Centralizované riešenie na riadenie bezpečnosti a zabezpečenie súladu s nariadeniami, ktoré poskytuje informácie o stave zabezpečenia podniku
IBM Tivoli Security Information and Event Manager V1.0 pomáha organizáciám zaoberajúcim sa bezpečnosťou IT získavať cenné informácie o bezpečnosti, podľa ktorých môže vaša organizácia konať, prostredníctvom:
- Uľahčenia dosahovania súladu s nariadeniami s použitím centralizovaného ovládacieho panelu a funkcií nahlasovania.
- Podpory ochrany duševného vlastníctva a súkromia auditovaním správania všetkých užívateľov - privilegovaných aj neprivilegovaných.
- Efektívneho a účinného riadenia bezpečnostných operácií pomocou centralizovanej korelácie, hierarchizácie, skúmania a odozvy na bezpečnostné udalosti.
IBM Tivoli Security Information and Event Manager V1.0 ponúka:
- Integráciu a výmenu udalostí medzi korelačnými mechanizmami IBM Tivoli Security Operations Manager a IBM Tivoli Compliance Insight Manager.
- Nové možnosti cenotvorby pre bezpečnostné udalosti a pre kolekciu auditových protokolov.
Riadenie bezpečnostných informácií a udalostí (SIEM) je primárnym záujmom CIO a CSO v mnohých podnikoch a organizáciách. Existuje potreba centralizovať udalosti súvisiace s bezpečnosťou a analyzovať konsolidované údaje pre získanie dôležitých informácií o zabezpečení a súlade s nariadeniami.
IBM ponúka dve doplnkové perspektívy pre SIEM:
- Ovládací panel na riadenie sieťových udalostí v reálnom čase, ktorý uľahčuje rozpoznávanie útokov a riadenie bezpečnostných udalostí.
- Ovládací panel na analýzu informácií, umožňujúci monitorovanie miery dodržiavania bezpečnostných a kontrolných politík organizácie.
IBM TivoliSecurity Information and Event Manager V1.0 sa skladá z dvoch produktov, ktoré úzko spolupracujú, aby poskytli všetky výhody podnikového SIEM: IBM Tivoli Security Operations Manager V4.1 a IBM Tivoli Compliance Insight Manager V8.5. Teraz môžete centralizovať zhromažďovanie protokolov a koreláciu udalostí v celom podniku a môžete využívať výhody rozšíreného ovládacieho panelu pre súlad s nariadeniami a správ vyhovujúcich nariadeniam na prepojenie udalostí bezpečnosti a správania užívateľov s podnikovými politikami.
Tivoli Security Information and Event Manager V1.0 poskytuje základ, z ktorého môžete určovať vaše požiadavky na SIEM - teraz aj v budúcnosti. Následkom toho môžu IT organizácie znížiť mieru vystavovania sa narušeniam bezpečnosti, riadiť náklady na zhromažďovanie, analýzu a nahlasovanie udalostí, súvisiacich so súladom s nariadeniami, a riadiť zložité heterogénne technológie a infraštruktúry. IBM Tivoli Security Information and Event Manager ponúka komplexné schopnosti, vrátane:
- Ovládacieho panelu súladu s bezpečnostnými nariadeniami.
- Ovládacieho panelu bezpečnostných operácií na riadenie bezpečnostných udalostí.
- Agregácie, korelácie a analýzy protokolov bezpečnostných udalostí v reálnom čase.
- Integrácie IT operácií.
- Automatického rozpoznávania, skúmania a odozvy na bezpečnostné udalosti.
- Racionalizácie sledovania, spracovania a rozlišovania udalostí.
- Auditovej analýzy mainframov, operačných systémov, aplikácií a databáz.
- Monitorovania a auditovania privilegovaných užívateľov (PUMA).
- Nahlasovania riadenia protokolov.
Zistite viac
Nakúpiť Tivoli Security Information and Event Manager
Obnovenie softvérových licencií a podpora na prvý rok sú zahrnuté v cene produktu.
Stiahnite si online softvér po nákupe - bez nákladov na zásielku
Nieje k dispozícii na kúpu online. Pre iné spôsoby nákupu alebo viac informácií kontaktujte IBM.
