enterprisesecuritymag

| | JULY 2024ENTERPRISE SECURITY8IN MY OPINIONIN MY OPINIONArnaud WieheOVER STIMULATING SIEMBy Craig Newell, CISSP, CISA, CISM, CRISC, CDPSE, Vice President, Enterprise Information Security, GDI Integrated Facility Services Inc.The problem with feeding every log from every system into your organization's SIEM is it gets every log from every system, creating a virtual tsunami of data. However, data itself is useless; it needs to be turned into information, which is then consumed to become knowledge. With hundreds of thousands of data points flooding your correlation engine, how can we InfoSec professionals filter out the chaff and get to the wheat?It seems obvious, but aggregation, correlation, and alerting tools need tuning to get the most out of them. Too many organizations implement an SIEM, turn on every rule they can find, and wait for alerts with the mindset of `not wanting to miss anything.' This Craig Newell
< Page 7 | Page 9 >