<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Information Management Resource Guide</title>
	<atom:link href="http://www.simbuyer.com/weblog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.simbuyer.com/weblog</link>
	<description>New Resource Weblog</description>
	<lastBuildDate>Fri, 04 Jun 2010 18:14:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Security Information Management Purchasing Best Practices: Security Information Management: Not Just the Next Big Thing</title>
		<link>http://www.simbuyer.com/weblog/security-information-management-purchasing-best-practices-security-information-management-not-just-the-next-big-thing/</link>
		<comments>http://www.simbuyer.com/weblog/security-information-management-purchasing-best-practices-security-information-management-not-just-the-next-big-thing/#comments</comments>
		<pubDate>Fri, 04 Jun 2010 16:44:04 +0000</pubDate>
		<dc:creator>simbuyer</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://simbuyer.com/weblog/?p=148</guid>
		<description><![CDATA[&#8220;When shopping for SIM vendors: 1) Learn about the organization, not just the product and its price tag (though SIM products do have a large price variance). 2) Read the customer testimonials to understand what kind of problems customers were able to solve. 3) Make sure the critical assets, such as servers and firewalls, can [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;When shopping for SIM vendors: 1) Learn about the organization, not just the product and its price tag (though SIM products do have a large price variance). 2) Read the customer testimonials to understand what kind of problems customers were able to solve. 3) Make sure the critical assets, such as servers and firewalls, can be covered, but leave room for some flexibility. 4) See a product demonstration, preferably a live system where the flow of data can be seen. 5) Ask questions of the sales team that they may not be able to answer. The purchaser has to live with this product, and he/she needs to be confident that the vendor as a whole is doing what is in his/her best interest and the product is going to address the organization&#8217;s needs. 6) Get a feel for how the product is deployed and what the responsibilities are going to be during deployment. It is pretty safe to assume that the SIM vendors have deployed more SIM solutions than the buyer, so they should be able to answer any questions about how they will deploy in the organization&#8217;s environment.&#8221;</p>
<p>Resource: <a href="http://www.itgi.org/Template.cfm?Section=Home&amp;CONTENTID=52656&amp;TEMPLATE=/ContentManagement/ContentDisplay.cfm">Security Information Management: Not Just the Next Big Thing</a></p>
<p>Source: Nicole Pauls, Information Systems Audit and Control Association</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=90&amp;resourceid=sim_quotes_media&amp;Itemid=67">Security Information Management Purchasing Best Practices</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/security-information-management-purchasing-best-practices-security-information-management-not-just-the-next-big-thing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Information Management Best Practices: SIM Lessons Learned Along the Way</title>
		<link>http://www.simbuyer.com/weblog/security-information-management-best-practices-lessons-learned-along-the-way/</link>
		<comments>http://www.simbuyer.com/weblog/security-information-management-best-practices-lessons-learned-along-the-way/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 13:18:41 +0000</pubDate>
		<dc:creator>simbuyer</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://simbuyer.com/weblog/?p=160</guid>
		<description><![CDATA[Top 5 SIM Mistakes and Misconceptions: 1) Expecting installation of Security Information Management (SIM) software to solve a problem. 2) No definition of the problem to solve with SIM implementation. 3) Failure to define usage (use cases) before work begins. 4) Failure to understand the data available.] 5) Failure to make SIM relevant to business. [...]]]></description>
			<content:encoded><![CDATA[<p>Top 5 SIM Mistakes and Misconceptions:</p>
<p>1) Expecting installation of Security Information Management (SIM) software to solve a problem.</p>
<p>2) No definition of the problem to solve with SIM implementation.</p>
<p>3) Failure to define usage (use cases) before work begins.</p>
<p>4) Failure to understand the data available.]</p>
<p>5) Failure to make SIM relevant to business.</p>
<p>Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.seccuris.com/documents/newsletters/Seccuris%20Quarterly/Sep06/article2.htm">Lessons Learned Along the Way</a></p>
<p>Source: Tom Chmielarski, Motorola</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=73&amp;resourceid=sim_impact_benefits&amp;Itemid=62">Security Information Management Best Practices</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/security-information-management-best-practices-lessons-learned-along-the-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Information Management Best Practices: Perfect SIEM Preparation: The Crib Sheet</title>
		<link>http://www.simbuyer.com/weblog/security-information-management-best-practices-perfect-siem-preparation-the-crib-sheet/</link>
