Challenges traditional SEM/SIM/SIEM solution projects |
|
The majority of traditional SIM, SEM and SIEM solution projects have failed to meet critical expectations. Reasons for these failures are mainly due to using inadequate technology, lack of skilled resources, poor reporting value, no 24/7 manned operations and maybe most important, 'project thinking'. Let's have a look at what Secode finds when auditing SIEM infrastructures: - Relative passive SEM/SIM infrastructure, project based
- Aging hardware dependent technology
- Non-optimal scaling options
- Poor analysis of security events
- No real-time correlation
- Troublesome connector development
- No currently required reporting content, quality and frequency
- SEM/SIM not part of the incident management organisation
- High operational costs against less than average results
- High technology costs against less than average results
- No 24/7 manned SEM/SIM operations
- No effective and managed internal and external SLA's
It's quite a lengthy list, but 9 years of SIEM experience does count for something. Please do read further... |