セキュリティー操作および情報リスク管理を改善するよう設計されたプラットフォーム
- 個別の組織、テクノロジー、およびプロセスを対象とするセキュリティー操作を集中化します
- セキュリティー操作を IT 運用およびビジネス上の優先順位に合わせて調整し、ビジネスおよびサービスのアップタイムを最大化します
- 準拠要件および企業のリスク管理ポリシーに対応します
- セキュリティーの問題の認識と解決にかかる時間を最小限に短縮します
IBM Tivoli® Security Operations Manager (TSOM) V4.1 の新機能
IBM Tivoli Security Operations Manager (TSOM) V4.1 は、次のような新機能および改善された機能を提供して、IT セキュリティーの問題に効率的に対処できるようにします。
- 単純化および簡素化された構成と管理 - 単純化および集中化されたデバイス・インターフェースと新しいイベント・ソース自動構成機能により、使いやすさが向上しており、デプロイメントおよび管理のための時間と労務が減ります
- 改善されたイベント・フィルタリングおよび相関エンジン・インフラストラクチャー。柔軟性、機能、およびパフォーマンスが高められます
- 拡張されたセキュリティー操作ダッシュボード・ユーザー・インターフェース。さらなるカスタマイズが可能で、新しいセキュリティー知識ベース機能を備えています
- 拡張された問題チケットおよびケース管理
- 問題の判別および解決のための拡張されたホスト調査ツール
- DB2®、AIX®、および完全なグローバリゼーションと国際化対応のサポートを含む、拡張および更新されたプラットフォーム・サポート
- Tivoli Compliance Insight Manager との統合。セキュリティー情報およびイベント管理 (SIEM) のための包括的なソリューションを提供します。
次の機能は、TSOM V4.1 では使用できなくなっています。
- Remedy Integration Module。チケットの BMC Remedy Help Desk System への片方向転送ができました。
- SourceFire API サポート
- Central Management Server (CMS) の高可用性機能
- 内部データベース・リポジトリーとしての MySQL サポート。付属の IBM DB2 Enterprise Edition に置き換えられています。
機密保護は、多くの企業や通信事業者の CIO にとって最も重要な関心事です。ネットワークおよびリソースの可用性は、ビジネスおよびサービスの保証にとって極めて重要であるためです。企業、政府機関、およびサービス・プロバイダーは、ワームやその他のタイプのマルウェアが企業のリソースおよび顧客対応サービスに侵入した結果として数百万ドルを失う可能性があります。
リソースおよびサービスの可用性を最大限に高め、顧客情報を保護するために、情報チームは以下を実行できる必要があります。
- セキュリティーの問題の迅速な認識および対処
- セキュリティー・ポリシーの適用
- 監査および準拠のイニシアチブのサポート
これらのすべてのアクションには、組織全体に置かれているセキュリティー・データが関与します。企業およびサービス・プロバイダーは、この個別のデータに迅速かつ効率的にアクセスしてそれらを分析する必要があります。今日の複雑なマルチベンダー環境では、そのために自動化および統合化されたソリューションが必要です。
IBM Tivoli Security Operations Manager (TSOM) は、お客様がセキュリティー操作の課題に対応する上で役立つセキュリティー情報およびイベント管理プラットフォームです。セキュリティー操作および情報リスク管理の有効性、効率、および可視性を改善するよう設計された TSOM は、テクノロジー・インフラストラクチャー全体のセキュリティー・データを一元管理して保管し、お客様が以下のことを行えるようにします。
- ログの集約、相関、および分析の自動化
- 問題の自動的な認識、調査、および対応
- 問題の追跡および処理の簡素化
- ポリシーのモニタリングおよび適用
- 準拠の取り組みに関するレポートの提供
製品について
ご購入 Tivoli Security Operations Manager
初年度の IBM ソフトウェア・サブスクリプション & サポートは製品価格に含まれています。
ご購入には諸手続きが必要になりますので、弊社窓口までお問い合わせください。
| Features | Advantages | Benefits |
|---|---|---|
| Automated log aggregation | Operational efficiency through platform integration | Centralize security operations across discrete organizations, technologies and processes |
| Automated event correlation and analysis | Efficiency through automation | Align security operations with IT operations to assure business uptime |
| Streamlined incident tracking and handling | Support for audit and compliance | Align security activities with the business' top priorities |
Business benefits
Network and resource availability is absolutely critical to business and service assurance. But enterprises, federal agencies and service providers can lose millions of dollars per year as a result of worms and other types of malware that bring down corporate resources and customer-facing services. That's why information security is one of the top concerns of every CIO in any enterprise or carrier.
