Monday | 22 March, 2010
CSO
Avoiding Pitfalls in Log Management Planning
Key considerations include scalability and references at comparable organizations, says ArcSight's Ansh Patnaik.
Ansh Patnaik 26/03/2009 10:25:00

Over the past decade cyber security has emerged as an important concern for organizations of all sizes. The increase in digitized corporate records, coupled with the rise in cyber crime, is driving organizations in the public and private sectors to invest in more protection for sensitive data and regulated or other critical assets. In just the first two months this year, the Privacy Rights Clearinghouse has noted data breaches at several financial, healthcare and educational institutions as well at federal, state and local governmental agencies.

While private businesses may store specific pieces of information about a consumer-such as a credit card number or a medical record-in different departments, governments process and store enough information to entirely reconstruct an identity. The risk they must address goes well beyond consumer identity theft. Governments conduct research and development in numerous areas, including biotechnology and military advancement. They manage and regulate the transportation and utilities infrastructures. All of these functions rely heavily on information systems which, if compromised, would have a widespread impact and tremendous cost.

Monitoring and Log Management

Fundamentally, protecting IT assets in the public or private sector requires visibility into activity occurring on networks. But with so much happening at any given time-employees logging in and out of applications, badge swipes, email communications, opening and closing of sensitive files etc, simply capturing and making sense of network activity in itself a huge challenge. This is where effective log management can make a huge difference.

Logs provide a minimally intrusive means of gaining visibility into all user, system, and application activities. With proper planning, selection, and deployment of a log management solution, organizations can proactively detect threats, breaches, and policy violations, while also reducing the costs and efforts associated with regulatory compliance. Yet, across the planning and selection phases of log management important criteria and considerations are often overlooked.

Planning Phase

In the planning phase, the most common oversight is inadequate consideration of long term use cases and drivers. Any organization might begin its search for a log management solution with a given driver in mind, such as perimeter device monitoring. Over time, most will expand into broader use cases such as privileged user monitoring or regulatory compliance with FISMA, HIPAA, and PCI, etc. This trend highlights the importance of evaluating the functional breadth and the scalability of any log management solution up front.

A common driver for functional breadth arises as use cases transition from requiring historical analysis (which is integral for regulatory compliance) to robust real time correlation capabilities (for scenarios such as user activity monitoring or sensitive data protection). Solutions that do not offer an integrated growth path from historical to real time analysis (or vice versa) will eventually require a second investment with redundant log collection and storage layers.

More about ArcSight

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the CSO Online comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

Making the move to Ethernet | A DECISION GUIDE

While enterprises today need higher bandwidth, there is increasing demand for solutions that can provide scalability, performance, simplicity and control at lower costs. Get the best of both worlds - read about Ethernet adoption today.

Sponsored Links