<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>Security Information Management Resource Guide</title>
	<link>http://www.simbuyer.com/weblog</link>
	<description>New Resource Weblog</description>
	<lastBuildDate>Fri, 04 Jun 2010 18:14:24 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0" -->

	<item>
		<title>Security Information Management Purchasing Best Practices: Security Information Management: Not Just the Next Big Thing</title>
		<description><![CDATA[&#8220;When shopping for SIM vendors: 1) Learn about the organization, not just the product and its price tag (though SIM products do have a large price variance). 2) Read the customer testimonials to understand what kind of problems customers were able to solve. 3) Make sure the critical assets, such as servers and firewalls, can [...]]]></description>
		<link>http://www.simbuyer.com/weblog/security-information-management-purchasing-best-practices-security-information-management-not-just-the-next-big-thing/</link>
			</item>
	<item>
		<title>Security Information Management Best Practices: SIM Lessons Learned Along the Way</title>
		<description><![CDATA[Top 5 SIM Mistakes and Misconceptions: 1) Expecting installation of Security Information Management (SIM) software to solve a problem. 2) No definition of the problem to solve with SIM implementation. 3) Failure to define usage (use cases) before work begins. 4) Failure to understand the data available.] 5) Failure to make SIM relevant to business. [...]]]></description>
		<link>http://www.simbuyer.com/weblog/security-information-management-best-practices-lessons-learned-along-the-way/</link>
			</item>
	<item>
		<title>Security Information Management Best Practices: Perfect SIEM Preparation: The Crib Sheet</title>
		<description><![CDATA[&#8220;1) Establish a cross-department steering committee first, to ensure all parties are onside. 2) Build a security baseline: assess activities &#38; risks, prioritise them, and how you&#8217;ll remediate. 3) Simplify the network before installing large management systems to shorten implementation time, reduce event numbers and raise input quality for SIEM. 4) Boost signal to noise [...]]]></description>
		<link>http://www.simbuyer.com/weblog/security-information-management-best-practices-perfect-siem-preparation-the-crib-sheet/</link>
			</item>
	<item>
		<title>Cyber Command and Control-Cyber War Foglifter</title>
		<description><![CDATA[Deloitte presents an impressive &#8220;Cyber War Foglifter&#8221; diagram detailing the components of modern IT security threats and defenses. SIEM is shown as a key part of the IT security process (see step six in the diagram). Link to Resource: Cyber Command and Control &#8211; Cyber War Foglifter Source: Deloitte SIM Resource Guide Section: Security Information [...]]]></description>
		<link>http://www.simbuyer.com/weblog/cyber-command-and-control-cyber-war-foglifter/</link>
			</item>
	<item>
		<title>Enterprise Security Tactical Plan &#8211; State of Minnesota</title>
		<description><![CDATA[A insightful, real-life document that describes the State of Minnesota&#8217;s two-year enterprise security tactical plan. The document prioritizes the tactical initiatives for the management, control, and protection of information assets and highlights SIEM as a key component of the plan, which has the following strategic principles: - Improved situational awareness, which includes continuous system monitoring [...]]]></description>
		<link>http://www.simbuyer.com/weblog/enterprise-security-tactical-plan-state-of-minnesota/</link>
			</item>
	<item>
		<title>The Gartner 2010 CyberThreat Landscape</title>
		<description><![CDATA[A strategic and data-rich look at the current CyberThreat landscape. This original report is filled with examples, data, graphics and guidance and covers: - Review of new and expected IT security threats - Cyber threat taxonomy - CIO strategies - Cybercrime as a service &#8211; definitions, examples, and data - Global attack sources - Critical [...]]]></description>
		<link>http://www.simbuyer.com/weblog/the-gartner-2010-cyberthreat-landscape/</link>
			</item>
	<item>
		<title>SIEM Platform Secures University&#039;s Open Network</title>
		<description><![CDATA[&#8220;[Our SIEM implementation] allows us to be a lot more responsive in taking decisive action in remediating some of the problems we&#8217;re seeing. Ideally, we&#8217;d love to catch 100% of the problems and vulnerabilities that are out there, but that&#8217;s not going to happen, based on just sheer magnitude. But it&#8217;s putting us in a [...]]]></description>
		<link>http://www.simbuyer.com/weblog/siem-platform-secures-universitys-open-network/</link>
			</item>
	<item>
		<title>Security Information Management User Readiness and Adoption: Demanding More from Log Management Systems</title>
		<description><![CDATA[An insightful survey which takes a data-intensive look into what enterprises are doing with log management. Questions include: - Why does log data matter? - Why are people collecting log data? - How are organizations using log data? - What are companies using for log management? - What are the pain points with log analysis? [...]]]></description>
		<link>http://www.simbuyer.com/weblog/demanding-more-from-log-management-systems/</link>
			</item>
	<item>
		<title>Are SIEM and Log Management the Same Thing?</title>
		<description><![CDATA[&#8220;&#8230;we believe there is room for both traditional log management tools and the real-time analysis capabilities provided by SIEM tools, but we suspect that organizations would prefer to go to a single vendor for both. Clearly organizations have to solve the first problem (log management) in order to address the second (analysis and monitoring), but [...]]]></description>
		<link>http://www.simbuyer.com/weblog/are-siem-and-log-management-the-same-thing/</link>
			</item>
	<item>
		<title>Security Information Event Management Security Development Life Cycle</title>
		<description><![CDATA[A comprehensive and usable Resource that presents a Security Development Life Cycle to guide users through pre- and post-deployment considerations for a SIEM installation. Highly recommended. Includes many best practices and specific guidance. Sections include: Project planning Systems analysis Systems design Implementation Integration and testing Acceptance and Deployment Maintenance Resource: Security Information/Event Management Security Development [...]]]></description>
		<link>http://www.simbuyer.com/weblog/security-informationevent-management-security-development-life-cycle/</link>
			</item>
</channel>
</rss>
