Today's Information Security Landscape

The information security landscape has changeddata critical to financial operations, customers, and
dramatically in recent years. While the network hackeremployees. Achieving regulatory compliance is a
continues to pose a threat, regulatory compliance hascomplex challenge for organizations, with massive
shifted the focus to internal threats. As noted byamounts of data and complex applications to monitor,
Charles Kolodgy, analyst at IDC, "Compliance shiftedand increasing numbers of users with access to those
security management from monitoring externalapplications and data. Organizations need accessibility
network activity to managing internal user activity atto contextual information and to understand real-time
the application and database level." Whethernetwork changes, such as adding assets, and the new
contending with the Sarbanes-Oxley Act (SOX), thevulnerabilities and threats that creates. Business
Health Insurance Portability and Accountability ActServices Continuity Continuity of the security
(HIPAA), the Gramm-Leach-Bliley Act (GLBA), themanagement program across an organization is key
Federal Information Security Management Actto risk management and compliance success.
(FISMA), or other compliance challenges, companiesOrganizations should be able to predict where most
must prove diligence in managing information securitythreats might occur, and how they might impact the
risk. Maintaining the integrity of security information isbusiness. Data is constantly in motion, continually
increasingly complex, consuming valuable resources.consumed by users and applications across the
Service-oriented architectures are increasing the paceenterprise. Increased deployment of service-oriented
of application development. Networks are comprisedapplications increases the number of users with
of more applications and data with greater distribution,potential access to enterprise data. Service-oriented
creating more access points to critical data. Thoughapplications have many moving parts, and monitoring at
visibility into real-time threats and vulnerabilities is calledthe application layer is much more difficult than
for, most organizations lack the tools needed tomonitoring network activity.
transform information security data into actionableThreat and Risk Management As businesses and
security intelligence. Security Information Managementnetworks grow, organizations shift their security focus
Challenges Developing and implementing an effectivefrom trying to address all security issues to establishing
security information management system has manysecurity priorities. The larger, more complex
challenges. With the recent explosion of informationorganizations choose to focus on the most damaging
privacy and security legislation, executives and ITthreats, those with the greatest financial impact, and
groups are more accountable for securitythose security issues that can cause the most
requirements and compliance auditing. Closerdisruption to business processes. Previously, the focus
examination of company security postures is exposingfor security organizations has been on stopping threats
potential vulnerabilities previously unimportant or evenfrom outside the enterprise. Yet data leakage and
unrecognized, including:inappropriate user activity from inside the enterprise
- Disconnect Between Security Programs andare often bigger threats, since the potential hacker is
Business Processes - Information security programsso much closer to the data. Organizations today are
are often inadequately integrated into businessforced to reconsider their approach to managing risk
processes, creating disconnect and processfrom insiders. Security Performance Measurement
inefficiencies.Given that organizations cannot manage what they
- Fragmented Security Information, Processes, andcannot measure, the need for security information
Operations - Information security often takes place in aevent management and benchmarking are key
decentralized manner. Separate databases andaspects of an effective security decision support
unrelated processes might be used for auditsolution. Organizations need to understand their
assessments, intrusion detection efforts, and antivirussecurity posture at any point in time, and then have the
technology.ability to use that as a security baseline to measure
- Security Performance Measurement Difficulties -against. Also, executive management needs a fast,
Many organizations struggle with performancestraightforward, and credible way to have visibility into
measurement and management, and developing athe organization's security posture.
standardized approach to information securityUnified Network and Security Management Too often,
accountability can be a daunting task.identifying, managing and eliminating threats across the
- Broken or Nonexistent Remediation Processes -enterprise is a fragmented and ineffective process for
Previously, compliance and regulatory requirementsbusinesses and can lead to damaging outcomes.
called for organizations to simply log and archiveTaking a trial-and-error approach can result in network
security-related information. Now, auditors requestand application outages, lost data, lost revenue,
in-depth process documentation. Both threatpotential compliance violations, and frustrated users. To
identification and remediation are becoming moremeet compliance needs and maintain business
important.services continuity, organizations need a coordinated
- Abnormal User Activity and Data Leakageresponse across a unified infrastructure. Paul Stamp,
Identification - With today's security requirements,Senior Analyst for Forrester Research, states, "When
organizations need to quickly and efficiently addsecurity incidents like a worm outbreak or a system
processes to facilitate incident identification andcompromise occur, information risk management
detection of anomalous behavior.needs to coordinate the response, providing timely
Security Decision Support Solutions Today, achievingadvice regarding the appropriate response actions.
information security compliance and managing riskMoreover, they need to make sure that the different
requires a new level of security awareness andteams involved in IT security that need to plug the
decision support. Organizations can use both internalsecurity holes communicate effectively and get the job
security expertise and external consultants, todone as efficiently as possible." Security Information
implement security information. Integration of networkManagement: The Backbone of Security Decision
operations centers with security operations centersSupport
aids timely identification and remediation ofSecurity decision support can provide a flexible yet
security-related issues. For successful security decisioncomprehensive solution for addressing risk
support, organizations must automate incidentmanagement and compliance challenges. An
response processes. These automated processes,enterprise-class SIM platform can translate raw data
however, must remain flexible and scalable. Riskinto actionable security intelligence that can facilitate
management and compliance are dynamic, withdecisions regarding appropriate mitigation and
ongoing modifications, regular and complex securityremediation. Security metrics enable management to
incidents, and continuous efforts for improvement. Atake decisive action. SIM also accelerates incident
successful comprehensive security decision supportresponse with a consistent work flow. SIM technology
solution involves several critical elements: compliance,enables collection and interpretation of security
business services continuity, threat and riskinformation from strategic applications and
management, and security performance measurement.compliance-related assets, as well as from perimeter
Compliancedevices. Security information is made available to
The emergence of compliance as the leading driverindividuals and technology domains across the
for information security management projects hasenterprise, while supporting IT governance, enterprise
forced organizations to refocus on securing underlyingcompliance, and risk management initiatives.