SIEM (SECURITY INFORMATION AND EVENT MANAGEMENT SOLUTIONS) IMPLEMENTATIONS IN PRIVATE OR PUBLIC CLOUDS
Scientific Bulletin of Naval Academy · 2016
The underlying principle of a SIEM system is that relevant data about an enterprise's security is produced in multiple locations and being able to look at all the data from a single point of view makes it easier to spot trends and see patterns that are out of the ordinary.Today's security threats are dynamic in nature and exploits are constantly evolving.Attackers grow more organized, precise and persistent and have access to various automated tools that can trigger very sophisticated attacks.As threatsand security events evolve, SIEM vendors and the information securitycommunity must work together to build relevant and actionable businessanalytics into their systems.By continuously improving recommendationsand the controls to support those recommendations, SIEM products canbecome true information security hubs that not only automate audits butalso provide proactive means to protect the organization.SIEMtechnologies for centralization and consolidation of an organization'ssecurity data will continue to be important investments for organizationswanting to accurately respond to threats and ultimately improve their riskand compliance postures.In the field of computer security, security information and event management (SIEM) software products and services combine security information management (SIM) and security event management (SEM).They provide real-time analysis of security alerts generated by network hardware and applications.