Security systems should be integrated with ticketing systems

Opinion
Mar 1, 20053 mins

* Security management in the data center

Security is always only as strong as the weakest link. For many years, IT security managers have realized that, more often than not, the weakest link is human. Be it the end user who inadvertently clicks and launches a virus, or the administrator who mistakes a security breach for a routing failure, human error is the most common cause of security problems. Unfortunately, we cannot automate security functions to the point of completely removing the human element (nor would we necessarily want to go that far). So, in the meantime, we have to ensure that our technology infrastructure and our human resources work together as well as possible.

More vendors of security systems are integrating operational processes into their products. Whether by improving alert and notification mechanisms or by integrating with workflow management and ticketing systems, we are seeing a renewed awareness of the necessity to have a seamless handoff between the system and the person or team charged with action. Help desks and operations teams rely on ticketing systems such as BMC’s Remedy or Peregrine Systems’ Service Center to manage the workflow of fault remediation across geographically dispersed and multi-disciplined teams. Now security teams are also using these tools to manage global incident response within companies. Fortunately, security vendors are responding with tighter integration and better support for the most common ticketing systems.

Tightly integrating the security infrastructure with the ticketing and workflow tools is important for a number of reasons:

* No dropped events – Without integration, security incidents might “drop through the cracks” and may not be fully remediated.

* More actionable information – Tighter integration means that all the information needed to resolve the incident is available in the fault ticket. If you always have to go back to an intrusion detection system or firewall to see what was going on, your workflow software is not well integrated.

* Tracking – By classifying events automatically and marking trouble tickets with the correct information you can track your operational overhead based on the type of security event. This will be very useful if you want to track historical data, such as the reduction in operational costs delivered by a new security product.

* Auditing – Several government regulations (such as Sarbanes-Oxley) require that you show that your operational processes work well. Ticketing systems can provide useful metrics for auditors, such as the mean time to remediation.

Before you buy your next security product, ask the vendor if its system integrates with your ticketing application. Tightly integrating every step of the security process can help you ensure that each link in the chain is as strong as it needs to be.