<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>Speaking of Security - The RSA Blog and Podcast &#187; SMInsights</title>
	<atom:link href="http://blogs.rsa.com/author/smi/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.rsa.com</link>
	<description>The Security Blog for Security Professionals</description>
	<lastBuildDate>Tue, 21 May 2013 18:37:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5</generator>
<!-- podcast_generator="Blubrry PowerPress/4.0.7" -->
	<itunes:summary>The Speaking of Security podcast features lively discussion with industry experts on the latest issues and trends in the security industry.</itunes:summary>
	<itunes:author>RSA, The Security Division of EMC</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png" />
	<itunes:owner>
		<itunes:name>RSA, The Security Division of EMC</itunes:name>
		<itunes:email>podcast@rsa.com</itunes:email>
	</itunes:owner>
	<managingEditor>podcast@rsa.com (RSA, The Security Division of EMC)</managingEditor>
	<itunes:subtitle>The Security Blog for Security Professionals</itunes:subtitle>
	<itunes:keywords>Security, Cyber Crime, APTs, Sam Curry, RSA, EMC, Advanced Persistant Threats, Fraud</itunes:keywords>
	<image>
		<title>Speaking of Security - The RSA Blog and Podcast &#187; SMInsights</title>
		<url>http://blogs.rsa.com/wp-content/uploads/userphoto/sos.png</url>
		<link>http://blogs.rsa.com</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
		<itunes:category text="Podcasting" />
	</itunes:category>
		<item>
		<title>An Intelligence-Driven SOC – Come See It</title>
		<link>http://blogs.rsa.com/an-intelligence-driven-soc-come-see-it/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=an-intelligence-driven-soc-come-see-it</link>
		<comments>http://blogs.rsa.com/an-intelligence-driven-soc-come-see-it/#comments</comments>
		<pubDate>Mon, 29 Apr 2013 21:19:36 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Advanced Threats]]></category>
		<category><![CDATA[Intelligence-driven security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security Analytics]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[SOC]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=8942</guid>
		<description><![CDATA[I just returned from a weeklong trip to Europe, where I contributed my voice to the wildly successful series of RSA Security Summits. With near unanimity in London and Zurich the audience accepted our premise that as a result of the changing IT landscape – including cloud, mobile, big data, extended workforce, supply chains – and the realities of today’s sophisticated attackers, the approach to security in organizations needs to dramatically change. Furthermore there was also general agreement that today’s preventive security systems, that are largely perimeter and signature-based, no longer provide sufficient defenses, and that to compensate organizations must improve their detective and response focused security controls. This quickly led to the practical and real challenge of how organizations can best make those improvements. How in an environment of fixed security budgets can organizations invest to create or significantly enhance their monitoring and response capabilities?]]></description>
				<content:encoded><![CDATA[<p>By Matthew Gardiner, Sr. Manager, RSA</p>
<p>I just returned from a weeklong trip to Europe, where I contributed my voice to the wildly successful series of <span style="text-decoration: underline;"><strong><a href="http://www.emc.com/microsites/rsa-security-summit/index.htm">RSA Security Summits</a></strong></span>. With near unanimity in London and Zurich the audience accepted our premise that as a result of the changing IT landscape – including cloud, mobile, big data, extended workforce, supply chains – and the realities of today’s sophisticated attackers, the approach to security in organizations needs to dramatically change. Furthermore there was also general agreement that today’s preventive security systems, that are largely perimeter and signature-based, no longer provide sufficient defenses, and that to compensate organizations must improve their detective and response focused security controls. This quickly led to the practical and real challenge of how organizations can best make those improvements. How in an environment of fixed security budgets can organizations invest to create or significantly enhance their monitoring and response capabilities?</p>
<p>In effect organizations are asking themselves how they can build out their security operation centers (SOCs). No doubt there are many factors to consider when considering a significant SOC investment, not the least of which is the organization’s security maturity, type and location of sensitive digital assets, expertise, and risk tolerance. But equally important are the technical infrastructure and processes necessary to make SOCs both more effective and efficient in their task of detecting, investigating, and remediating threats and vulnerabilities. With limited human resources, how can the mundane tasks be automated away and the complex ones be made easier? This is a deep topic that we were only able to touch on during these Summits.</p>
<p>But fortunately if you have interest in building what we call an intelligence-driven SOC, RSA is running a webinar precisely on this topic in which we will spend most of the session walking through the detection, investigation, and response lifecycle of a representative advanced attack and show you how an intelligence-driven SOC solution can help to optimize this process. Sound interesting? Come join us at this <span style="text-decoration: underline;"><strong><a href="https://www.brighttalk.com/webcast/9217/72629">event</a></strong></span> happening Thursday, May 2 at 2 pm EST.</p>
<p><em>Matthew Gardiner is on the product marketing team at RSA and is focused on the evolution of the SOC and RSA’s solutions which help SOC analysts be more effective and efficient in their jobs. You can follow him on twitter @jmatthewg1234.</em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;t=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It%20-%20http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=I%20just%20returned%20from%20a%20weeklong%20trip%20to%20Europe%2C%20where%20I%20contributed%20my%20voice%20to%20the%20wildly%20successful%20series%20of%20RSA%20Security%20Summits.%20With%20near%20unanimity%20in%20London%20and%20Zurich%20the%20audience%20accepted%20our%20premise%20that%20as%20a%20result%20of%20the%20changing%20IT%20landscape%20%E2%80%93%20including%20cloud%2C%20mobile%2C%20big%20data%2C%20extended%20workforce%2C%20supply%20chains%20%E2%80%93%20and%20the%20realities%20of%20today%E2%80%99s%20sophisticated%20attackers%2C%20the%20approach%20to%20security%20in%20organizations%20needs%20to%20dramatically%20change.%20Furthermore%20there%20was%20also%20general%20agreement%20that%20today%E2%80%99s%20preventive%20security%20systems%2C%20that%20are%20largely%20perimeter%20and%20signature-based%2C%20no%20longer%20provide%20sufficient%20defenses%2C%20and%20that%20to%20compensate%20organizations%20must%20improve%20their%20detective%20and%20response%20focused%20security%20controls.%20This%20quickly%20led%20to%20the%20practical%20and%20real%20challenge%20of%20how%20organizations%20can%20best%20make%20those%20improvements.%20How%20in%20an%20environment%20of%20fixed%20security%20budgets%20can%20organizations%20invest%20to%20create%20or%20significantly%20enhance%20their%20monitoring%20and%20response%20capabilities%3F"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&body=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-8942')" id="sociable-post-8942" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;t=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;notes=I%20just%20returned%20from%20a%20weeklong%20trip%20to%20Europe%2C%20where%20I%20contributed%20my%20voice%20to%20the%20wildly%20successful%20series%20of%20RSA%20Security%20Summits.%20With%20near%20unanimity%20in%20London%20and%20Zurich%20the%20audience%20accepted%20our%20premise%20that%20as%20a%20result%20of%20the%20changing%20IT%20landscape%20%E2%80%93%20including%20cloud%2C%20mobile%2C%20big%20data%2C%20extended%20workforce%2C%20supply%20chains%20%E2%80%93%20and%20the%20realities%20of%20today%E2%80%99s%20sophisticated%20attackers%2C%20the%20approach%20to%20security%20in%20organizations%20needs%20to%20dramatically%20change.%20Furthermore%20there%20was%20also%20general%20agreement%20that%20today%E2%80%99s%20preventive%20security%20systems%2C%20that%20are%20largely%20perimeter%20and%20signature-based%2C%20no%20longer%20provide%20sufficient%20defenses%2C%20and%20that%20to%20compensate%20organizations%20must%20improve%20their%20detective%20and%20response%20focused%20security%20controls.%20This%20quickly%20led%20to%20the%20practical%20and%20real%20challenge%20of%20how%20organizations%20can%20best%20make%20those%20improvements.%20How%20in%20an%20environment%20of%20fixed%20security%20budgets%20can%20organizations%20invest%20to%20create%20or%20significantly%20enhance%20their%20monitoring%20and%20response%20capabilities%3F"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;bodytext=I%20just%20returned%20from%20a%20weeklong%20trip%20to%20Europe%2C%20where%20I%20contributed%20my%20voice%20to%20the%20wildly%20successful%20series%20of%20RSA%20Security%20Summits.%20With%20near%20unanimity%20in%20London%20and%20Zurich%20the%20audience%20accepted%20our%20premise%20that%20as%20a%20result%20of%20the%20changing%20IT%20landscape%20%E2%80%93%20including%20cloud%2C%20mobile%2C%20big%20data%2C%20extended%20workforce%2C%20supply%20chains%20%E2%80%93%20and%20the%20realities%20of%20today%E2%80%99s%20sophisticated%20attackers%2C%20the%20approach%20to%20security%20in%20organizations%20needs%20to%20dramatically%20change.%20Furthermore%20there%20was%20also%20general%20agreement%20that%20today%E2%80%99s%20preventive%20security%20systems%2C%20that%20are%20largely%20perimeter%20and%20signature-based%2C%20no%20longer%20provide%20sufficient%20defenses%2C%20and%20that%20to%20compensate%20organizations%20must%20improve%20their%20detective%20and%20response%20focused%20security%20controls.%20This%20quickly%20led%20to%20the%20practical%20and%20real%20challenge%20of%20how%20organizations%20can%20best%20make%20those%20improvements.%20How%20in%20an%20environment%20of%20fixed%20security%20budgets%20can%20organizations%20invest%20to%20create%20or%20significantly%20enhance%20their%20monitoring%20and%20response%20capabilities%3F"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;annotation=I%20just%20returned%20from%20a%20weeklong%20trip%20to%20Europe%2C%20where%20I%20contributed%20my%20voice%20to%20the%20wildly%20successful%20series%20of%20RSA%20Security%20Summits.