		<comments>http://www.simbuyer.com/weblog/security-information-management-best-practices-perfect-siem-preparation-the-crib-sheet/#comments</comments>
		<pubDate>Thu, 27 May 2010 15:18:46 +0000</pubDate>
		<dc:creator>simbuyer</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://simbuyer.com/weblog/?p=159</guid>
		<description><![CDATA[&#8220;1) Establish a cross-department steering committee first, to ensure all parties are onside. 2) Build a security baseline: assess activities &#38; risks, prioritise them, and how you&#8217;ll remediate. 3) Simplify the network before installing large management systems to shorten implementation time, reduce event numbers and raise input quality for SIEM. 4) Boost signal to noise [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;1) Establish a cross-department steering committee first, to ensure all parties are onside. 2) Build a security baseline: assess activities &amp; risks, prioritise them, and how you&#8217;ll remediate. 3) Simplify the network before installing large management systems to shorten implementation time, reduce event numbers and raise input quality for SIEM. 4) Boost signal to noise ratios for reduced hardware load and fewer events. 5) Phase the roll-out. 6) People and procedures are vital for successful deployment.&#8221;</p>
<p>Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.net-security.org/article.php?id=1008&amp;p=4">Perfect SIEM Preparation: The Crib Sheet</a></p>
<p>Source: Jason Holloway, Help Net Security</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=73&amp;resourceid=sim_impact_benefits&amp;Itemid=62">Security Information Management Best Practices</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/security-information-management-best-practices-perfect-siem-preparation-the-crib-sheet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Command and Control-Cyber War Foglifter</title>
		<link>http://www.simbuyer.com/weblog/cyber-command-and-control-cyber-war-foglifter/</link>
		<comments>http://www.simbuyer.com/weblog/cyber-command-and-control-cyber-war-foglifter/#comments</comments>
		<pubDate>Fri, 21 May 2010 15:34:30 +0000</pubDate>
		<dc:creator>ajindy</dc:creator>
				<category><![CDATA[SOA Governance]]></category>

		<guid isPermaLink="false">http://www.simbuyer.com/weblog/?p=516</guid>
		<description><![CDATA[Deloitte presents an impressive &#8220;Cyber War Foglifter&#8221; diagram detailing the components of modern IT security threats and defenses. SIEM is shown as a key part of the IT security process (see step six in the diagram). Link to Resource: Cyber Command and Control &#8211; Cyber War Foglifter Source: Deloitte SIM Resource Guide Section: Security Information [...]]]></description>
			<content:encoded><![CDATA[<p>Deloitte presents an impressive &#8220;Cyber War Foglifter&#8221; diagram detailing the components of modern IT security threats and defenses. SIEM is shown as a key part of the IT security process (see step six in the diagram).</p>
<p>Link to Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.deloitte.com/assets/Dcom-UnitedStates/Local%20Assets/Documents/us_ps_CyberCommandandControlFoglifter_030310.pdf">Cyber Command and Control &#8211; Cyber War Foglifter</a></p>
<p>Source: Deloitte</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=59&amp;resourceid=sim_defined_about&amp;Itemid=38">Security  Information Management Explored</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/cyber-command-and-control-cyber-war-foglifter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enterprise Security Tactical Plan &#8211; State of Minnesota</title>
		<link>http://www.simbuyer.com/weblog/enterprise-security-tactical-plan-state-of-minnesota/</link>
		<comments>http://www.simbuyer.com/weblog/enterprise-security-tactical-plan-state-of-minnesota/#comments</comments>
		<pubDate>Sun, 28 Mar 2010 16:45:41 +0000</pubDate>
		<dc:creator>ajindy</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://www.simbuyer.com/weblog/?p=510</guid>
		<description><![CDATA[A insightful, real-life document that describes the State of Minnesota&#8217;s two-year enterprise security tactical plan. The document prioritizes the tactical initiatives for the management, control, and protection of information assets and highlights SIEM as a key component of the plan, which has the following strategic principles: - Improved situational awareness, which includes continuous system monitoring [...]]]></description>
			<content:encoded><![CDATA[<p>A insightful, real-life document that describes the State of Minnesota&#8217;s two-year enterprise security tactical plan. The document prioritizes the tactical initiatives for the management, control, and protection of information assets and highlights SIEM as a key component of the plan, which has the following strategic principles:<br />
- Improved situational awareness, which includes continuous system monitoring and assessment of controls;<br />
- Proactive risk management, such as solidly articulated requirements and ongoing security training; and<br />
- Robust crisis and security incident management, which allows critical services to continue uninterrupted in a crisis.</p>
