleration technologies enable you to generate reports on big data at lightning fast speeds.” (Splunk, N.D.) This software solution will help the company manage of its assets and collect all of the data from the antivirus and other security solutions.

There are some downsides when picking a company that is known as a leader in the SIEM. This product is mainly designed for large scale Enterprise Company so the support for predefined conditions is basic. If the company is going to be experiencing a extremely large data flow they might want to consider seeking another company since the pricing is based on volume of data that is indexed per day. (Kavangh, Rochford, 2015) “Workflow and case management functions lag behind those of competitors. Organizations with mature SOC processes may require customization or integrations with third­party technologies for these functions.” (Kavangh, Rochford, 2015)

References:

Gartner, N.D. Security Inforemation and Event Management retrieved from http://www.gartner.com/it-glossary/security-information-and-event-management-siem

Kavangh, Kelly,. Rochford,. Oliver 20 July 2015. Magic Quadrant for Security Information and Event Management retrieved from https://scadahacker.com/library/Documents/White_Papers/Gartner%20-%20Magic%20Quadrant%20for%20SIEM%20-%202015.pdf

N.A, N.D, Using Splunk Software as a Siem retrieved from https://www.splunk.com/web_assets/pdfs/secure/Splunk_as_a_SIEM_Tech_Brief.pdf

N.A, N.D, Splunk Enterprise retrieved from http://www.splunk.com/en_us/products/splunk-enterprise.html