The Economic Condition

After the down slide of US economy, there is lull now. Even the noted economist are not sure which way it will turn. Even in the uncertain economic times, the IT security cannot be compromised. It is a good sign that the companies are considering the IT/data security far too important. 

Gartner Survey Results

This is evidently clear from the results of the recent Gartner survey on budget allocation towards security software and services. Definitely there will be  an increase. It is around 4%. Even though there is an increase in budget, the increase is limited. But during the tough times, you do not have the luxury of big budget. The limited budget, the companies can set aside, need to be spent on the security software judiciously. This was reflected by the Gartner analysts in their report.

More Quality and Less Cost

SIEM is a major area, which is a proactive way of ensuring security. The companies have realized the benefit of being proactive when it comes to IT/data security. Hence, the results show the increase in budget (even though it is marginal) for security software. The emphasis is on limited increase in budget during these turbulent economic times. This means that the IT managers with budgetary powers, should look for the products/suites which offer real value for money. As such small and medium businesses are prudent in their security spending. Now it is time large enterprises to toe the SMB line and scout for enterprise grade, cost effective security solutions. They are not afford to spend their fortune to chase the reputed brand names for ensuring security.

ManageEngine Philosophy

ManageEngine, since inception believed in the philosophy of high quality and low cost (whether it is rain or shine in economy). IT Managers in your search for cost effective enterprise SIEM solutions, take note of ManageEngine suite. Yes, ManageEngine now offers enterprise grade (Distributed Edition) SIEM solutions. EventLog Analyzer, is an  event log management & regulatory compliance solution and Firewall Analyzer is a security event management & bandwidth monitoring solution. Take an informed decision during tough economic situations. Choose the right SIEM enterprise solutions complete in features and right in price.

Have a look at EventLog Analyzer Enterrpise Solution (Distributed Edition).

   

When it is a matter of network security, be pro-active. Do not wait for compliance regulation or statutory government legislation.

But, once a regulatory body of your domain formulates compliance acts, you should ensure that your network is secured and compliant with the regulatory act. This will also instill confidence in your customers that you are following standard practices to keep your network secured.

At the next level, if a national government promulgates a law to counter the computer related offenses and if you operate in that country, you have to abide by the act. Failing which you will attract penal action and punishment.

One such example is 'Computer Crime Act B.E 2550 (2007)' of Thailand government.

Enterprises with computer networks and service providers should scout for a Security Information Management (SIM) solution which fulfills the requirements of the government act.

The SIM solution application should be,

  • easy to use
  • should be able to install on any platform 
  • access the application from anywhere (should we say web-based)
  • should require minimum manual intervention to operate
  • collect the security information (logs) from a central location
  • agent should not be required 
  • should collect information from heterogeneous devices
  • analyse, normalise, and aggregate the log information
  • provide multi-format, canned, customisable, scheduled, and distributable reports
  • generate alerts for anomalous and specific log information
  • notify the alerts by Email or other means
  • flexible archiving of log information to suit the requirements of government act
  • importing the log information from archive or any other system which is not monitored by the application
  • analysing and generating reports for imported log information
  • exhaustive search feature to cater for forensic analysis requirements of government act
  • above all, it should not pinch your pocket

Wonder whether some such SIM solution is available? Give ManageEngine EventLog Analyzer a try.

Have some fun with the toonz

Sep 23 2008 11:07:29 PM Posted By : Ragavan S
Comments (0)

Want to know more about Privileged User Threat? Refer EventLog Analyzer.

Yes!

AdventNet ManageEngine is hosting Roadshows in countries across the European Union.

If security of your enterprise IT infrastructure is your concern, then you must visit ME Euro Roadshow 2008.

We are available in your town. Feel free to seek any information about EventLog Analyzer.  Join us at the Roadshow in your country, register here 

Check complete details about the Roadshow, visit the link: http://manageengine.adventnet.com/euroroadshow/

Insight into Internal Security Threat

Jun 23 2008 06:04:21 AM Posted By : Ragavan S
Comments (0)

Do you need to worry? May be. 

Startling revelations make you to sit up and take note. Yes, the issue is about the insider security threat to your enterprise network. You have to trust your staff, as they are part and parcel of you enterprise. After all they are the one who is running the show. The issue is very delicate to tread. A recent article published in Times of India news paper, the results a IT security survey, reveals that 33% of IT people snoop in the sensitive enterprise data and approximately 50 % of the people accessed information not releavant to their roles. Abused confidential data ranges from board meeting minutes to salary details of colleagues. The privileged users or any user who can get the privileged user credentials have the chance of snooping your enterprise data. Lack of pro-active security policy or its non-implementation like, not changing the administrative passwords at regular intervals makes thing worse. It leads to information access even by your ex-employess.   