<p>Link to Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.state.mn.us/mn/externalDocs/OETnet/Enterprise_Security_Tactical_Plan_101509095517_ESO_TacticalPlan.pdf">Enterprise Security Tactical Plan</a> PDF</p>
<p>Source: State of Minnesota</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=76&amp;resourceid=sim_impact_adoption&amp;Itemid=63">Security  Information Management User Implementations and Success Stories</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/enterprise-security-tactical-plan-state-of-minnesota/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Gartner 2010 CyberThreat Landscape</title>
		<link>http://www.simbuyer.com/weblog/the-gartner-2010-cyberthreat-landscape/</link>
		<comments>http://www.simbuyer.com/weblog/the-gartner-2010-cyberthreat-landscape/#comments</comments>
		<pubDate>Thu, 11 Mar 2010 15:07:33 +0000</pubDate>
		<dc:creator>ajindy</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://www.simbuyer.com/weblog/?p=505</guid>
		<description><![CDATA[A strategic and data-rich look at the current CyberThreat landscape. This original report is filled with examples, data, graphics and guidance and covers: - Review of new and expected IT security threats - Cyber threat taxonomy - CIO strategies - Cybercrime as a service &#8211; definitions, examples, and data - Global attack sources - Critical [...]]]></description>
			<content:encoded><![CDATA[<p>A strategic and data-rich look at the current CyberThreat landscape. This original report is filled with examples, data, graphics and guidance and covers:<br />
- Review of new and expected IT security threats<br />
- Cyber threat taxonomy<br />
- CIO strategies<br />
- Cybercrime as a service &#8211; definitions, examples, and data<br />
- Global attack sources<br />
- Critical Security processes<br />
The Resource contains the following recommendations:<br />
- Focus on a two-pronged strategy:<br />
1) Get more efficient at dealing with old threats: platforms, vulnerability avoidance, sourcing.<br />
2) Get more effective at dealing with new threats: Web security gateway, security in the cloud, application control, data protection.<br />
- Institutionalize a threat assessment step in all new business IT projects.<br />
- Protect the business first, demonstrate compliance later. Regulations are rarely a long-term friend to security.</p>
<p>Link to Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.dts.ca.gov/pdf/news_events/sec_awareness/Gartner_CyberThreat_landscape_2010.pdf">The Gartner 2010 CyberThreat Landscape</a></p>
<p>Source: Andrew Walls, Gartner</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=59&amp;resourceid=sim_defined_about&amp;Itemid=38">Security  Information Management Explored</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/the-gartner-2010-cyberthreat-landscape/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIEM Platform Secures University&#039;s Open Network</title>
		<link>http://www.simbuyer.com/weblog/siem-platform-secures-universitys-open-network/</link>
		<comments>http://www.simbuyer.com/weblog/siem-platform-secures-universitys-open-network/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 15:13:31 +0000</pubDate>
		<dc:creator>simbuyer</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://simbuyer.com/weblog/?p=163</guid>
		<description><![CDATA[&#8220;[Our SIEM implementation] allows us to be a lot more responsive in taking decisive action in remediating some of the problems we&#8217;re seeing. Ideally, we&#8217;d love to catch 100% of the problems and vulnerabilities that are out there, but that&#8217;s not going to happen, based on just sheer magnitude. But it&#8217;s putting us in a [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;[Our SIEM implementation] allows us to be a lot more responsive in taking decisive action in remediating some of the problems we&#8217;re seeing. Ideally, we&#8217;d love to catch 100% of the problems and vulnerabilities that are out there, but that&#8217;s not going to happen, based on just sheer magnitude. But it&#8217;s putting us in a position to be alerted when suspicious activities or footprints are noted on the network.&#8221;</p>
<p>Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.searchcommunications.imix.co.za/?q=node/88112">SIEM Platform Secures University&#8217;s Open Network</a></p>
<p>Source: Morris Reynolds, Director of Information Security and Access Management, Wayne State University</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=&amp;resourceid=Placeholder&amp;Itemid=">Security Information Management Quotes by Users</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/siem-platform-secures-universitys-open-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Information Management User Readiness and Adoption: Demanding More from Log Management Systems</title>
		<link>http://www.simbuyer.com/weblog/demanding-more-from-log-management-systems/</link>
		<comments>http://www.simbuyer.com/weblog/demanding-more-from-log-management-systems/#comments</comments>
		<pubDate>Mon, 11 Jan 2010 12:00:07 +0000</pubDate>
		<dc:creator>simbuyer</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://simbuyer.com/weblog/?p=179</guid>
