SenSage enables compliance analytics

Opinion
Aug 14, 20064 mins

* SenSage helps organizations navigate security, regulatory and data management issues

In the old days – before stringent compliance regulations and pervasive security concerns – system event and security logs used to be the boring diagnostic tool of network/system engineers and security professionals. They’d glance at the logs mostly when there was a problem to see what stuck out like a sore thumb.

Now, however, these logs are gaining importance in the wake of legislation like Sarbanes-Oxley, HIPAA and Gramm-Leach-Bliley, and also with the increased focus on identity theft, information privacy, hacking, and insider abuse. Those boring old IT logs are now viewed as legal/regulatory datasets that must be complete, accurate, and verifiable for use in compliance reviews and forensic investigations. Managing and using event log data has become a de facto security best practice.

These ever increasing requirements and realities are forcing organizations to reassess how they monitor systems, how long log data must be held, and what tools are in place to conduct analysis on that data. Log data is an organization’s strongest information asset to proactively assess its security posture, track threats, and meet audit/compliance requirements.

Generally speaking, the audit control sections of today’s regulations require that organizations:

* Capture and routinely audit security events that may impact the integrity of financial reporting. Specifically, this means all financial applications and their databases, servers, and networks.

* Follow detailed procedures based on COSO and COBiT audit frameworks. In most cases, this requires that system administrators and business owners explicitly review and sign off on their accuracy.

What’s challenging is that these regulations are mere guidelines which do not always spell out how to meet their specific requirements. A further complication is the sheer size and volume of information being aggregated, as evidence, from all system activity. If the staggering amounts of log data were merely collected, stored and archived, it would quickly overwhelm most databases and storage devices – while taking hours or days to interrogate and get answers.

That’s where SenSage helps in assisting organizations navigate the security, regulatory and data management issues:

* For compliance, SenSage has reviewed the regulations in-depth and through customer deployment has developed a set of comprehensive packages that provides increased assurance and documentation that organizations are adhering with both industry and regulatory mandates.

* For data management, SenSage automates the collection and analysis of terabytes of audit trail log data from a vast range of sources – centralizing the logs into a clustered repository which compresses log data to less than 10% of its original size.

* For security, SenSage can correlate the events in real-time and against the stored data to give IT needed alerts, reports and high-speed search capability against the entire data set.

The SenSage Enterprise Security Analytics (ESA) solution facilitates the aggregation and correlation of data required in the identification of security breaches and user policy violations across multiple security and network systems, platforms and applications – which is an imperative to demonstrate compliance due process as well as investigating any security breaches. The product leverages over 180 available log adapters which fully integrate SenSage with network, application, host and security log sources. Additionally, SenSage’s infrastructure provides the scalability to store and process searches through billions of records rapidly. The compressed data can be used to reconstruct individual or suspicious activity in near-real-time, months or even years after the activity took place.

To meet today’s regulatory reporting requirements, SenSage provides both predefined and client customized reports to enable organizations and their auditors to easily perform spot checks and reviews. And, it has more than 100 targeted reports based on predefined queries, as well as real-time correlation rules monitoring financial infrastructure access and integrity. The security foundation analytic reporting is standard out-of-the-box, and you can choose to add reporting modules to suit your needs. Available analytic modules include Sarbanes-Oxley, HIPAA, GLBA, FFIEC, NISPOM, DCID 6/3, PCI, ISO 17799, FISMA, and EU data retention.

All those acronyms aside, here’s the bottom line of what SenSage ESA can do for your organization. Call it “security decision support.” By pulling together seemingly meaningless log data from multiple sources, SenSage can help you spot activities and trends of people (and machines) doing things you wouldn’t expect them to do. You can identify all sorts of policy violations. And then you can take measures to stop and prevent such activity.

Ask yourself, are your activity logs working for you, or do you just look at them when there’s a hiccup in the system? There’s a treasure trove of stories in those logs, waiting to be told. SenSage wants to give them a voice.