%20With%20near%20unanimity%20in%20London%20and%20Zurich%20the%20audience%20accepted%20our%20premise%20that%20as%20a%20result%20of%20the%20changing%20IT%20landscape%20%E2%80%93%20including%20cloud%2C%20mobile%2C%20big%20data%2C%20extended%20workforce%2C%20supply%20chains%20%E2%80%93%20and%20the%20realities%20of%20today%E2%80%99s%20sophisticated%20attackers%2C%20the%20approach%20to%20security%20in%20organizations%20needs%20to%20dramatically%20change.%20Furthermore%20there%20was%20also%20general%20agreement%20that%20today%E2%80%99s%20preventive%20security%20systems%2C%20that%20are%20largely%20perimeter%20and%20signature-based%2C%20no%20longer%20provide%20sufficient%20defenses%2C%20and%20that%20to%20compensate%20organizations%20must%20improve%20their%20detective%20and%20response%20focused%20security%20controls.%20This%20quickly%20led%20to%20the%20practical%20and%20real%20challenge%20of%20how%20organizations%20can%20best%20make%20those%20improvements.%20How%20in%20an%20environment%20of%20fixed%20security%20budgets%20can%20organizations%20invest%20to%20create%20or%20significantly%20enhance%20their%20monitoring%20and%20response%20capabilities%3F"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;t=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=I%20just%20returned%20from%20a%20weeklong%20trip%20to%20Europe%2C%20where%20I%20contributed%20my%20voice%20to%20the%20wildly%20successful%20series%20of%20RSA%20Security%20Summits.%20With%20near%20unanimity%20in%20London%20and%20Zurich%20the%20audience%20accepted%20our%20premise%20that%20as%20a%20result%20of%20the%20changing%20IT%20landscape%20%E2%80%93%20including%20cloud%2C%20mobile%2C%20big%20data%2C%20extended%20workforce%2C%20supply%20chains%20%E2%80%93%20and%20the%20realities%20of%20today%E2%80%99s%20sophisticated%20attackers%2C%20the%20approach%20to%20security%20in%20organizations%20needs%20to%20dramatically%20change.%20Furthermore%20there%20was%20also%20general%20agreement%20that%20today%E2%80%99s%20preventive%20security%20systems%2C%20that%20are%20largely%20perimeter%20and%20signature-based%2C%20no%20longer%20provide%20sufficient%20defenses%2C%20and%20that%20to%20compensate%20organizations%20must%20improve%20their%20detective%20and%20response%20focused%20security%20controls.%20This%20quickly%20led%20to%20the%20practical%20and%20real%20challenge%20of%20how%20organizations%20can%20best%20make%20those%20improvements.%20How%20in%20an%20environment%20of%20fixed%20security%20budgets%20can%20organizations%20invest%20to%20create%20or%20significantly%20enhance%20their%20monitoring%20and%20response%20capabilities%3F"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;Title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;selection=I%20just%20returned%20from%20a%20weeklong%20trip%20to%20Europe%2C%20where%20I%20contributed%20my%20voice%20to%20the%20wildly%20successful%20series%20of%20RSA%20Security%20Summits.%20With%20near%20unanimity%20in%20London%20and%20Zurich%20the%20audience%20accepted%20our%20premise%20that%20as%20a%20result%20of%20the%20changing%20IT%20landscape%20%E2%80%93%20including%20cloud%2C%20mobile%2C%20big%20data%2C%20extended%20workforce%2C%20supply%20chains%20%E2%80%93%20and%20the%20realities%20of%20today%E2%80%99s%20sophisticated%20attackers%2C%20the%20approach%20to%20security%20in%20organizations%20needs%20to%20dramatically%20change.%20Furthermore%20there%20was%20also%20general%20agreement%20that%20today%E2%80%99s%20preventive%20security%20systems%2C%20that%20are%20largely%20perimeter%20and%20signature-based%2C%20no%20longer%20provide%20sufficient%20defenses%2C%20and%20that%20to%20compensate%20organizations%20must%20improve%20their%20detective%20and%20response%20focused%20security%20controls.%20This%20quickly%20led%20to%20the%20practical%20and%20real%20challenge%20of%20how%20organizations%20can%20best%20make%20those%20improvements.%20How%20in%20an%20environment%20of%20fixed%20security%20budgets%20can%20organizations%20invest%20to%20create%20or%20significantly%20enhance%20their%20monitoring%20and%20response%20capabilities%3F"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;t=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;s=I%20just%20returned%20from%20a%20weeklong%20trip%20to%20Europe%2C%20where%20I%20contributed%20my%20voice%20to%20the%20wildly%20successful%20series%20of%20RSA%20Security%20Summits.%20With%20near%20unanimity%20in%20London%20and%20Zurich%20the%20audience%20accepted%20our%20premise%20that%20as%20a%20result%20of%20the%20changing%20IT%20landscape%20%E2%80%93%20including%20cloud%2C%20mobile%2C%20big%20data%2C%20extended%20workforce%2C%20supply%20chains%20%E2%80%93%20and%20the%20realities%20of%20today%E2%80%99s%20sophisticated%20attackers%2C%20the%20approach%20to%20security%20in%20organizations%20needs%20to%20dramatically%20change.%20Furthermore%20there%20was%20also%20general%20agreement%20that%20today%E2%80%99s%20preventive%20security%20systems%2C%20that%20are%20largely%20perimeter%20and%20signature-based%2C%20no%20longer%20provide%20sufficient%20defenses%2C%20and%20that%20to%20compensate%20organizations%20must%20improve%20their%20detective%20and%20response%20focused%20security%20controls.%20This%20quickly%20led%20to%20the%20practical%20and%20real%20challenge%20of%20how%20organizations%20can%20best%20make%20those%20improvements.%20How%20in%20an%20environment%20of%20fixed%20security%20budgets%20can%20organizations%20invest%20to%20create%20or%20significantly%20enhance%20their%20monitoring%20and%20response%20capabilities%3F"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;title=An%20Intelligence-Driven%20SOC%20%E2%80%93%20Come%20See%20It&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fan-intelligence-driven-soc-come-see-it%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-8942')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-8942',true)" class="close">

		  <img onclick="hide_sociable('post-8942',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/an-intelligence-driven-soc-come-see-it/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/an-intelligence-driven-soc-come-see-it/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business Context and Incident Management for the Security Operations Center (SOC)</title>
		<link>http://blogs.rsa.com/business-context-and-incident-management-for-the-security-operations-center-soc/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=business-context-and-incident-management-for-the-security-operations-center-soc</link>
		<comments>http://blogs.rsa.com/business-context-and-incident-management-for-the-security-operations-center-soc/#comments</comments>
		<pubDate>Tue, 19 Mar 2013 16:00:09 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[IT Security]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=8388</guid>
		<description><![CDATA[Today’s IT environments are more fluid and complex than ever. Security teams are faced with a flood of alerts and indicators across thousands of devices and massive volumes and varieties of applications and information types. It is more important than ever that the efforts of the security teams are prioritized such that threats that pose the biggest risk to the organization are investigated and resolved first.]]></description>
				<content:encoded><![CDATA[<p><i>By Bali Kuchipudi, RSA Consultant Product Marketing Manager, Security Management and Compliance</i></p>
<p>Today’s IT environments are more fluid and complex than ever. Security teams are faced with a flood of alerts and indicators across thousands of devices and massive volumes and varieties of applications and information types. It is more important than ever that the efforts of the security teams are prioritized such that threats that pose the biggest risk to the organization are investigated and resolved first.</p>
<p>So, how are security teams dealing with this? Yes, it is a Big Data problem and security teams must have full visibility, intelligence and governance to rapidly detect advanced threats and have an incident management process to prioritize, investigate and resolve security incidents. It is about prioritizing the efforts of the security teams by finding the right needle in a stack of needles.</p>
<p><a href="http://blogs.rsa.com/?attachment_id=8389" rel="attachment wp-att-8389"><img class="size-full wp-image-8389 alignnone" alt="Untitled" src="http://blogs.rsa.com/wp-content/uploads/Untitled.jpg" width="431" height="179" /></a></p>
<p>&nbsp;</p>
<p>At RSA Conference in February, we announced <span style="text-decoration: underline"><strong><a href="http://www.emc.com/about/news/press/2013/20130225-01.htm">RSA Asset Criticality Intelligence (ACI)</a></strong></span> and <span style="text-decoration: underline"><strong><a href="http://www.emc.com/about/news/press/2013/20130225-01.htm">RSA Advanced Incident Management for Security (AIMS)</a></strong></span>, now I am thrilled to say that both these solutions are generally available. <span style="text-decoration: underline"><strong><a href="http://www.emc.com/security/security-analytics/security-analytics.htm">RSA Security Analytics</a></strong></span> is a transformative security monitoring and investigative solution that captures and analyzes all security related data as network packets and logs and fuses this with threat intelligence to speed up the detection of potential threats. With <span style="text-decoration: underline"><strong><a href="http://www.emc.com/security/security-analytics/security-analytics.htm#!integration_options">RSA ACI and RSA AIMS</a></strong></span>, the threats that pose the biggest risk to the most critical assets of the organization are prioritized and followed through by the security teams. These solutions provide a single-user interface for security analysts to use when investigating a security event;  the security analyst can engage key business stakeholders,  follow standard response procedures and document the resolution. For example, in the case of data exfiltration from a critical asset – the incident is automatically created, the asset owner can be notified of the exfiltration, and the IT team can be notified to close ports and kick-off the remediation process to remove any malware on the asset or patch the vulnerabilities. Additionally, while the security incident is being investigated, the various stakeholders are kept apprised of the situation through advanced reporting and dashboards.</p>
<p>RSA ACI and RSA AIMS bridge the gap between security and business teams so both teams are aligned in protecting the most critical assets and information of an organization.</p>