Kontaktujte IBM
- Vyžiadajte si ponuku
- Pošlite nám e-mail
- alebo nám zavolajte na: 0800 100 112
Priorita kód: 100KU05W
| Features | Advantages | Benefits |
|---|---|---|
| Automated log aggregation | Operational efficiency through platform integration | Centralize security operations across discrete organizations, technologies and processes |
| Automated log management and analysis with an intuitive log management dashboard | Generate numerous reports directly from the log data, as well as a log continuity report, which allows you to demonstrate to auditors and regulators the completeness and continuity of your log management program. | Reduce costs involved in managing and demonstrating compliance |
| Web based management console with support for thousands of event sources per server | Single integrated SIEM platform and seamless management of multiple servers from one desktop | Reduce complexity associated with management and configuration |
| Streamlined incident tracking and handling | Support for audit and compliance | Align security activities with the business' top priorities |
| Automated audit reporting through a compliance dashboard and flexible report distribution. | Centralizes the compliance monitoring process from the collection point on, providing concise and understandable information through the dashboard and reporting. | Gain an understanding of your compliance posture to help ease the demands of preparing and responding to the increasing numbers of security audits and helping to improve your security stature. |
| 64 bit platform support | Provides better scalability | Reduce your total cost of ownership |
| Privileged user monitoring and audit (PUMA) on databases, applications, servers and mainframes and alert in near real time with insider threat analytics. | Unobtrusively monitors and reports on privileged user activities, allowing your administrators to perform their jobs and supporting strong controls over user access. | Provides a cost-effective, automated way to monitor, report and investigate privileged user behaviors to both protect key corporate applications and information assets and provide assurance to auditors and management that effective controls are in place. |
| Translates captured native log data into easily understood language. | Patent-pending W7 methodology translates all events into a single language that states Who, did What, When, Where, Where from, Where to and on What, understandable by security personnel, auditors and management. | Reduces reliance on over-burdened and costly platform-subject matter experts by delivering easily understood reporting to support auditors’ evidence requests and security managers’ investigatory needs. |
| Integration with IBM Tivoli Identity Manager, Tivoli Access Manager, and Tivoli Security Operations Manager. | Integration with IBM’s identity management solutions simplifies efforts to implement identity auditing as part a strong controls environment, and automates the comparison of user to security policies and best practice frameworks. Integration with Tivoli Security Operations Manager automates the process of notifying security operations personnel about policy violations that can threaten security or compliance measures. | Reduce the risks of access to sensitive systems and non-compliance with security policies and requirements. Improve incident response and policy compliance by allowing security personnel to investigate exceptions and take immediate action. |
| Advanced report definition engine allow | New custom reporting tool provides offers easy-to-use interface for creating | Helps you to quickly and easily meet your organization’s |
| users to create custom compliance modules and reports. | custom reports, including summary and detail reports, Top-N and threshold reporting. Reports can use filtering selection criteria and be presented in text or chart form. | specific reporting requirements, new compliance initiatives and ad-hoc report requests through an intuitive user interface. |
| Efficiently collect, store, investigate and retrieve logs through automated log management capability. | A scalable log collector helps ensure the reliable and verifiable collection of native logs from virtually any platform, including syslog and Simple Network Management Protocol (SNMP) logs, and almost any security log type, including operating systems, databases and security devices. | Automating and centralizing the collection of logs files can help make the process more efficient, saving time and money. |
| Enhance RACF auditing capabilities | Leverage the optional mainframe plugins with enhanced capabilities for RACF auditing and analyze and report on mainframe events | reducing the cost and skill needed to maintain a secure environment for your business-critical asset |
Business benefits
Tivoli Security Information and Event Manager provides visibility into your security posture, controls the cost of demonstrating compliance; and reduces the complexity of managing a heterogeneous IT infrastructure.
Product requirements
HARDWARE REQUIREMENTS:
The Enterprise Server, Standard Server, and Log Management Server have the following processor and RAM requirements:
Minimum Enterprise Server requirements
Quad Core Intel Xeon 3.0 GHz processor (64-bit)
8 GB RAM (+ 0.5 GB for each Reporting Database)
Temp directory: 600 MB (during installation)
A minimum of 200 GB of free hard disk space is required. Specific requirements depend on log volumes and types of log data. For information about determining the required disk space, see Determining disk space requirements. The disks that store the log management depot and indexes must be fast (at least 10,000 RPM) and configured in a striped configuration (for example, RAID 5).
