Information Technology Security (ITSec): The Effects of SIEM Technology in Monitoring Employee Computer Use
Roberto Sandoval · Journal of the Association for Information Systems · 2014
Threats against network security systems are increasing with more sophisticated attack techniques being utilized by adversaries from both outside and inside of the network itself. In response to this ever growing threat, there is a new concept for the formation of a new type of Incident Response Center (IRC) specifically to address the Insider Threat against enterprise level systems that utilize Security Information & Event Management (SIEM) monitoring technology. The SIEM technology and the IRC are being developed and integrated for computer network real-time monitoring in order to counter Insider Threats within an organization. The SIEM technology monitors network system security and access controls in real-time and correlates this logged information with other events triggered within the network to keep track of possible threats. This study will examine the effects of real-time SIEM technology on employee computer use.