<p>This Thursday, March 21<sup>st</sup>, RSA will hold a live webcast called “Business Context and Incident Management for the Security Operations Center (SOC)”. You can register for this webcast here: <span style="text-decoration: underline"><strong><a href="https://emcinformation.com/137302/REG/.ashx?reg_src=speakingofsecurity">https://emcinformation.com/137302/REG/.ashx?reg_src=speakingofsecurity</a></strong></span>. It will provide you with an overview of RSA ACI and RSA AIMS and will also provide a live demonstration of both these solutions.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;t=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29%20-%20http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Today%E2%80%99s%20IT%20environments%20are%20more%20fluid%20and%20complex%20than%20ever.%20Security%20teams%20are%20faced%20with%20a%20flood%20of%20alerts%20and%20indicators%20across%20thousands%20of%20devices%20and%20massive%20volumes%20and%20varieties%20of%20applications%20and%20information%20types.%20It%20is%20more%20important%20than%20ever%20that%20the%20efforts%20of%20the%20security%20teams%20are%20prioritized%20such%20that%20threats%20that%20pose%20the%20biggest%20risk%20to%20the%20organization%20are%20investigated%20and%20resolved%20first."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&body=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-8388')" id="sociable-post-8388" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;t=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;notes=Today%E2%80%99s%20IT%20environments%20are%20more%20fluid%20and%20complex%20than%20ever.%20Security%20teams%20are%20faced%20with%20a%20flood%20of%20alerts%20and%20indicators%20across%20thousands%20of%20devices%20and%20massive%20volumes%20and%20varieties%20of%20applications%20and%20information%20types.%20It%20is%20more%20important%20than%20ever%20that%20the%20efforts%20of%20the%20security%20teams%20are%20prioritized%20such%20that%20threats%20that%20pose%20the%20biggest%20risk%20to%20the%20organization%20are%20investigated%20and%20resolved%20first."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;bodytext=Today%E2%80%99s%20IT%20environments%20are%20more%20fluid%20and%20complex%20than%20ever.%20Security%20teams%20are%20faced%20with%20a%20flood%20of%20alerts%20and%20indicators%20across%20thousands%20of%20devices%20and%20massive%20volumes%20and%20varieties%20of%20applications%20and%20information%20types.%20It%20is%20more%20important%20than%20ever%20that%20the%20efforts%20of%20the%20security%20teams%20are%20prioritized%20such%20that%20threats%20that%20pose%20the%20biggest%20risk%20to%20the%20organization%20are%20investigated%20and%20resolved%20first."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;annotation=Today%E2%80%99s%20IT%20environments%20are%20more%20fluid%20and%20complex%20than%20ever.%20Security%20teams%20are%20faced%20with%20a%20flood%20of%20alerts%20and%20indicators%20across%20thousands%20of%20devices%20and%20massive%20volumes%20and%20varieties%20of%20applications%20and%20information%20types.%20It%20is%20more%20important%20than%20ever%20that%20the%20efforts%20of%20the%20security%20teams%20are%20prioritized%20such%20that%20threats%20that%20pose%20the%20biggest%20risk%20to%20the%20organization%20are%20investigated%20and%20resolved%20first."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;t=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Today%E2%80%99s%20IT%20environments%20are%20more%20fluid%20and%20complex%20than%20ever.%20Security%20teams%20are%20faced%20with%20a%20flood%20of%20alerts%20and%20indicators%20across%20thousands%20of%20devices%20and%20massive%20volumes%20and%20varieties%20of%20applications%20and%20information%20types.%20It%20is%20more%20important%20than%20ever%20that%20the%20efforts%20of%20the%20security%20teams%20are%20prioritized%20such%20that%20threats%20that%20pose%20the%20biggest%20risk%20to%20the%20organization%20are%20investigated%20and%20resolved%20first."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;Title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;selection=Today%E2%80%99s%20IT%20environments%20are%20more%20fluid%20and%20complex%20than%20ever.%20Security%20teams%20are%20faced%20with%20a%20flood%20of%20alerts%20and%20indicators%20across%20thousands%20of%20devices%20and%20massive%20volumes%20and%20varieties%20of%20applications%20and%20information%20types.%20It%20is%20more%20important%20than%20ever%20that%20the%20efforts%20of%20the%20security%20teams%20are%20prioritized%20such%20that%20threats%20that%20pose%20the%20biggest%20risk%20to%20the%20organization%20are%20investigated%20and%20resolved%20first."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;t=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;s=Today%E2%80%99s%20IT%20environments%20are%20more%20fluid%20and%20complex%20than%20ever.%20Security%20teams%20are%20faced%20with%20a%20flood%20of%20alerts%20and%20indicators%20across%20thousands%20of%20devices%20and%20massive%20volumes%20and%20varieties%20of%20applications%20and%20information%20types.%20It%20is%20more%20important%20than%20ever%20that%20the%20efforts%20of%20the%20security%20teams%20are%20prioritized%20such%20that%20threats%20that%20pose%20the%20biggest%20risk%20to%20the%20organization%20are%20investigated%20and%20resolved%20first."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;title=Business%20Context%20and%20Incident%20Management%20for%20the%20Security%20Operations%20Center%20%28SOC%29&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fbusiness-context-and-incident-management-for-the-security-operations-center-soc%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-8388')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-8388',true)" class="close">

		  <img onclick="hide_sociable('post-8388',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/business-context-and-incident-management-for-the-security-operations-center-soc/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/business-context-and-incident-management-for-the-security-operations-center-soc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Big Data Security Analytics Era Is Here</title>
		<link>http://blogs.rsa.com/the-big-data-security-analytics-era-is-here/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-big-data-security-analytics-era-is-here</link>
		<comments>http://blogs.rsa.com/the-big-data-security-analytics-era-is-here/#comments</comments>
		<pubDate>Wed, 30 Jan 2013 11:00:09 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[advanced threats]]></category>
		<category><![CDATA[Big Data Analytics]]></category>
		<category><![CDATA[Big Data Security]]></category>
		<category><![CDATA[security analytics]]></category>
		<category><![CDATA[SIEM]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=7987</guid>
		<description><![CDATA[My blog today reflects on newly published research from Jon Olstik at ESG (from whom I borrowed the title of this blog), which covers the collision of advanced threats, security monitoring, SIEM, big data technologies and techniques, and organizational security maturity.  In the paper Jon clearly brings forward his argument - with which I completely agree - that security threats have changed and thus the tools used and approaches for defense need to change significantly.  I recognize this sounds a bit clichéd, but read the paper and you will see that there is a clear argument and evidence to back up this claim.  One very obvious technical trend is that the flood of security data that is required to provide the visibility that is necessary to improve the organization’s defenses, have gone up -- way, way up.]]></description>
				<content:encoded><![CDATA[<p><em>By Matthew Gardiner, Senior Manager, RSA Security Management &amp; Compliance<br />
</em></p>
<p>My blog today reflects on newly <span style="text-decoration: underline"><strong>published research</strong></span> from <span style="text-decoration: underline"><strong><a href="http://www.esg-global.com/author/jon-oltsik/">Jon Olstik</a></strong></span> at <span style="text-decoration: underline"><strong><a href="http://www.esg-global.com/">ESG</a></strong></span> (from whom I borrowed the title of this blog), which covers the collision of advanced threats, security monitoring, SIEM, big data technologies and techniques, and organizational security maturity.  In the paper Jon clearly brings forward his argument &#8211; with which I completely agree &#8211; that security threats have changed and thus the tools used and approaches for defense need to change significantly.  I recognize this sounds a bit clichéd, but read the paper and you will see that there is a clear argument and evidence to back up this claim.  One very obvious technical trend is that the flood of security data that is required to provide the visibility that is necessary to improve the organization’s defenses, have gone up &#8212; way, way up.</p>
<p>But there is the rub, as most centralized security data collection and analytics systems in use by enterprises today (SIEM systems generally) not only rely on partially informative data sources (logs/events), but are already computationally overwhelmed by the amount and rate of change of this security data.  Collecting data that can’t be analyzed in a timely manner adds little value.  Asking these traditional SIEM systems to provide better security monitoring to match the stealthiest attacks has become a dead end.  It is our view that further tuning and tweaking of traditional, log-centric SIEM systems is futile given the security realities on the ground.  While security organizations face more than SIEM technology challenges, such as rapid infrastructure and application changes and the growing security skills shortage, more effective monitoring tools can help to mitigate the impact of all of these problems.</p>
<p>Enter the era of Big Data security analytics.  RSA’s new product for this new era is <a href="http://www.emc.com/about/news/press/2013/20130130-01.htm"><span style="text-decoration: underline"><strong>RSA Security Analytics</strong></span></a>.  Whether or not the market ultimately considers this product a SIEM or creates a new category for it, RSA Security Analytics brings forward a new approach to the detection and investigation of threats that goes beyond traditional, log-centric SIEM systems.  It enables the ingestion and analysis of large and fast changing data sets with the goal of helping the security analyst draw intelligence from it in near real-time.</p>
<p>Does it consume logs?  Yes.  But it is not limited to only that form of telemetry.  RSA Security Analytics combines broad telemetry (most notably full network packet capture, automated threat intelligence, and asset information) with a data management and analytic platform that scales to make real-time security monitoring effective against even the most stealthy attacks.</p>
