Gartner分析报告:SIEM技术评估

Gartner收购Burton Group后,Burton的IT1 Reasearch成为了Gartner的一个子品牌。Burton的研究报告一般都比较深入细致,更偏技术。就在2010年9月24日,Ramon Krikken发表一份研究报告《SIEM Technology Assessment》。
摘要如下:The ongoing evolution of threats and regulations requires the enterprise to put in place systems to perform security monitoring and auditing of a variety of IT components. Security information and event management (SIEM) is an important technology component of an enterprise security auditing and monitoring strategy. In this assessment, Analyst Ramon Krikken examines SIEM technology (including the data it collects, as well as its architecture, analysis capabilities, and user interface) and its place in the greater security monitoring, auditing, and management infrastructure. He also provides recommendations for implementing SIEM in enterprise environments.
以下是该报告的目录:
 

  • Summary of Findings
  • Analysis
    • SIM, SEM, or SIEM: Threat, IT, and Compliance Management Evolution
      • Threat Analysis and Incident Management
      • Compliance Measures and Compliance Measurement
      • Beyond Infrastructure: User and Application Monitoring
      • Beyond Security: Operational Monitoring
    • Information Overload: And Still Not Enough Data?
      • Data of All Shapes and Sizes: Event, State, and Context
      • Data Everywhere: Collecting and Managing Security Information
    • Security Monitoring Architecture and SIEM
      • Scalability and Availability Through Componentization
      • Security Monitoring System Hierarchies
      • Security Monitoring in Cloud Environments
      • The Effect of Standards (or Lack Thereof)
    • Deriving Actionable Information Through Analytics
      • Real-Time and Post Hoc Data Analysis
      • Rule-Based Event Analytics
      • Anomaly Detection Event Analytics
      • Information Interfaces, Exploration, and Visualization
    • Organizational Factors in Implementation
    • Strengths
    • Weaknesses
  • Recommendations
  • Notes
  • Further Information
     
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值