To maximize resource and service availability and protect customer information, today's information security teams must be able to:
Quickly recognize and handle security incidents.
Enforce security policies.
Support audit and compliance initiatives.
The challenge is that each of these activities involves security data that resides throughout the organization. Enterprises and service providers need to be able to access and quickly analyze this disparate data - quickly and efficiently. In today's complex, multi-vendor environments, that means leveraging an automated, integrated solution.
Tivoli Security Operations Manager
In response to these challenges, turn to Tivoli® Security Operations Manager (TSOM) - a security information and event management (SIEM) platform designed to improve the effectiveness, efficiency and visibility of security operations and information risk management. By centralizing and storing security data from throughout the technology infrastructure, Tivoli Security Operations Manager enables you to:
Automate log aggregation, correlation and analysis
Recognize, investigate and respond to incidents automatically
Streamline incident tracking and handling
Enable monitoring and enforcement of policy
Provide comprehensive reporting for compliance efforts
Tivoli's Security Operations Manager automates many repetitive, time-intensive activities required for effective security operations. The result is an efficient, cost-effective approach to security operations.
Improve efficiency through operational integration
TSOM addresses operational inefficiencies experienced by siloed IT organizations by facilitating the flow of incident management data between security, network and systems management operations teams. For example, TSOM integrates closely with enterprise network and system management products - including Netcool® event managers and dashboards, as well as Tivoli Enterprise Console® - and IT help-desk ticketing systems. You can leverage these integrations to:
Ensure business and service assurance.
Correlate security insights with information from the broader operations environment.
Further facilitate incident remediation.
TSOM also integrates with Tivoli Identity Manager and Tivoli Access Manager to provide monitoring and oversight for customer's identity and access policies, ensuring that policies are enforced, and that potential misuse attempts are quickly detected and addressed.
Deepen understanding by using comprehensive reporting
The on-the-fly data mining, historical reporting, self-auditing and tracking capabilities in Tivoli Security Operations Manager provide critical components for understanding security trends. What's more, these reports help IT communicate relevant security information to other audiences, such as management and audit.
Features include:
Standard and customizable report templates.
An automated report scheduler.
HTML, PDF and XML exporting of all graphs and charts.
Self-auditing and tracking of all security activities.
Tivoli Security Operations Manager draws on information stored in a security event database to deliver historical reporting and trending on demand.
Select from multiple deployment options to suit your environment
Tivoli Security Operations Manager features a modular architecture that can adapt to - and grow with - your organization's security infrastructure. Each of the components - the event aggregation module that collects and normalizes data, the central management server that performs advanced analysis and correlation, and the database that stores historical information - can be distributed on separate hardware, or the components can be deployed together.
An organization might deploy multiple event aggregation modules throughout the organization to support higher volumes of event information or facilitate geographic distribution of system resources. For example, one customer uses 12 event aggregation modules for its geographically dispersed locations - enabling the company to distribute data collection and processing.
Similarly, the event aggregation modules can all send data to a single central management server, or an organization can use multiple servers to maximize availability - if one server is unavailable to an event aggregation module, it will instead forward the event to a secondary central management server.
Provide a platform for offering managed security services
In addition to serving as the critical IT security platform for midsize and large enterprises and carriers, Tivoli Security Operations Manager can also act as a strong, proven foundation for a highly profitable managed security services business. The same deployment options that make the software scalable and stable for any organization also enable Tivoli Security Operations Manager to meet the needs of a highly distributed services environment.
When used by managed security service providers, Tivoli Security Operations Manager helps:
Reduce operational costs by offering a high degree of operational automation.
Optimize time to value, thanks to speedy implementation and immediate, out-of-the-box capabilities.
Demonstrate service levels and value to customers through comprehensive reporting capabilities.
Security breaches can have serious, measurable consequences: lost revenue, downtime, damage to reputation, damage to IT assets, theft of proprietary or customer information, cleanup and restoration costs, and potential litigation costs. To reduce these risks, security organizations need the capability to quickly identify and react to attacks.
Tivoli Security Operations Manager provides a holistic view of your security posture and the abilities to drill down and investigate attacks quickly. As a result, it is a valuable tool to help prevent intrusions and help maximize the security of your business.
-
セキュリティー・インテリジェンスおよびコンプライアンス分析
- Tivoli Security Information and Event Manager
- Tivoli Security Operations Manager