<p>To take part in our product launch event (or view a recording of it later) come join us <span style="text-decoration: underline"><strong><a href="https://presentations.inxpo.com/Shows/RSA_SA/Registration/RSASAR.html?AffiliateKey=15973&amp;AffiliateData=eDM">here</a></strong></span>.</p>
<p><em>Matthew Gardiner is on the Security Management &amp; Compliance product marketing team at RSA and is focused on the evolution of the SOC and RSA’s solutions which help SOC analysts be more effective and efficient in their jobs.  You can follow him on twitter @jmatthewg1234. </em></p>
<div>
<hr align="left" size="1" width="33%" />
</div>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;t=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here%20-%20http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=My%20blog%20today%20reflects%20on%20newly%20published%20research%20from%20Jon%20Olstik%20at%20ESG%20%28from%20whom%20I%20borrowed%20the%20title%20of%20this%20blog%29%2C%20which%20covers%20the%20collision%20of%20advanced%20threats%2C%20security%20monitoring%2C%20SIEM%2C%20big%20data%20technologies%20and%20techniques%2C%20and%20organizational%20security%20maturity.%20%20In%20the%20paper%20Jon%20clearly%20brings%20forward%20his%20argument%20-%20with%20which%20I%20completely%20agree%20-%20that%20security%20threats%20have%20changed%20and%20thus%20the%20tools%20used%20and%20approaches%20for%20defense%20need%20to%20change%20significantly.%20%20I%20recognize%20this%20sounds%20a%20bit%20clich%C3%A9d%2C%20but%20read%20the%20paper%20and%20you%20will%20see%20that%20there%20is%20a%20clear%20argument%20and%20evidence%20to%20back%20up%20this%20claim.%20%20One%20very%20obvious%20technical%20trend%20is%20that%20the%20flood%20of%20security%20data%20that%20is%20required%20to%20provide%20the%20visibility%20that%20is%20necessary%20to%20improve%20the%20organization%E2%80%99s%20defenses%2C%20have%20gone%20up%20--%20way%2C%20way%20up."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&body=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-7987')" id="sociable-post-7987" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;t=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;notes=My%20blog%20today%20reflects%20on%20newly%20published%20research%20from%20Jon%20Olstik%20at%20ESG%20%28from%20whom%20I%20borrowed%20the%20title%20of%20this%20blog%29%2C%20which%20covers%20the%20collision%20of%20advanced%20threats%2C%20security%20monitoring%2C%20SIEM%2C%20big%20data%20technologies%20and%20techniques%2C%20and%20organizational%20security%20maturity.%20%20In%20the%20paper%20Jon%20clearly%20brings%20forward%20his%20argument%20-%20with%20which%20I%20completely%20agree%20-%20that%20security%20threats%20have%20changed%20and%20thus%20the%20tools%20used%20and%20approaches%20for%20defense%20need%20to%20change%20significantly.%20%20I%20recognize%20this%20sounds%20a%20bit%20clich%C3%A9d%2C%20but%20read%20the%20paper%20and%20you%20will%20see%20that%20there%20is%20a%20clear%20argument%20and%20evidence%20to%20back%20up%20this%20claim.%20%20One%20very%20obvious%20technical%20trend%20is%20that%20the%20flood%20of%20security%20data%20that%20is%20required%20to%20provide%20the%20visibility%20that%20is%20necessary%20to%20improve%20the%20organization%E2%80%99s%20defenses%2C%20have%20gone%20up%20--%20way%2C%20way%20up."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;bodytext=My%20blog%20today%20reflects%20on%20newly%20published%20research%20from%20Jon%20Olstik%20at%20ESG%20%28from%20whom%20I%20borrowed%20the%20title%20of%20this%20blog%29%2C%20which%20covers%20the%20collision%20of%20advanced%20threats%2C%20security%20monitoring%2C%20SIEM%2C%20big%20data%20technologies%20and%20techniques%2C%20and%20organizational%20security%20maturity.%20%20In%20the%20paper%20Jon%20clearly%20brings%20forward%20his%20argument%20-%20with%20which%20I%20completely%20agree%20-%20that%20security%20threats%20have%20changed%20and%20thus%20the%20tools%20used%20and%20approaches%20for%20defense%20need%20to%20change%20significantly.%20%20I%20recognize%20this%20sounds%20a%20bit%20clich%C3%A9d%2C%20but%20read%20the%20paper%20and%20you%20will%20see%20that%20there%20is%20a%20clear%20argument%20and%20evidence%20to%20back%20up%20this%20claim.%20%20One%20very%20obvious%20technical%20trend%20is%20that%20the%20flood%20of%20security%20data%20that%20is%20required%20to%20provide%20the%20visibility%20that%20is%20necessary%20to%20improve%20the%20organization%E2%80%99s%20defenses%2C%20have%20gone%20up%20--%20way%2C%20way%20up."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;annotation=My%20blog%20today%20reflects%20on%20newly%20published%20research%20from%20Jon%20Olstik%20at%20ESG%20%28from%20whom%20I%20borrowed%20the%20title%20of%20this%20blog%29%2C%20which%20covers%20the%20collision%20of%20advanced%20threats%2C%20security%20monitoring%2C%20SIEM%2C%20big%20data%20technologies%20and%20techniques%2C%20and%20organizational%20security%20maturity.%20%20In%20the%20paper%20Jon%20clearly%20brings%20forward%20his%20argument%20-%20with%20which%20I%20completely%20agree%20-%20that%20security%20threats%20have%20changed%20and%20thus%20the%20tools%20used%20and%20approaches%20for%20defense%20need%20to%20change%20significantly.%20%20I%20recognize%20this%20sounds%20a%20bit%20clich%C3%A9d%2C%20but%20read%20the%20paper%20and%20you%20will%20see%20that%20there%20is%20a%20clear%20argument%20and%20evidence%20to%20back%20up%20this%20claim.%20%20One%20very%20obvious%20technical%20trend%20is%20that%20the%20flood%20of%20security%20data%20that%20is%20required%20to%20provide%20the%20visibility%20that%20is%20necessary%20to%20improve%20the%20organization%E2%80%99s%20defenses%2C%20have%20gone%20up%20--%20way%2C%20way%20up."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;t=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=My%20blog%20today%20reflects%20on%20newly%20published%20research%20from%20Jon%20Olstik%20at%20ESG%20%28from%20whom%20I%20borrowed%20the%20title%20of%20this%20blog%29%2C%20which%20covers%20the%20collision%20of%20advanced%20threats%2C%20security%20monitoring%2C%20SIEM%2C%20big%20data%20technologies%20and%20techniques%2C%20and%20organizational%20security%20maturity.%20%20In%20the%20paper%20Jon%20clearly%20brings%20forward%20his%20argument%20-%20with%20which%20I%20completely%20agree%20-%20that%20security%20threats%20have%20changed%20and%20thus%20the%20tools%20used%20and%20approaches%20for%20defense%20need%20to%20change%20significantly.%20%20I%20recognize%20this%20sounds%20a%20bit%20clich%C3%A9d%2C%20but%20read%20the%20paper%20and%20you%20will%20see%20that%20there%20is%20a%20clear%20argument%20and%20evidence%20to%20back%20up%20this%20claim.%20%20One%20very%20obvious%20technical%20trend%20is%20that%20the%20flood%20of%20security%20data%20that%20is%20required%20to%20provide%20the%20visibility%20that%20is%20necessary%20to%20improve%20the%20organization%E2%80%99s%20defenses%2C%20have%20gone%20up%20--%20way%2C%20way%20up."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;Title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;selection=My%20blog%20today%20reflects%20on%20newly%20published%20research%20from%20Jon%20Olstik%20at%20ESG%20%28from%20whom%20I%20borrowed%20the%20title%20of%20this%20blog%29%2C%20which%20covers%20the%20collision%20of%20advanced%20threats%2C%20security%20monitoring%2C%20SIEM%2C%20big%20data%20technologies%20and%20techniques%2C%20and%20organizational%20security%20maturity.%20%20In%20the%20paper%20Jon%20clearly%20brings%20forward%20his%20argument%20-%20with%20which%20I%20completely%20agree%20-%20that%20security%20threats%20have%20changed%20and%20thus%20the%20tools%20used%20and%20approaches%20for%20defense%20need%20to%20change%20significantly.%20%20I%20recognize%20this%20sounds%20a%20bit%20clich%C3%A9d%2C%20but%20read%20the%20paper%20and%20you%20will%20see%20that%20there%20is%20a%20clear%20argument%20and%20evidence%20to%20back%20up%20this%20claim.%20%20One%20very%20obvious%20technical%20trend%20is%20that%20the%20flood%20of%20security%20data%20that%20is%20required%20to%20provide%20the%20visibility%20that%20is%20necessary%20to%20improve%20the%20organization%E2%80%99s%20defenses%2C%20have%20gone%20up%20--%20way%2C%20way%20up."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;t=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;s=My%20blog%20today%20reflects%20on%20newly%20published%20research%20from%20Jon%20Olstik%20at%20ESG%20%28from%20whom%20I%20borrowed%20the%20title%20of%20this%20blog%29%2C%20which%20covers%20the%20collision%20of%20advanced%20threats%2C%20security%20monitoring%2C%20SIEM%2C%20big%20data%20technologies%20and%20techniques%2C%20and%20organizational%20security%20maturity.%20%20In%20the%20paper%20Jon%20clearly%20brings%20forward%20his%20argument%20-%20with%20which%20I%20completely%20agree%20-%20that%20security%20threats%20have%20changed%20and%20thus%20the%20tools%20used%20and%20approaches%20for%20defense%20need%20to%20change%20significantly.%20%20I%20recognize%20this%20sounds%20a%20bit%20clich%C3%A9d%2C%20but%20read%20the%20paper%20and%20you%20will%20see%20that%20there%20is%20a%20clear%20argument%20and%20evidence%20to%20back%20up%20this%20claim.%20%20One%20very%20obvious%20technical%20trend%20is%20that%20the%20flood%20of%20security%20data%20that%20is%20required%20to%20provide%20the%20visibility%20that%20is%20necessary%20to%20improve%20the%20organization%E2%80%99s%20defenses%2C%20have%20gone%20up%20--%20way%2C%20way%20up."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;title=The%20Big%20Data%20Security%20Analytics%20Era%20Is%20Here&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fthe-big-data-security-analytics-era-is-here%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-7987')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-7987',true)" class="close">

		  <img onclick="hide_sociable('post-7987',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/the-big-data-security-analytics-era-is-here/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/the-big-data-security-analytics-era-is-here/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Waiting for Big Data to Impact Security?  It Already Has.</title>
		<link>http://blogs.rsa.com/waiting-for-big-data-to-impact-security-it-already-has/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=waiting-for-big-data-to-impact-security-it-already-has</link>
		<comments>http://blogs.rsa.com/waiting-for-big-data-to-impact-security-it-already-has/#comments</comments>
		<pubDate>Thu, 27 Sep 2012 12:00:24 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=6523</guid>
		<description><![CDATA[In the case of security, organizations need to understand where the risks are, where the infections have landed, where the attacks are in process, and what they should do about them, fast.  This has lead security organizations directly into the challenge/opportunity of Big Data, now.
