Skip to:

Security Information and Event Management (SIEM)

Processes and tools that help address ongoing and increasing security monitoring needs.

 
 


Overview

A Security Information and Event Management System (SIEM) helps organizations and their security professionals identify and promptly respond to threats, demonstrate compliance with regulatory requirements, and perform sophisticated forensics.

This service includes a log management appliance that collects and manages logs from selected systems, as well as an event monitoring system that correlates events for incident response and reports on compliance.  The system sends automated alerts and reports to requestors. 

Although part of a broad-reaching enterprise system, individual customers log into segregated areas and monitor according to an organization's requirements.

Services offered include log management, event correlation, start-up assistance, modification and customized report generation.

 
 

Features & Benefits

Features

  • Management of security event logs and repository.
  • Correlation of security events from different log sources.
  • Generation of needed reports and logs for compliance reporting.
  • Assistance with the profiling of assets and known vulnerabilities.

Benefits

  • Streamline handling of security incident information in the security incident response process.
  • Near real time notification of security events.
  • Relevant state computer systems are continously monitored for adverse information security events.
  • Better situational awareness that recognizes and prevents unwanted behavior on the network or computer system.
 
 

Getting Started

This service is provided to the executive branch.  For more information about using this service, contact your Account Manager.

Contact your Account Manager    Visit the MN.IT Mall for more information