The “NOC” on Security Management

Opinion
Jan 16, 20092 mins

In the “EMA on Management” column series, I covered the fact that our recent research revealed many network operators are taking on responsibility for systems management as part of their day-to-day. This phenomenon also applies to other functional areas, such as security management. While network managers have long been concerned with security terms of process and procedure, especially regarding management of access controls and security-specific network infrastructure elements like firewalls and IDS/IPSs, there is another angle worth exploring in multi-purposing network monitoring technologies to serve security objectives (and vice versa). At a time when every expenditure is closely scrutinized, getting more out of your management technology investments by covering more than one function can be very compelling. EMA has been studying the overlap in security management and network management technologies (see our recent report “Proactive Information Security Through Network Visibility”) and recognizes an important trend towards merging these disciplines, at least at the data collection level. Network managers are under pressure to become application aware, and flow monitoring or deep packet inspection instrumentation hold the key to better quality of experience assurance and effective application performance troubleshooting. These same detailed data sources are ideal for many aspects of security monitoring. In my next post, I’ll be looking at the landscape of cross-over products and solutions.