]]></description>
				<content:encoded><![CDATA[<p>By Matthew Gardiner, Sr. Manager, RSA</p>
<p>If you were wondering when Big Data and security analytics were going to collide, recent data strongly suggests that they already have. In a big way. If you are currently employed as a security analyst you can stop rolling your eyes now. I know you know this; the purpose of this blog is to communicate to the people around you that don’t know what you already are living every day.</p>
<p>RSA recently sponsored some survey-based research with analyst firm ESG largely on the topic of Big Data &amp; security. While ESG hasn’t published this research yet, RSA was recently able to get an early look at the results. A key take-away from the research is that most enterprises are already smack in the middle of the challenge/opportunity of using Big Data approaches to improve their security position. In an effort to gain better visibility and improved detection and investigative efficiency and effectiveness, organizations are collecting and trying to glean intelligence from more sources than ever before.</p>
<p>For example, when asked “How has the amount of data your organization collects to support its information security activities changed in the last 2 years”, 86% of respondents answered either “substantially more” or “somewhat more”. &#8211;  0% selected “less”.  When asked about the types of data that their organization collects or plans to collect in the next 12-24 months, the list of data types that more than 75% of respondents checked included more than 18 types.</p>
<p>These two questions hit directly at two key pillars of the Big Data phenomenon, namely the existence of large data sets of highly diverse data types, from which key insights must be quickly gleaned. In the case of security, organizations need to understand where the risks are, where the infections have landed, where the attacks are in process, and what they should do about them, fast. This has lead security organizations directly into the challenge/opportunity of Big Data, now.</p>
<p><em>Matthew Gardiner is on the product marketing team at RSA and is focused on the evolution of the SOC and RSA’s solutions which help SOC analysts be more effective and efficient in their jobs. You can follow him on twitter @jmatthewg1234. </em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;t=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has."></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.%20-%20http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=In%20the%20case%20of%20security%2C%20organizations%20need%20to%20understand%20where%20the%20risks%20are%2C%20where%20the%20infections%20have%20landed%2C%20where%20the%20attacks%20are%20in%20process%2C%20and%20what%20they%20should%20do%20about%20them%2C%20fast.%20%20This%20has%20lead%20security%20organizations%20directly%20into%20the%20challenge%2Fopportunity%20of%20Big%20Data%2C%20now.%0D%0A"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&body=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-6523')" id="sociable-post-6523" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;t=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has."></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;notes=In%20the%20case%20of%20security%2C%20organizations%20need%20to%20understand%20where%20the%20risks%20are%2C%20where%20the%20infections%20have%20landed%2C%20where%20the%20attacks%20are%20in%20process%2C%20and%20what%20they%20should%20do%20about%20them%2C%20fast.%20%20This%20has%20lead%20security%20organizations%20directly%20into%20the%20challenge%2Fopportunity%20of%20Big%20Data%2C%20now.%0D%0A"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;bodytext=In%20the%20case%20of%20security%2C%20organizations%20need%20to%20understand%20where%20the%20risks%20are%2C%20where%20the%20infections%20have%20landed%2C%20where%20the%20attacks%20are%20in%20process%2C%20and%20what%20they%20should%20do%20about%20them%2C%20fast.%20%20This%20has%20lead%20security%20organizations%20directly%20into%20the%20challenge%2Fopportunity%20of%20Big%20Data%2C%20now.%0D%0A"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has."></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has."></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;annotation=In%20the%20case%20of%20security%2C%20organizations%20need%20to%20understand%20where%20the%20risks%20are%2C%20where%20the%20infections%20have%20landed%2C%20where%20the%20attacks%20are%20in%20process%2C%20and%20what%20they%20should%20do%20about%20them%2C%20fast.%20%20This%20has%20lead%20security%20organizations%20directly%20into%20the%20challenge%2Fopportunity%20of%20Big%20Data%2C%20now.%0D%0A"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;t=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has."></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=In%20the%20case%20of%20security%2C%20organizations%20need%20to%20understand%20where%20the%20risks%20are%2C%20where%20the%20infections%20have%20landed%2C%20where%20the%20attacks%20are%20in%20process%2C%20and%20what%20they%20should%20do%20about%20them%2C%20fast.%20%20This%20has%20lead%20security%20organizations%20directly%20into%20the%20challenge%2Fopportunity%20of%20Big%20Data%2C%20now.%0D%0A"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;Title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has."></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;selection=In%20the%20case%20of%20security%2C%20organizations%20need%20to%20understand%20where%20the%20risks%20are%2C%20where%20the%20infections%20have%20landed%2C%20where%20the%20attacks%20are%20in%20process%2C%20and%20what%20they%20should%20do%20about%20them%2C%20fast.%20%20This%20has%20lead%20security%20organizations%20directly%20into%20the%20challenge%2Fopportunity%20of%20Big%20Data%2C%20now.%0D%0A"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;t=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;s=In%20the%20case%20of%20security%2C%20organizations%20need%20to%20understand%20where%20the%20risks%20are%2C%20where%20the%20infections%20have%20landed%2C%20where%20the%20attacks%20are%20in%20process%2C%20and%20what%20they%20should%20do%20about%20them%2C%20fast.%20%20This%20has%20lead%20security%20organizations%20directly%20into%20the%20challenge%2Fopportunity%20of%20Big%20Data%2C%20now.%0D%0A"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;title=Waiting%20for%20Big%20Data%20to%20Impact%20Security%3F%20%20It%20Already%20Has.&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fwaiting-for-big-data-to-impact-security-it-already-has%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-6523')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-6523',true)" class="close">

		  <img onclick="hide_sociable('post-6523',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/waiting-for-big-data-to-impact-security-it-already-has/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/waiting-for-big-data-to-impact-security-it-already-has/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apply Pressure to SIEM and it Turns into Security Analytics</title>
		<link>http://blogs.rsa.com/apply-pressure-to-siem-and-it-turns-into-security-analytics/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=apply-pressure-to-siem-and-it-turns-into-security-analytics</link>
		<comments>http://blogs.rsa.com/apply-pressure-to-siem-and-it-turns-into-security-analytics/#comments</comments>
		<pubDate>Mon, 10 Sep 2012 16:00:42 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=6346</guid>
		<description><![CDATA[It is a well known that if you want someone or something to change, just apply pressure over a period of time. This is true for organizations, people, and even earthly matter, such as carbon (diamonds) and formerly living plants (hydrocarbons). Markets also transform when under pressure. I believe this is precisely what is happening to the SIEM market right now.]]></description>
				<content:encoded><![CDATA[<p>By Matthew Gardiner, Sr. Manager, RSA</p>
<p>It is a well known that if you want someone or something to change, just apply pressure over a period of time. This is true for organizations, people, and even earthly matter, such as carbon (diamonds) and formerly living plants (hydrocarbons). Markets also transform when under pressure. I believe this is precisely what is happening to the SIEM market right now.</p>
<p>What are the points of pressure for the SIEM market? There are a number of them, but the big one is the rise of advanced or targeted attacks against organizations. While traditional, log-centric SIEM systems are theoretically well positioned to become early warning systems for advanced threats, due to their centralized position pared with highly distributed data collection, they currently fall short in many critical ways.</p>
<p>For one, traditional SIEM systems do not have sufficient visibility into the IT environment or organizational context to be able to detect security vulnerabilities or risky anomalous activity. Even if they had this capability, SIEM systems don’t provide sufficiently deep analytics to be able to aid the security analyst sort through the meaningless noise to find the security issues that matter. Furthermore, even if they could accomplish the previous two things, most traditional SIEM systems choke when applied to this level of “big data” – often measured in terabytes per day.</p>
<p>And finally, SIEM systems were not designed with the security (or SOC) analyst sufficiently in mind. Since security analysts spend much of their time investigating issues and incidents, it is absolutely critical, especially with the rise of advanced threats, that they be able to conduct these investigations efficiently and effectively, as time is the enemy.</p>
<p>The traditional, log-centric SIEM market is under pressure from advanced threats, but as do organizations, people, and earthly matter, the SIEM market in general (and RSA in particular) is responding to this pressure by transforming SIEM into Security Analytics.</p>
