fhs
Volume 9, Number 10 -- March 10, 2009

RSA Cracks Down on Security Threats with enVision 4.0

Published: March 10, 2009

by Alex Woodie

RSA yesterday unveiled a new version of its security information and event management (SIEM) software, enVision 4.0. With the new release, the EMC subsidiary has introduced several new features aimed at making it easier to correlate and make sense of the security-related log and vulnerability data that is inundating organizations. And in a bid to show enVision is not just for big enterprises, RSA unveiled two new appliances for medium size companies.

RSA bills enVision, which it obtained with its 2006 acquisition of Network Intelligence, as a three-in-one SIEM platform aimed at solving the three interrelated problems of network visibility, regulatory compliance, and security. With more than 1,600 customers, enVision is certainly one of the most highly visible SIEM platforms on the market. And with its capability to gather and correlate pertinent log data from hundreds of pieces of equipment commonly found in datacenters--including IBM System i servers--the product should be on the research list of any enterprise IT administrator in the market for a SIEM solution.

As is the case with most IT security products, enVision's goal is a moving target. Security administrators must continually adapt to changing conditions as new security vulnerabilities are revealed and the hacking techniques of for-profit cyber criminals evolve to take advantage of those vulnerabilities. As the main control panel for achieving an enterprise-wide view of an organization's security posture, SIEM products are under an enormous amount of pressure to adapt to new security threats while trying to keep administrators from becoming overburdened with data and decision making.

In other words, continuous automation is the name of the game in the SIEM world, and RSA strives to deliver that with enVision 4.0.

For starters, enVision now hooks into configuration management database (CMDB) products, such as EMC's own Voyence Control, and vulnerability scanners to get the most accurate and up-to-date list of assets, so that it can map the products to current threats. Hooking into CMDBs and vulnerability scanners "vastly improved our ability to add context to the log data we're gathering," RSA's Paul Stamp says in a blog posting.

enVision 4.0 also delivers better alerting capabilities to notify analysts when high risk vulnerabilities are discovered, and also brings improved correlation rules that should be easier for customers to customize for their specific environment. Many of these rules were developed by RSA partner Assurent, Stamp writes. "Not only are the rules top-notch, but they come with a whole set of background information about what the rules mean, how to tailor them to your environment, and what to do when they fire."

And when a security incident does occur, enVision 4.0 customers should be more prepared to deal with it, thanks to several new features in the product, including new screens designed specifically for investigating security issues. "We've made some big improvements to our Event Explorer interface, which lets you get down and dirty with the detailed event data, and make those ad-hoc forensic queries quicker and easier to perform," Stamp writes. And with this release, events monitored through enVision can also be hooked into a ticketing system, such as EMC's Infra system, to close the loop on security incidents.

enVision is sold as an appliance-based solution. With this week's announcement, two new mid-market appliances have been added to the lineup, including the ES-1260, which supports up to 600 devices and event volumes of up to 1,200 events per second, and the ES-3060, which supports up to 1,200 devices and event volumes of up to 3,000 events per second. These join existing appliances, which can scale up to more than 6,000 devices and handle 30,000 events per second. For more information, visit www.rsa.com.




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
SAFEDATA

FREE White Paper
IBM iSeries Recovery Options:
An Executive Guide

50% of businesses that have a data recovery solution
may still be vulnerable to downtime.

Download the FREE white paper now
to avoid this risk and examine solutions
for protecting your IBM iSeries investment
that are affordable, reliable and simple.

Download now at www.safedata.net


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

BCD:  Reaching your IBM i Web modernization goals is a lot closer with BCD
WMCPA:  24rd Annual Spring Technical Conference, April 1 & 2, 2009, Delavan, WI
COMMON:  Join us at the 2009 annual meeting and expo, April 26-30, Reno, Nevada


 

IT Jungle Store Top Book Picks

Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
Getting Started with PHP for i5/OS: List Price, $59.95
The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
Getting Dizzy from Dynamic Infrastructure

The Economy Gives the Server Biz a Flat Tire in Q4

Infor Battles Customers in Court Over License Fees

As I See It: Isolation

Global IT Spending Barely Ahead of 2008; Some Regions Showing Strength

Four Hundred Guru
A Bevy of BIFs: %XLATE and %REPLACE

Send Messages Unto Others

Admin Alert: Things I learned About IBM Maintenance Contracts

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

System i PTF Guide
March 7, 2009: Volume 11, Number 10

February 28, 2009: Volume 11, Number 9

February 21, 2009: Volume 11, Number 8

February 14, 2009: Volume 11, Number 7

February 7, 2009: Volume 11, Number 6

January 31, 2009: Volume 11, Number 5

TPM at The Register
AT&T wants to run your data center

Gartner: PC sales, except netbooks, to slump in 2009

Citrix taps VMLogix for fake server jukeboxing

Taiwan bails out memory makers

Lenovo erects Atom tower

Forrester: Fake servers like recessions

HP babysits small biz servers

Dell plays with virtual data centers

Server market gets second opinion on Q4

SGI lays off another 9 per cent

Virtualization soars on Big Blue Power boxes

AMD: 'At heart, we're a design company'

EMC facing DoJ probe

Gartner: PC sales, except netbooks, to slump in 2009

THIS ISSUE SPONSORED BY:

Maximum Availability
ARCAD Software
Guild Companies
Safedata
VAULT400


Printer Friendly Version


TABLE OF CONTENTS
DB2/400 Storage Engine for MySQL Now Available as Public Beta

PHP Saves Company Millions by Refurbishing Old ERP System

ManageEngine Goes On Demand with Data Center Tools

RSA Cracks Down on Security Threats with enVision 4.0

Kisco Adds Fax Support to WebReport/400

News Briefs and Product Shorts:

Blog Food for the RPG Programmer: Tastes a Bit Like .NET . . . HiT Touts Real World Work of IBM i Data Provider . . . New Tip Sheet for RDE and WDSc Programmers Arrives . . . PlanetJ Gives WOW an AJAX Refresh . . . Tolly Report Shows Reflection 2008 Outperforms Competitors, Attachmate Says . . .

Four Hundred Stuff

BACK ISSUES




 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2009 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement