Menu


Security Information & Event Management - SIEM

In IT systems, there are many sources of safety measures and information status. Different devices generate a large amount of logs that are very hard to follow and analyze in real time and it is often possible that some incidents may be notice too late or may not be noticed at all.

Security Information and Event Management (SIEM) solution represent collecting, normalization and automated analysis of security events and logs from various devices in real time. The logs of all network devices, servers, applications for identity management and access to resources, databases and other services in the system are collected in one place due to processing and generating reports i.e. archiving. SIEM solution collects logs and analyzes events, taking into consideration their correlations hence it generates automatic alerts and reports in real time. Depending on your situation, it can set up and receive notifications of potentially hazardous events. On a single console are displayed all the warnings of the entire network, presented and connecting information, generate report i.e. prepared long-term security information provided. The focus is on monitoring and managing user rights and servicing, Name and Network Information Services, monitoring of network activities and changes in the system, revision of logs and management responses to threats. It is not possible to change or be deleted the archived logs in order to cover some activities.

SIEM functionalities:
  • Gathering information from various sources.
  • Correlation, testing and analysis of linkage and dependence between the events and incidents.
  • Warnings, sending an automated alerts for potentially hazardous events immediately after the analysis of the collected data.
  • Presentation overview of significant events through charts, easier identifying non-standard events.
  • Verification of alignment with defined standards for Management of security and protection of information (supported standards PCI DSS, SOX, NIST 800-53, DISA STIG, HIPAA, NERC CIP and NRC RG, DODI Defense Cyber security Program).
  • Long-term preserving security logs.

Benefits:
  • Data protection.
  • Protection from malicious or undesirable actions of employees or external partners.
  • Harmonization with legal regulations.

Manufacturers: New Net Technologies (NNT)