-
Security Information and Event Management (SIEM):
- An approach to security management that combines SIM (Security Information Management) and SEM (Security Event Management) functions into a single product.
- Note: The acronym SIEM is pronounced "sim" with a silent e.
-
Capabilities of a SIEM solution include:
-
Data Aggregation:
- Combining data from network devices, servers and applications
-
Correlation Engines:
- Automatically look for common attributes of events across the various monitored platforms
- Compliance with government regulatory auditing processes
- Forensic Analysis
-
Automatic De-Duplication:
- The elimination of redundant data
-
Configuration Compliance Manager:
- Scanning for configuration compliance
-
Write-Once, Read Many (WORM):
- Log information, once written, cannot be changed.