case study 4

User Generated

Dngnevrf

Computer Science

Description

Attached,please find-Case study 4

Unformatted Attachment Preview

CSIA 310: Cybersecurity Processes & Technologies Case Study #4: Technology & Product Review for an SIEM Solution Case Scenario: Security Operations Control Centers (SOCC) are a necessity for large businesses and government agencies. But, for a small to medium sized business such as Sifers-Grayson, the expense of setting up and operating a SOCC may outweigh the benefits. Instead of a full SOCC, smaller companies may decide to invest in an enterprise monitoring technology such as a Security Information and Event Management (SIEM) tool. Such tools can be used by to monitor the enterprise, collect information, and report upon security events (generate alerts and alarms). Your task for this case study is to identify, assess, and recommend an SIEM tool which is appropriate for Sifers-Grayson and which could be used to support the activities of a SOCC should Sifers-Grayson decide to establish this organization as a separate operating unit. Research: 1. Review the weekly readings. 2. Choose one of the SIEM products from the Gartner Magic Quadrant analyses. 3. Research your chosen product using the vendor’s website and product information brochures. (Vendors for highly rated products will provide a copy of Gartner’s most recent Magic Quadrant report on their websites but, registration is required.) 4. Find three or more additional sources which provide reviews for (a) your chosen product or (b) general information about SIEM technologies and solutions. Write: Write a 3 page summary of your research. At a minimum, your summary must include the following: 1. An introduction or overview for the security technology category (SIEM). 2. A review of the features, capabilities, and deficiencies for your selected vendor and product 3. Discussion of how the selected product could be used by your client to support its cybersecurity objectives by reducing risk, increasing resistance to threats/attacks, decreasing vulnerabilities, etc. 4. A closing section in which you restate your recommendation for a product (include the three most important benefits). As you write your review, make sure that you address security issues using standard cybersecurity terminology (e.g. protection, detection, prevention, “governance,” confidentiality, integrity, availability, nonrepudiation, assurance, etc.). See the ISACA glossary https://www.isaca.org/pages/glossary.aspx if you need a refresher on acceptable terms and definitions. Copyright ©2016 by University of Maryland University College. All Rights Reserved CSIA 310: Cybersecurity Processes & Technologies As you write your review, make sure that you address security issues using standard cybersecurity terminology (e.g. 5 Pillars IA, 5 Pillars Information Security). See the resources listed under Course Resources > Cybersecurity Concepts Review for definitions and terminology. Formatting Instructions Use standard APA formatting for the MS Word document that you submit to your assignment folder. Formatting requirements and examples are found under Course Resources > APA Resources. Submit For Grading Submit your paper in MS Word format (.docx or .doc file) using the Case Study #4:SIEM Technology & Product Review assignment in your assignment folder. (Attach the file.) Additional Information 1. There is no penalty for writing more than 3 pages but, clarity and conciseness are valued. If your essay is shorter than 3 pages, you may not have sufficient content to meet the assignment requirements (see the rubric). 2. You are expected to write grammatically correct English in every assignment that you submit for grading. Do not turn in any work without (a) using spell check, (b) using grammar check, (c) verifying that your punctuation is correct and (d) reviewing your work for correct word usage and correctly structured sentences and paragraphs. 3. You are expected to credit your sources using in-text citations and reference list entries. Both your citations and your reference list entries must comply with APA 6th edition Style requirements. Failure to credit your sources will result in penalties as provided for under the university’s Academic Integrity policy. Copyright ©2016 by University of Maryland University College. All Rights Reserved
Purchase answer to see full attachment
User generated content is uploaded by users for the purposes of learning and should be used following Studypool's honor code & terms of service.

Explanation & Answer

Let me know where you need further help

Running Head: ACCELOPS
Selected SIEM Product: AccelOps
Introduction
The technology sector is a dynamic field that is constantly experiencing innovation and
advancements on a regular basis. However, this field faces exposure to breaches in security
operations, dwindling skilled cybersecurity personnel, and complexity of managing networks
making it difficult to protect network assets and manage the wide array of data sources. It is for
such reasons that FortiSIEM came up with AccelOps, a SIEM product that can guarantee
security for networks in organizations, (Kukuruzovic, 2016).
FortiSIEM recognized the need to develop a scalable, holistic and comprehensive
solution for compliance management, security, and performance for organizations of all sizes.
Fortinet thus sought a product that could combine advanced analytics with compliance and
security monitoring AccelOps became the solution to provide security and compliance
management from IoT to the cloud that provides maximum security for data and network assets,
(Kotenko, 2012). This product provides fully integrated configuration management database, file
integrity monitoring, performance and availability monitoring, security event management and
security information management.
Features, capabilities, and deficiencies of the product
AccelOps is developed in such a way that it expands network visibility to identify
commercial threats. It is also integrated with open source that increases its ability to associate
with correlation rules and remediation activities, (Kotenko, 2012). AccelOps consists dynamic
HTML5 dashboards, over 200 report templates, and visual analytics making it dynamic for

ACCELOPS

2

application in many disciplines. It also consists an API for bi-directional native support and
workflow integration for LANDesk and Connects Wise.
AccelOps allows the customization of depth and flexibility. The product can be easily
deployed. It provides deep packet inspection, network forensics, security testing, and data loss
prevention operations thus promoting the security of data assets and networks for large, mediumsized and small firms, (Hernando, 2012). AccelOps enables actionable security intelligence and
automated multi-vendor security solutions to be achieved from IoT to the cloud thus providing
high-performance cybersecurity solutions for organizations.
This product allows ...


Anonymous
Excellent resource! Really helped me get the gist of things.

Studypool
4.7
Trustpilot
4.5
Sitejabber
4.4

Similar Content

Related Tags