		<description><![CDATA[An insightful survey which takes a data-intensive look into what enterprises are doing with log management. Questions include: - Why does log data matter? - Why are people collecting log data? - How are organizations using log data? - What are companies using for log management? - What are the pain points with log analysis? [...]]]></description>
			<content:encoded><![CDATA[<p>An insightful survey which takes a data-intensive look into what enterprises are doing with log management. Questions include:</p>
<p>- Why does log data matter?<br />
- Why are people collecting log data?<br />
- How are organizations using log data?<br />
- What are companies using for log management?<br />
- What are the pain points with log analysis?</p>
<p>Highly recommended.</p>
<p>Link to Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.sans.org/reading_room/analysts_program/LogMgt_June08.pdf">Demanding More from Log Management Systems</a></p>
<p>Source: Jerry Shenk, SANS</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=76&amp;resourceid=sim_impact_adoption&amp;Itemid=63">Security Information Management User Readiness and Adoption</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/demanding-more-from-log-management-systems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are SIEM and Log Management the Same Thing?</title>
		<link>http://www.simbuyer.com/weblog/are-siem-and-log-management-the-same-thing/</link>
		<comments>http://www.simbuyer.com/weblog/are-siem-and-log-management-the-same-thing/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 15:18:18 +0000</pubDate>
		<dc:creator>simbuyer</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://simbuyer.com/weblog/?p=161</guid>
		<description><![CDATA[&#8220;&#8230;we believe there is room for both traditional log management tools and the real-time analysis capabilities provided by SIEM tools, but we suspect that organizations would prefer to go to a single vendor for both. Clearly organizations have to solve the first problem (log management) in order to address the second (analysis and monitoring), but [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;&#8230;we believe there is room for both traditional log management tools and the real-time analysis capabilities provided by SIEM tools, but we suspect that organizations would prefer to go to a single vendor for both. Clearly organizations have to solve the first problem (log management) in order to address the second (analysis and monitoring), but the wise purchaser will know that after the first problem is addressed the second will become immediately apparent. Plan accordingly.&#8221;</p>
<p>Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.cio.com/article/419363/Are_SIEM_and_Log_Management_the_Same_Thing_">Are SIEM and Log Management the Same Thing?</a></p>
<p>Source: Greg Shipley, CIO Magazine</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=90&amp;resourceid=sim_quotes_media&amp;Itemid=67">Security Information Management Purchasing Best Practices</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/are-siem-and-log-management-the-same-thing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Information Event Management Security Development Life Cycle</title>
		<link>http://www.simbuyer.com/weblog/security-informationevent-management-security-development-life-cycle/</link>
		<comments>http://www.simbuyer.com/weblog/security-informationevent-management-security-development-life-cycle/#comments</comments>
		<pubDate>Mon, 28 Dec 2009 13:00:26 +0000</pubDate>
		<dc:creator>simbuyer</dc:creator>
				<category><![CDATA[simbuyer]]></category>

		<guid isPermaLink="false">http://simbuyer.com/weblog/?p=169</guid>
		<description><![CDATA[A comprehensive and usable Resource that presents a Security Development Life Cycle to guide users through pre- and post-deployment considerations for a SIEM installation. Highly recommended. Includes many best practices and specific guidance. Sections include: Project planning Systems analysis Systems design Implementation Integration and testing Acceptance and Deployment Maintenance Resource: Security Information/Event Management Security Development [...]]]></description>
			<content:encoded><![CDATA[<p>A comprehensive and usable Resource that presents a Security Development Life Cycle to guide users through pre- and post-deployment considerations for a SIEM installation. Highly recommended. Includes many best practices and specific guidance. Sections include:</p>
<ol>
<li>Project planning</li>
<li>Systems analysis</li>
<li>Systems design</li>
<li>Implementation</li>
<li>Integration and testing</li>
<li>Acceptance and Deployment</li>
<li>Maintenance</li>
</ol>
<p>Resource: <a href="http://www.simbuyer.com/redirect.php?url=http://www.sans.org/score/esa_current.pdf">Security Information/Event Management Security Development Life Cycle</a></p>
<p>Source: The SANS Institute</p>
<p>SIM Resource Guide Section: <a href="http://simbuyer.com/index.php?option=com_content&amp;view=article&amp;id=73&amp;resourceid=sim_impact_benefits&amp;Itemid=62">Security Information Management Best Practices</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.simbuyer.com/weblog/security-informationevent-management-security-development-life-cycle/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