Minimum Standard Server requirements
Duo Core Intel Xeon 3.0 GHz processor (64-bit)
8 GB RAM (+ 0.5 GB for Each Reporting Database)
Temp directory: 600 MB (during installation)
A minimum of 200 GB of free hard disk space is required. Specific requirements depend on log volumes and types of log data. For information about determining the required disk space, see Determining disk space requirements. The disks that store the log management depot and the database instances must be fast (at least 10,000 RPM) and configured in a striped configuration (for example, RAID 5).
Minimum Log Management Server requirements
Quad Core Intel Xeon 3.0 GHz processor (64-bit)
8 GB RAM
Temp directory: 600 MB (during installation)
Minimum hard disk space
A minimum of 200 GB of free hard disk space is required. Specific requirements depend on log volumes and types of log data. For information about determining the required disk space, see Determining disk space requirements. The disks that store the log management depot and indexes must be fast (at least 10,000 RPM) and configured in a striped configuration (for example, RAID 5).
SOFTWARE REQUIREMENTS:
The Enterprise Server, Standard Server, and Log Management Server all require the following software:
One of the following operating systems:
- Microsoft Windows 2003 Server SP1 (or higher) for 64-bit
- Microsoft Windows 2008 Server for 64-bit
- Microsoft Windows 2008 Server SP1 for 64-bit
- Microsoft Windows 2008 Server R2 for 64-bit
- In addition:
- NetBIOS enabled
- Internet Protocol network connection configured to all other systems hosting Tivoli Security Information and Event Manager components
- NTFS file systemTo use a screen reader during installation, a JVM (version 1.5 or higher) and the Java Access Bridge must be installed on the computer on which you are installing Tivoli Security Information and Event Manager. See Using screen readers with the Tivoli Security Information and Event Manager installation and uninstallation programs.
For SSH collect to work, PuTTY must be installed on the Windows agent, Windows Tivoli Security Information and Event Manager Servers, and Windows Log Management Servers involved in the collect operations. If PuTTY is not installed, SSH collections from AIX®, HP-UX, Linux, and Solaris systems do not work. This installation is not performed by the Tivoli Security Information and Event Manager installation program and must be performed separately. PuTTY is provided with Tivoli Security Information and Event Manager. You can find PuTTY on the IBM® Tivoli Security Information and Event Manager v2.0 for Windows DVD in the \utils\putty folder. See the IBM Tivoli Security Information and Event Manager Event Source Guide for information about installing PuTTY.
Tivoli Security Information and Event Manager runs on RedHat Linux too
-
Ochrana infraštruktúry
- IBM Endpoint Manager for Mobile Devices
- IBM Security Network Active Bypass
- IBM Security Network Controller
- IBM Security Network Intrusion Prevention System for Crossbeam
- IBM Security Network Intrusion Prevention System
- IBM Security Network Intrusion Prevention System Virtual Appliance
- IBM Security zSecure Admin
- IBM Security zSecure Alert for ACF2
- IBM Security zSecure Alert for RACF
- IBM Security zSecure Alert
- IBM Security zSecure Audit for ACF2
- IBM Security zSecure Audit for RACF
- IBM Security zSecure Audit for Top Secret
- IBM Security zSecure Audit
- IBM Security zSecure CICS Toolkit
- IBM Security zSecure Command Verifier
- IBM Security zSecure Suite
- IBM Security zSecure Visual
- Tivoli Endpoint Manager for Core Protection
- Tivoli Endpoint Manager for Patch Management
- Tivoli Endpoint Manager for Security and Compliance
- Tivoli Security Information and Event Manager
- Tivoli Security Management for z/OS
- Tivoli zSecure Manager for RACF z/VM
Jednoduchý spôsob ako nakúpiť alebo zistiť viac.
Sme tu, aby sme vám pomohli
Jednoduchý spôsob ako nakúpiť alebo zistiť viac.
- Vyžiadajte si ponuku
- Pošlite nám e-mail
- alebo nám zavolajte na: 0800 100 112
Priorita kód: 100KU05W