Security is one of the IT certainties that you could probably add to the “nothing can be said to be certain, except death and taxes” proverb. Although, perhaps Benjamin Franklin wasn’t exactly clued up with the debate around automating IT security processes.
One thing Franklin did often refer to was laws; compliance if you will, something that has driven the IT security world (nuts?) for a number of years. Compliance to meet the security and regulatory changes that have occurred in the last decade has been a central factor in the development of IT management processes.
Do you know your PCI from your Data Protection Act; your HIPAA from your MiFiD? Details are just a smokescreen when the problem is that wherever compliance is mandated, it has often meant manual responses such as sifting through security reports and events for malicious activity. This is a hugely inefficient process made worse by regulatory pressure. While regulators will continue to bring in new standards and such like, security has become a far wider, holistic entity within an organisation.
Security Information and Event Management (SIEM) is one such technology that can greatly aid IT managers in trying to automate and add efficiency to security processes. The benefits to such a solution can include; improved detection of cross-enterprise threats, ending the need to interrogate multiple data sources, space and power savings, and empowering more professionals with less specialised skills to be able to carry out the task. And that’s to say nothing of the enormous compliance benefits…