<p>Matthew Gardiner is on the product marketing team at RSA and is focused on the evolution of the SOC and RSA’s solutions which help SOC analysts be more effective and efficient in their jobs. You can follow him on twitter @jmatthewg1234.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;t=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics%20-%20http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=It%20is%20a%20well%20known%20that%20if%20you%20want%20someone%20or%20something%20to%20change%2C%20just%20apply%20pressure%20over%20a%20period%20of%20time.%20This%20is%20true%20for%20organizations%2C%20people%2C%20and%20even%20earthly%20matter%2C%20such%20as%20carbon%20%28diamonds%29%20and%20formerly%20living%20plants%20%28hydrocarbons%29.%20Markets%20also%20transform%20when%20under%20pressure.%20I%20believe%20this%20is%20precisely%20what%20is%20happening%20to%20the%20SIEM%20market%20right%20now."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&body=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-6346')" id="sociable-post-6346" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;t=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;notes=It%20is%20a%20well%20known%20that%20if%20you%20want%20someone%20or%20something%20to%20change%2C%20just%20apply%20pressure%20over%20a%20period%20of%20time.%20This%20is%20true%20for%20organizations%2C%20people%2C%20and%20even%20earthly%20matter%2C%20such%20as%20carbon%20%28diamonds%29%20and%20formerly%20living%20plants%20%28hydrocarbons%29.%20Markets%20also%20transform%20when%20under%20pressure.%20I%20believe%20this%20is%20precisely%20what%20is%20happening%20to%20the%20SIEM%20market%20right%20now."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;bodytext=It%20is%20a%20well%20known%20that%20if%20you%20want%20someone%20or%20something%20to%20change%2C%20just%20apply%20pressure%20over%20a%20period%20of%20time.%20This%20is%20true%20for%20organizations%2C%20people%2C%20and%20even%20earthly%20matter%2C%20such%20as%20carbon%20%28diamonds%29%20and%20formerly%20living%20plants%20%28hydrocarbons%29.%20Markets%20also%20transform%20when%20under%20pressure.%20I%20believe%20this%20is%20precisely%20what%20is%20happening%20to%20the%20SIEM%20market%20right%20now."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;annotation=It%20is%20a%20well%20known%20that%20if%20you%20want%20someone%20or%20something%20to%20change%2C%20just%20apply%20pressure%20over%20a%20period%20of%20time.%20This%20is%20true%20for%20organizations%2C%20people%2C%20and%20even%20earthly%20matter%2C%20such%20as%20carbon%20%28diamonds%29%20and%20formerly%20living%20plants%20%28hydrocarbons%29.%20Markets%20also%20transform%20when%20under%20pressure.%20I%20believe%20this%20is%20precisely%20what%20is%20happening%20to%20the%20SIEM%20market%20right%20now."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;t=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=It%20is%20a%20well%20known%20that%20if%20you%20want%20someone%20or%20something%20to%20change%2C%20just%20apply%20pressure%20over%20a%20period%20of%20time.%20This%20is%20true%20for%20organizations%2C%20people%2C%20and%20even%20earthly%20matter%2C%20such%20as%20carbon%20%28diamonds%29%20and%20formerly%20living%20plants%20%28hydrocarbons%29.%20Markets%20also%20transform%20when%20under%20pressure.%20I%20believe%20this%20is%20precisely%20what%20is%20happening%20to%20the%20SIEM%20market%20right%20now."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;Title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;selection=It%20is%20a%20well%20known%20that%20if%20you%20want%20someone%20or%20something%20to%20change%2C%20just%20apply%20pressure%20over%20a%20period%20of%20time.%20This%20is%20true%20for%20organizations%2C%20people%2C%20and%20even%20earthly%20matter%2C%20such%20as%20carbon%20%28diamonds%29%20and%20formerly%20living%20plants%20%28hydrocarbons%29.%20Markets%20also%20transform%20when%20under%20pressure.%20I%20believe%20this%20is%20precisely%20what%20is%20happening%20to%20the%20SIEM%20market%20right%20now."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;t=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;s=It%20is%20a%20well%20known%20that%20if%20you%20want%20someone%20or%20something%20to%20change%2C%20just%20apply%20pressure%20over%20a%20period%20of%20time.%20This%20is%20true%20for%20organizations%2C%20people%2C%20and%20even%20earthly%20matter%2C%20such%20as%20carbon%20%28diamonds%29%20and%20formerly%20living%20plants%20%28hydrocarbons%29.%20Markets%20also%20transform%20when%20under%20pressure.%20I%20believe%20this%20is%20precisely%20what%20is%20happening%20to%20the%20SIEM%20market%20right%20now."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;title=Apply%20Pressure%20to%20SIEM%20and%20it%20Turns%20into%20Security%20Analytics&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fapply-pressure-to-siem-and-it-turns-into-security-analytics%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-6346')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-6346',true)" class="close">

		  <img onclick="hide_sociable('post-6346',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/apply-pressure-to-siem-and-it-turns-into-security-analytics/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/apply-pressure-to-siem-and-it-turns-into-security-analytics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Knock, Knock. Who’s There? Big Data.</title>
		<link>http://blogs.rsa.com/knock-knock-whos-there-big-data/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=knock-knock-whos-there-big-data</link>
		<comments>http://blogs.rsa.com/knock-knock-whos-there-big-data/#comments</comments>
		<pubDate>Thu, 14 Jun 2012 12:30:13 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Big Data]]></category>
		<category><![CDATA[Big Data Analytics]]></category>
		<category><![CDATA[security analytics]]></category>
		<category><![CDATA[SIEM]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5457</guid>
		<description><![CDATA[I recently had the pleasure of attending the annual EMC World user conference in Las Vegas, NV. And it was, in my opinion, immensely informative, not just for me but for EMC, RSA and all of its partners and customers. The sessions and Solutions Pavilion were lively and engaging, the keynotes had the production value worthy of most Hollywood movies and the topics were relevant for today’s IT and security managers.]]></description>
				<content:encoded><![CDATA[<p><em>Barrett Mononen – Sr. Product Marketing Manager, Security Analytics, RSA</em></p>
<p>I recently had the pleasure of attending the annual EMC World user conference in Las Vegas, NV. And it was, in my opinion, immensely informative, not just for me but for EMC, RSA and all of its partners and customers. The sessions and Solutions Pavilion were lively and engaging, <strong><span style="text-decoration: underline;"><a href="http://http://emcworld.com/emctv.html?live=true">the keynotes</a></span> </strong>had the production value worthy of most Hollywood movies and the topics were relevant for today’s IT and security managers.</p>
<p>What truly stood out to me was the strong sense that this era of “big data” is no longer just a marketing phrase or jargon about a future state of the industry. The challenge and opportunity of Big Data is here and now. In session after session EMC’s partners and customers discussed the data sets they are managing. The sheer size was staggering. My favorite example was during a session entitled &#8220;Chad’s World&#8221; with <span style="text-decoration: underline;"><strong><a href="http://virtualgeek.typepad.com">Chad Sakac</a></strong></span>. He had with him an EMC customer, Los Alamos National Lab, who was responsible for running nuclear missile detonation simulations. When asked what his data set size typically was he calmly responded, “Somewhere around an Exabyte”.</p>
<p>An Exabyte! (That’s 1,000 petabytes for those counting at home). On top of it all both Joe Tucci and <strong><span style="text-decoration: underline;"><a href="https://twitter.com/#!/jburton">Jeremy Burton</a></span></strong> mentioned in their keynotes that it’s no longer a question of big data – it’s about big FAST data.</p>
<p>So our security tools must adapt to support this new paradigm. IT infrastructure is no longer application centric – its user and data centric. There are no hard and fast perimeters, the enterprise is boundless. These types of infrastructures create mountains of data. This means that having security solutions capable of big data analytics is more important than ever. To take it further, security solutions capable of predictive analytics, to help wade through the mountain of data.</p>
<p>In my <span style="text-decoration: underline;"><strong><a href="http://blogs.rsa.com/smi/stop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet/">previous blog</a></strong>,</span> I talked about the tactic of removing the hay from the haystack in order to find “security incident” needles more easily. Think about the types of solution(s) that would be able to sift through petabytes of data, filtering to remove known good and intelligently prioritizing the data you need – all with the end goal of finding the tiniest piece of evidence that something is awry. It would take a solution built from the ground up for security, speed and massive data sets. A tool with predictive analytics, real-time access to relevant data and the scale required for the ‘big data’ security world.</p>
<p>And guess what? These are no longer the solutions only for the bleeding edge innovators – these are the tools of today, the tools of our trade, the solutions that you need.</p>
