Tuesday, May 24, 2011

What influences your day to day decision making?

Does your strategic vision drive your tactical focus or do your tactical decisions turn into your strategic vision?

Will you have the same answer when you look back in six months?

Friday, May 6, 2011

The mortar between your defenses

The other day I read a bit by Andreas M. Antonopoulos on Networkworld about how to be an effective security buyer. Of course when it came to finding the article again when I wanted to write this….I couldn’t find it. +1 to the Interwebs though because Mike Rothman over at Securosis mentioned it in Wednesday's Incite 4 U. Andreas’ advice seems to be when you are buying security tools to not buy something designed to fulfill a singular function. Instead go for multi-purpose tools that can cover down on multiple areas. I think the idea somewhat boils down to knocking out two birds with one stone + it sucks to have to look at one dashboard for each tool you have. Enterprise resource scaling aside though I tend to agree with Mike’s take. What really stood out to me was an analogy Andreas used:

Tuesday, May 3, 2011

SIEM/LM Analyst Training part 2

The conversation in a meeting the other morning led to a thought…well more of an analogy really. It struck me that in some respects a SIEM/LM analyst or content creator is similar to an auditor. What I mean is you have groups of people devoted to keeping lights blinking be that AV, endpoint management, FW, etc. And then you have groups of people outside of care and feeding group(s) that try to distill value out of either those systems’ configuration or logs to some ends leveraging some other toolset be that specific or multiple compliance requirements or SIEM/LM tools. Auditors and SIEM/LM analysts (at least the tools they use) are sort of a force multiplier in a very loose algebraic sense:

Wednesday, April 27, 2011

How do you address training for SIEM/LM analysts?

I struggled a bit with the title but bear with me.

The question arises from time to time and especially now that I am at my new job where we are being asked to submit training requests for next year’s budget cycle – what training would you like to get/attend? Good question. The challenge in the SIEM-esque/LM space (IMHO) is you are getting events from any number of disparate systems which you may or may not have familiarity. My experience is generally there is a team of folks devoted to the care and feeding of a particular piece of technology but they usually don’t actually look at the (log) data coming out of it with an eye towards taking action – they are focused on making sure the blinking lights stay blinking. You come in at the critical juncture point of marrying up conceptual detection use cases to the technical exercise of extracting value out of the logs the blinking lights produce. So how do you bridge that knowledge gap or do you even approach the subject of getting training with an eye towards this gap or leverage the "training" opportunity to dive into other areas?   

I sure would be interested in how people have tackled this issue. A “Just in Time” 3rd party SME type education model appeals to me but would guess most shops don’t have enough people (or able to free up enough people) to justify the expense of hosting custom training on-site. No doubt shop maturity factors into the discussion. The SANS Intrusion Detection In-Depth class looks pretty good and looks like it covers a decent swath of topics. Have folks found any other good general type courses or do you tend to focus in on specific items/threat types of training with an eye towards “reverse engineering” your knowledge relative to the specific data streams you have coming into your solutions?

Thursday, March 31, 2011

Is ArcSight harder to use?

Interestingly enough (if I read Google Analytics correctly) the post I created back at the beginning of November related to the question of is ArcSight hard to use was the most visited page over the last month. In fact I think it has been on or towards the top of the list since I posted it. Since I have some time on my hands I figured I would write a sort of follow up to that post. Once again I will state that my only SIEM experience is with ArcSight so maybe someone will speak up for the other SIEM engines out there and/or tell me if I’m way off base.

I still maintain asking if something is “hard”, generally speaking, often only gets you only so far. Having some context implied in your question might get you an answer closer to what you really are looking for. Is calculus hard? Depends on who you are talking to. Is calculus harder than basic algebra? Yup. Is “ArcSight” hard to use? Depends on who you are talking to. Is ArcSight harder to use than some other SIEM? Ahh now we are getting somewhere. I did have sort of an interesting thought while reading the SIEM implementation book I wrote a review of back in January (at least it was interesting to me).