Security geek who writes about whatever comes to his mind: almost nothing :-)
Monday, September 24, 2007
About SIEMs and insider threats
This post is incredibly interesting for me, as I'm actively working on SIEMs, MSS for security monitoring and insider threats.What I really liked about this is that it points to some of the ideas that I like most. it mentions the company behavior with its employees and their actions as results, the misconception about the level of automation that can be reached and the need for someone behind the nuts and bolts putting intelligence in the process. That's really a nice piece.