SIM (security information management)
Software designed to automate the collection of event log data from security devices and helping users make sense of it through a common management console.
SIM products use data aggregation and event correlation features similar to those of network-management software and applies them to event logs generated from security devices such as firewalls, proxy servers, intrusion-detection systems and antivirus software. What's more, SIM products can normalize data - that is, they can translate Cisco and Check Point Software alerts, for example, into a common format so the data can be correlated.
Like network-management software, SIM tools generally consist of server software, agents installed either on servers or security devices, and a central management console.
From Users shoring up net security with SIM, Network World, 09/30/02.
Additional resources
Topic: SecurityLatest security news, analysis and newsletters from Network World Fusion.
Add a comment