<p><em>Barrett is a member of the product marketing team focused on the evolution of RSA’s SIEM and security analysis portfolio and is always looking to bring fresh “insights” to the security management landscape.  Outside of work you can find Barrett at the top of the closest mountain or running his legs off in the nearest road race.</em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;t=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data."></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.%20-%20http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=I%20recently%20had%20the%20pleasure%20of%20attending%20the%20annual%20EMC%20World%20user%20conference%20in%20Las%20Vegas%2C%20NV.%20And%20it%20was%2C%20in%20my%20opinion%2C%20immensely%20informative%2C%20not%20just%20for%20me%20but%20for%20EMC%2C%20RSA%20and%20all%20of%20its%20partners%20and%20customers.%20The%20sessions%20and%20Solutions%20Pavilion%20were%20lively%20and%20engaging%2C%20the%20keynotes%20had%20the%20production%20value%20worthy%20of%20most%20Hollywood%20movies%20and%20the%20topics%20were%20relevant%20for%20today%E2%80%99s%20IT%20and%20security%20managers."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&body=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5457')" id="sociable-post-5457" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;t=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data."></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;notes=I%20recently%20had%20the%20pleasure%20of%20attending%20the%20annual%20EMC%20World%20user%20conference%20in%20Las%20Vegas%2C%20NV.%20And%20it%20was%2C%20in%20my%20opinion%2C%20immensely%20informative%2C%20not%20just%20for%20me%20but%20for%20EMC%2C%20RSA%20and%20all%20of%20its%20partners%20and%20customers.%20The%20sessions%20and%20Solutions%20Pavilion%20were%20lively%20and%20engaging%2C%20the%20keynotes%20had%20the%20production%20value%20worthy%20of%20most%20Hollywood%20movies%20and%20the%20topics%20were%20relevant%20for%20today%E2%80%99s%20IT%20and%20security%20managers."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;bodytext=I%20recently%20had%20the%20pleasure%20of%20attending%20the%20annual%20EMC%20World%20user%20conference%20in%20Las%20Vegas%2C%20NV.%20And%20it%20was%2C%20in%20my%20opinion%2C%20immensely%20informative%2C%20not%20just%20for%20me%20but%20for%20EMC%2C%20RSA%20and%20all%20of%20its%20partners%20and%20customers.%20The%20sessions%20and%20Solutions%20Pavilion%20were%20lively%20and%20engaging%2C%20the%20keynotes%20had%20the%20production%20value%20worthy%20of%20most%20Hollywood%20movies%20and%20the%20topics%20were%20relevant%20for%20today%E2%80%99s%20IT%20and%20security%20managers."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data."></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data."></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;annotation=I%20recently%20had%20the%20pleasure%20of%20attending%20the%20annual%20EMC%20World%20user%20conference%20in%20Las%20Vegas%2C%20NV.%20And%20it%20was%2C%20in%20my%20opinion%2C%20immensely%20informative%2C%20not%20just%20for%20me%20but%20for%20EMC%2C%20RSA%20and%20all%20of%20its%20partners%20and%20customers.%20The%20sessions%20and%20Solutions%20Pavilion%20were%20lively%20and%20engaging%2C%20the%20keynotes%20had%20the%20production%20value%20worthy%20of%20most%20Hollywood%20movies%20and%20the%20topics%20were%20relevant%20for%20today%E2%80%99s%20IT%20and%20security%20managers."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;t=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data."></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=I%20recently%20had%20the%20pleasure%20of%20attending%20the%20annual%20EMC%20World%20user%20conference%20in%20Las%20Vegas%2C%20NV.%20And%20it%20was%2C%20in%20my%20opinion%2C%20immensely%20informative%2C%20not%20just%20for%20me%20but%20for%20EMC%2C%20RSA%20and%20all%20of%20its%20partners%20and%20customers.%20The%20sessions%20and%20Solutions%20Pavilion%20were%20lively%20and%20engaging%2C%20the%20keynotes%20had%20the%20production%20value%20worthy%20of%20most%20Hollywood%20movies%20and%20the%20topics%20were%20relevant%20for%20today%E2%80%99s%20IT%20and%20security%20managers."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;Title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data."></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;selection=I%20recently%20had%20the%20pleasure%20of%20attending%20the%20annual%20EMC%20World%20user%20conference%20in%20Las%20Vegas%2C%20NV.%20And%20it%20was%2C%20in%20my%20opinion%2C%20immensely%20informative%2C%20not%20just%20for%20me%20but%20for%20EMC%2C%20RSA%20and%20all%20of%20its%20partners%20and%20customers.%20The%20sessions%20and%20Solutions%20Pavilion%20were%20lively%20and%20engaging%2C%20the%20keynotes%20had%20the%20production%20value%20worthy%20of%20most%20Hollywood%20movies%20and%20the%20topics%20were%20relevant%20for%20today%E2%80%99s%20IT%20and%20security%20managers."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;t=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;s=I%20recently%20had%20the%20pleasure%20of%20attending%20the%20annual%20EMC%20World%20user%20conference%20in%20Las%20Vegas%2C%20NV.%20And%20it%20was%2C%20in%20my%20opinion%2C%20immensely%20informative%2C%20not%20just%20for%20me%20but%20for%20EMC%2C%20RSA%20and%20all%20of%20its%20partners%20and%20customers.%20The%20sessions%20and%20Solutions%20Pavilion%20were%20lively%20and%20engaging%2C%20the%20keynotes%20had%20the%20production%20value%20worthy%20of%20most%20Hollywood%20movies%20and%20the%20topics%20were%20relevant%20for%20today%E2%80%99s%20IT%20and%20security%20managers."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;title=Knock%2C%20Knock.%20Who%E2%80%99s%20There%3F%20Big%20Data.&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fknock-knock-whos-there-big-data%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5457')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5457',true)" class="close">

		  <img onclick="hide_sociable('post-5457',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/knock-knock-whos-there-big-data/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/knock-knock-whos-there-big-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enhancing Security Controls Using RSA Solutions with Microsoft Windows Server 2012</title>
		<link>http://blogs.rsa.com/enhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=enhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2</link>
		<comments>http://blogs.rsa.com/enhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2/#comments</comments>
		<pubDate>Mon, 11 Jun 2012 16:00:00 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Data Loss Prevention]]></category>
		<category><![CDATA[Enterprise Security]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5392</guid>
		<description><![CDATA[By Matthew Gardiner, Sr. Manager, RSA Unless you have been hiding under a rock in another universe, you are aware that Microsoft is soon to be releasing the latest major round of the Windows franchise, namely Windows 8 and its cousin Windows Server 2012. In fact at the upcoming TechEd North America 2012, this latest [...]]]></description>
				<content:encoded><![CDATA[<p>By Matthew Gardiner, Sr. Manager, RSA</p>
<p>Unless you have been hiding under a rock in another universe, you are aware that Microsoft is soon to be releasing the latest major round of the Windows franchise, namely Windows 8 and its cousin Windows Server 2012. In fact at the upcoming <a href="http://northamerica.msteched.com/#fbid=AHw9pA6tpwq">TechEd North America 2012</a>, this latest version of Windows will have a very prominent role in the conference content. This brings me to the point of this blog entry. How can these new versions of Windows, in particular Windows Server 2012, improve the security profile of the organization that uses it? And how is RSA extending this security value even further through upcoming product integrations with Windows Server 2012?</p>
<p>A good place to start your Windows Server 2012 security education is on the <a href="http://technet.microsoft.com/en-us/library/hh801901">Windows Server 2012 portion of Technet</a>. For the purposes of this blog, specifically check out the area of Technet which explains <a href="http://technet.microsoft.com/en-us/library/hh831717">Dynamic Access Control</a> (DAC). This is a new set of capabilities for Windows Server 2012 that enhances data governance by enabling more granular access enforcement and audit visibility.</p>
<p>The Windows Server 2012 DAC is a natural touch point for multiple RSA security management technologies, specifically <a href="http://www.emc.com/security/rsa-netwitness.htm">RSA NetWitness</a> and <a href="http://www.emc.com/security/rsa-data-loss-prevention.htm">RSA Data Loss Prevention</a> (DLP) to name a couple. At TechEd 2012 RSA will be demonstrating a real life scenario where Windows Server 2012 audit information is used to discover an internal user “gone bad” using the investigative capabilities of NetWitness. The increased level of security visibility enabled through the integrated use of NetWitness and Windows Server 2012 with the DAC is but one example of how the combination of RSA technology and Windows 2012 will make sensitive data “spills” less likely.</p>
<p>In addition to developing integration with NetWitness, RSA is also working on leveraging the Dynamic Access Control capability of Windows to better find and block misuse of sensitive information. This part of the story brings together RSA DLP and Windows Server 2012/DAC. Leveraging upcoming integration RSA DLP will be able to more easily find sensitive information so that it can track it, initiate remediation, block its movement outside the enterprise, force encryption, or all of the above. The bottom line, is as Microsoft moves forward with its enterprise infrastructure so RSA moves forward in collaboration with Microsoft to deliver more effective and efficient security controls.</p>
<p>Matthew Gardiner is on the product marketing team at RSA and is focused on the evolution of the SOC and RSA’s solutions which help SOC analysts be more effective and efficient in their jobs. You can follow him on twitter @jmatthewg1234.</p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;t=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012%20-%20http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=By%20Matthew%20Gardiner%2C%20Sr.%20Manager%2C%20RSA%0D%0A%0D%0AUnless%20you%20have%20been%20hiding%20under%20a%20rock%20in%20another%20universe%2C%20you%20are%20aware%20that%20Microsoft%20is%20soon%20to%20be%20releasing%20the%20latest%20major%20round%20of%20the%20Windows%20franchise%2C%20namely%20Windows%208%20and%20its%20cousin%20Windows%20Serve"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&body=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5392')" id="sociable-post-5392" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;t=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;notes=By%20Matthew%20Gardiner%2C%20Sr.%20Manager%2C%20RSA%0D%0A%0D%0AUnless%20you%20have%20been%20hiding%20under%20a%20rock%20in%20another%20universe%2C%20you%20are%20aware%20that%20Microsoft%20is%20soon%20to%20be%20releasing%20the%20latest%20major%20round%20of%20the%20Windows%20franchise%2C%20namely%20Windows%208%20and%20its%20cousin%20Windows%20Serve"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;bodytext=By%20Matthew%20Gardiner%2C%20Sr.%20Manager%2C%20RSA%0D%0A%0D%0AUnless%20you%20have%20been%20hiding%20under%20a%20rock%20in%20another%20universe%2C%20you%20are%20aware%20that%20Microsoft%20is%20soon%20to%20be%20releasing%20the%20latest%20major%20round%20of%20the%20Windows%20franchise%2C%20namely%20Windows%208%20and%20its%20cousin%20Windows%20Serve"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;annotation=By%20Matthew%20Gardiner%2C%20Sr.