Gartner对SIEM的定义

今天,被人问及LM、SIEM与SOC的异同。我引用了Gartner对于SIEM的定义作为整个回答的基础。其实,在我早先的博文中已经差不多回答过这个问题。如果你觉得那篇文章看起来比较冗长的话,那么,可以直接看看Gartner对于SIEM的官方定义的原文:

Security information and event management (SIEM) technology provides two main capabilities: security information management (SIM) and security event management (SEM).

Security information management (SIM) provides log management—the collection, reporting and analysis of log data—to support regulatory compliance reporting, internal threat management and resource access monitoring.

Security event management (SEM) processes event data from security devices, network devices, systems and applications in real time to provide security monitoring, event correlation and incident response. The technology can be used to discover activity associated with a targeted attack or a security breach, and is also used to satisfy a wide variety of regulatory requirements.

为啥要看Gartner的SIEM定义。好吧,必须承认,是Gartner创造了SIEM这个术语。

你可能感兴趣的:(Gartner对SIEM的定义)