Information security professionals are rarely at a loss for data. Point products—such as firewalls, intrusion prevention systems, antivirus programs, operating systems (OSs) and other elements of the security infrastructure—generate steady streams of data about events and conditions. Security professionals are not in need of data—they need information. Filtering volumes of raw data, correlating events, and reporting actionable information is the role of a security information management (SIM) system.
Click Here to download this free eBook Chapter