Anton Chuvakin
Original URL: http://blogs.gartner.com/anton-chuvakin/2012/08/09/on-people-running-siem/ | Archive.org Snapshot
Anton Chuvakin
Research Director
1 year with Gartner
12 years IT industry
Anton Chuvakin is a research director at Gartner's IT1 Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio
Coverage Areas:
by Anton Chuvakin | August 9, 2012 | 2 Comments
As promised, this next post from my SIEM research project is about people. Over the course of my 10+ year (!) experience with SIEM technology, I have come across organizations that assumed that buying and deploying a SIEM tool is all they need to do for security monitoring. I wish I can say that the number of such occurrences has decreased over time, but, in reality, it has increased (probably because less mature organizations are now buying SIEM tools en masse).
In any case, let me repeat what I’ve said many times in the past: your investment in SIEM will be completely, totally, absolutely wasted if you don’t have smart people operating the tool on an ongoing basis (yes, “ongoing basis” really does mean forever).
There are multiple ways to rephrase it so that more people will hopefully get it. My teammate Ramon Krikken once called SIEM “a force multiplier” for security. If your “force” of security analysts is 0 before SIEM, then using a force multiplier will still leave it at zero. Another way to say it is that SIEM is not and will not be a “set and forget” technology and everybody who even hints that their SIEM is “set and forget” is a liar. Yet another way of saying it is: a security monitoring project or a SIEM project isn’t … a project. It is a process that you start and then improve over time – and never “complete” by reassigning people to other things. Or, as my esteemed colleague said, “the end result is that your monitoring simply can’t work without a sufficient supply of carbon-based life forms.”
Still, I’m getting mixed reports about what percentage of organization buying SIEM tools only use them for simple log aggregation. Guess what, you can get log aggregation for 1/5-1/100 of a cost of SIEM. You can sometimes get it for free.
After this preface, let me follow with some questions that I’m trying to answer:
As a final word, the best SIEM deployments I’ve seen that also brought the most value to organizations were run by teams of skilled, passionate, well-trained and dedicated intrusion analysts.
Any other questions I missed? Any answers?
Category: logging monitoring security SIEM Tags: security, security monitoring, SIEM
1 Elba Stevenson August 11, 2012 at 12:01 am
How many change can you make to the SIEM tool in 24 hours, and how long will it take to impact the company?
2 James Voorhees August 11, 2012 at 2:54 pm
The question of who should have access also needs to be raised. I pose that question with the following in mind:
A SIEM sees everything on the network. Consequently, it can have value beyond looking for intrusions. So who should be able to view it? Who should be able to develop content for needs outside a strict security function?
Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.
© 2012 Gartner, Inc and/or its affiliates. All rights reserved.