Is it a wake up call? Yes.

Hence, it is time for you to take a fresh look at the internal security. Be pro-actively secured. Devise strong security policy and ensure it is fully implemented. Analyze the risk and mitigate it. You should also ensure that there is a mechanism in place to monitor the activities of the privileged users. The monitoring should not obstruct day to day activity, should not be obviously intrusive, and above all it should be in real-time. With this monitoring you will be able to assess the threat posed by various snooping activities. Then, you can employ appropriate means to mitigate the risk. You can formulate stricter security policies, restrict administrative user prvilileges to specific people, etc.  

What is the way out? EventLog Analyzer.

ManageEngine EventLog Analyzer offers a comprehensive solution for privileged user monitoring.

EventLog Analyzer application carries out real-time monitoring of the user access to various enterprise resources. On occurence of an event specified by you, an alert will be triggered and will notify by Email or other means. It provides extensive reports and trends on user activities. There is much more, Compliance Reports, Archiving and Searching logs for forensic analysis and trouble shooting, etc.

Try EventLog Analyzer today. Download from here.

The ManageEngine Booth at the Interop Las Vegas 2008 was abuzz with activity.

You can see one of the esteemed EventLog Analyzer customer visiting the booth. They were happy with the product and the level of support (definitely AdventNet forte) offered.

EventLog Analyzer customer Interop Las Vegas 2008 booth

Our contact person VJ Karthik flanked by EventLog Analyzer customers.

AdventNet ManageEngine EventLog Analyzer

Are you going to be there at the Interop Las Vegas 2008? EventLog Analyzer 5 will be show cased at booth number 2319. Feel free to drop in. For details about the product, contact Mr Karthik VJ. He will be there to help you.

compliance! Compliance! COMPLIANCE!

Mar 18 2008 04:08:24 AM Posted By : Ragavan S
Comments (2)

In the era of increased data security threat from both outside and inside of your enterprise, you need to be proactive in your approach.  On the government’s side, it wants to ensure the enterprise IT operations are regulated for the sake of data security of the citizens. In order to achieve this, government or the competent statutory authority issue regulations for the enterprises IT operations to be complied with. By complying the regulation, not only you are fulfilling the statutory requirements, you are also fortifying your enterprises security to the level acceptable to the external world.

Growing List of Compliance Regulations

One important point of concern is the growing number of Compliance Regulations issued by various statutory authorities. Already there are Sarbanes-Oxley Act (SOX), Payment Card Industry (PCI), Health Insurance Portability and Accountability Act (HIPAA),  Gramm-Leach-Bliley Act (GLBA). Further more there are California Senate Bill No. 1386, Federal Information Security Management Act (FISMA), and SCADA security best practices. Each regulatory compliance will be outlining its own separate set of reports which needs to be presented to the IT auditors. So how the small and medium enterprises with their limited IT budget will cope up with growing demand of regulatory compliance.

How to address the ensuing scenario

An ideal solution would be to generate customized set of reports for each compliance to be available as pre-built package.  But customizing the set of reports will be time consuming and will be involving software developers with development time changes in the software application. This may not be desirable as every time a new regulation is introduced you have to carry out the exercise to comply with.  What you can look out for is an application which allows you the flexibility of customization of the available set of reports to make ready for the new compliance. Further, you choose to fine tune or prune the set of reports meant for the existing regulatory compliance.  Further more, you may feel that it will be nice to have the reports generated periodically without your intervention manually.

A solution in sight

AdventNet ManageEngine with its fore thought addresses your above stated problems. The EventLog Anayzer 5 allows you create a set of reports for a new compliance.  This value added feature removes your burden of customizing the application every time you require reports for a new regulatory compliance. It takes no time and can be created by the System Administrator. Another feature of EventLog Anayzer 5 is to allow customization of the set of reports for the existing compliance report. This is another value addition that ensure that you submit only required reports and remove reports which are not required or add a new one which is required. You dodnot have to panic for minor changes in the regulations. What more, EventLog Anayzer 5 allows you to schdule the compliance report generation automatically at periodic interval. You can sit back and relax. The EventLog Anayzer 5 comes packed with a lot more features. Get the details here.

Want to see it to belive it, try EventLog Anayzer 5. You can download it from here. The full functionality download is available free for thirty days trial.