%20Manager%2C%20RSA%0D%0A%0D%0AUnless%20you%20have%20been%20hiding%20under%20a%20rock%20in%20another%20universe%2C%20you%20are%20aware%20that%20Microsoft%20is%20soon%20to%20be%20releasing%20the%20latest%20major%20round%20of%20the%20Windows%20franchise%2C%20namely%20Windows%208%20and%20its%20cousin%20Windows%20Serve"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;t=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=By%20Matthew%20Gardiner%2C%20Sr.%20Manager%2C%20RSA%0D%0A%0D%0AUnless%20you%20have%20been%20hiding%20under%20a%20rock%20in%20another%20universe%2C%20you%20are%20aware%20that%20Microsoft%20is%20soon%20to%20be%20releasing%20the%20latest%20major%20round%20of%20the%20Windows%20franchise%2C%20namely%20Windows%208%20and%20its%20cousin%20Windows%20Serve"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;Title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;selection=By%20Matthew%20Gardiner%2C%20Sr.%20Manager%2C%20RSA%0D%0A%0D%0AUnless%20you%20have%20been%20hiding%20under%20a%20rock%20in%20another%20universe%2C%20you%20are%20aware%20that%20Microsoft%20is%20soon%20to%20be%20releasing%20the%20latest%20major%20round%20of%20the%20Windows%20franchise%2C%20namely%20Windows%208%20and%20its%20cousin%20Windows%20Serve"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;t=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;s=By%20Matthew%20Gardiner%2C%20Sr.%20Manager%2C%20RSA%0D%0A%0D%0AUnless%20you%20have%20been%20hiding%20under%20a%20rock%20in%20another%20universe%2C%20you%20are%20aware%20that%20Microsoft%20is%20soon%20to%20be%20releasing%20the%20latest%20major%20round%20of%20the%20Windows%20franchise%2C%20namely%20Windows%208%20and%20its%20cousin%20Windows%20Serve"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;title=Enhancing%20Security%20Controls%20Using%20RSA%20Solutions%20with%20Microsoft%20Windows%20Server%202012&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fenhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5392')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5392',true)" class="close">

		  <img onclick="hide_sociable('post-5392',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/enhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/enhancing-security-controls-using-rsa-solutions-with-microsoft-windows-server-2012-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Transforming From the Hunted to the Hunter</title>
		<link>http://blogs.rsa.com/transforming-from-the-hunted-to-the-hunter/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=transforming-from-the-hunted-to-the-hunter</link>
		<comments>http://blogs.rsa.com/transforming-from-the-hunted-to-the-hunter/#comments</comments>
		<pubDate>Fri, 08 Jun 2012 12:30:10 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Cybercrime and Fraud]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5254</guid>
		<description><![CDATA[I recently watched the 1932 movie The Most Dangerous Game which was adapted from a short story written by Richard Connell.  In short, the story is about a young man, Bob Rainsford, who is ship wrecked on an isolated Pacific island run by a rich, crazy, yet wily Russian Count named Zaroff.  Zaroff’s favorite hobby is to hunt big game, in particular human game that was amply supplied by ship wrecked people that washed up on his island.  Typically the Count didn’t have too much trouble bagging his human game.  After all how long and how far can one run on an island?  However, the hunt of Bob Rainsford (and Fay Ray – of King Kong fame - as his helpless love interest) went very differently.  Bob, being an experienced hunter himself, used his skills and guile to turn the table on Zaroff.  The hunted became the hunter.  Let’s just say it didn’t end well for Zaroff.]]></description>
				<content:encoded><![CDATA[<p>I recently watched the 1932 movie The Most Dangerous Game which was adapted from a short story written by Richard Connell.  In short, the story is about a young man, Bob Rainsford, who is ship wrecked on an isolated Pacific island run by a rich, crazy, yet wily Russian Count named Zaroff.  Zaroff’s favorite hobby is to hunt big game, in particular human game that was amply supplied by ship wrecked people that washed up on his island.</p>
<p>Typically the Count didn’t have too much trouble bagging his human game.  After all how long and how far can one run on an island?  However, the hunt of Bob Rainsford (and Fay Ray – of King Kong fame &#8211; as his helpless love interest) went very differently.  Bob, being an experienced hunter himself, used his skills and guile to turn the table on Zaroff.  The hunted became the hunter.  Let’s just say it didn’t end well for Zaroff.</p>
<p>This story actually relates directly to organizations and the security departments that digitally protect them.</p>
<p>For too long, too many organizations have been like most people on Zaroff’s island, they ran and hid “digitally” for as long as they could, but ultimately were found and breached by persistent computer attackers.  Defensive measures can’t keep organizations completely safe, these alone are akin to running and hiding.  What leading organizations are now doing, with the help of RSA and others, is to turn the tables and transform from hunted to hunter.</p>
<p>In this case they are hunting with a combination of powerful detective tools, threat intelligence, big data analytics, and deep security “big game” expertise. I think of the perfect SOC analyst as being the Bob Rainsford of their organizations.  The SOC analyst being every bit as good and as aggressive as their digital attackers.  They lay traps and monitor the attackers long before the attackers realize it.  Of course in the digital world no one is fed to the dogs in the end (as far as I know), but just the psychological lift of transforming from hunted to hunter should positively impact the security of organizations that make the switch.  If nothing else it should make the job of a SOC analyst more fun.</p>
<p><em>Matthew Gardiner is on the product marketing team at RSA and is focused on the evolution of the SOC and RSA’s solutions which help SOC analysts be more effective and efficient in their jobs.  You can follow him on twitter @jmatthewg1234.</em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;t=Transforming%20From%20the%20Hunted%20to%20the%20Hunter"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Transforming%20From%20the%20Hunted%20to%20the%20Hunter%20-%20http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=I%20recently%20watched%20the%201932%20movie%20The%20Most%20Dangerous%20Game%20which%20was%20adapted%20from%20a%20short%20story%20written%20by%20Richard%20Connell.%20%20In%20short%2C%20the%20story%20is%20about%20a%20young%20man%2C%20Bob%20Rainsford%2C%20who%20is%20ship%20wrecked%20on%20an%20isolated%20Pacific%20island%20run%20by%20a%20rich%2C%20crazy%2C%20yet%20wily%20Russian%20Count%20named%20Zaroff.%20%20Zaroff%E2%80%99s%20favorite%20hobby%20is%20to%20hunt%20big%20game%2C%20in%20particular%20human%20game%20that%20was%20amply%20supplied%20by%20ship%20wrecked%20people%20that%20washed%20up%20on%20his%20island.%20%20Typically%20the%20Count%20didn%E2%80%99t%20have%20too%20much%20trouble%20bagging%20his%20human%20game.%20%20After%20all%20how%20long%20and%20how%20far%20can%20one%20run%20on%20an%20island%3F%20%20However%2C%20the%20hunt%20of%20Bob%20Rainsford%20%28and%20Fay%20Ray%20%E2%80%93%20of%20King%20Kong%20fame%20-%20as%20his%20helpless%20love%20interest%29%20went%20very%20differently.%20%20Bob%2C%20being%20an%20experienced%20hunter%20himself%2C%20used%20his%20skills%20and%20guile%20to%20turn%20the%20table%20on%20Zaroff.%20%20The%20hunted%20became%20the%20hunter.%20%20Let%E2%80%99s%20just%20say%20it%20didn%E2%80%99t%20end%20well%20for%20Zaroff."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&body=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5254')" id="sociable-post-5254" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;t=Transforming%20From%20the%20Hunted%20to%20the%20Hunter"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;notes=I%20recently%20watched%20the%201932%20movie%20The%20Most%20Dangerous%20Game%20which%20was%20adapted%20from%20a%20short%20story%20written%20by%20Richard%20Connell.%20%20In%20short%2C%20the%20story%20is%20about%20a%20young%20man%2C%20Bob%20Rainsford%2C%20who%20is%20ship%20wrecked%20on%20an%20isolated%20Pacific%20island%20run%20by%20a%20rich%2C%20crazy%2C%20yet%20wily%20Russian%20Count%20named%20Zaroff.%20%20Zaroff%E2%80%99s%20favorite%20hobby%20is%20to%20hunt%20big%20game%2C%20in%20particular%20human%20game%20that%20was%20amply%20supplied%20by%20ship%20wrecked%20people%20that%20washed%20up%20on%20his%20island.%20%20Typically%20the%20Count%20didn%E2%80%99t%20have%20too%20much%20trouble%20bagging%20his%20human%20game.%20%20After%20all%20how%20long%20and%20how%20far%20can%20one%20run%20on%20an%20island%3F%20%20However%2C%20the%20hunt%20of%20Bob%20Rainsford%20%28and%20Fay%20Ray%20%E2%80%93%20of%20King%20Kong%20fame%20-%20as%20his%20helpless%20love%20interest%29%20went%20very%20differently.%20%20Bob%2C%20being%20an%20experienced%20hunter%20himself%2C%20used%20his%20skills%20and%20guile%20to%20turn%20the%20table%20on%20Zaroff.%20%20The%20hunted%20became%20the%20hunter.%20%20Let%E2%80%99s%20just%20say%20it%20didn%E2%80%99t%20end%20well%20for%20Zaroff."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;bodytext=I%20recently%20watched%20the%201932%20movie%20The%20Most%20Dangerous%20Game%20which%20was%20adapted%20from%20a%20short%20story%20written%20by%20Richard%20Connell.%20%20In%20short%2C%20the%20story%20is%20about%20a%20young%20man%2C%20Bob%20Rainsford%2C%20who%20is%20ship%20wrecked%20on%20an%20isolated%20Pacific%20island%20run%20by%20a%20rich%2C%20crazy%2C%20yet%20wily%20Russian%20Count%20named%20Zaroff.%20%20Zaroff%E2%80%99s%20favorite%20hobby%20is%20to%20hunt%20big%20game%2C%20in%20particular%20human%20game%20that%20was%20amply%20supplied%20by%20ship%20wrecked%20people%20that%20washed%20up%20on%20his%20island.%20%20Typically%20the%20Count%20didn%E2%80%99t%20have%20too%20much%20trouble%20bagging%20his%20human%20game.%20%20After%20all%20how%20long%20and%20how%20far%20can%20one%20run%20on%20an%20island%3F%20%20However%2C%20the%20hunt%20of%20Bob%20Rainsford%20%28and%20Fay%20Ray%20%E2%80%93%20of%20King%20Kong%20fame%20-%20as%20his%20helpless%20love%20interest%29%20went%20very%20differently.%20%20Bob%2C%20being%20an%20experienced%20hunter%20himself%2C%20used%20his%20skills%20and%20guile%20to%20turn%20the%20table%20on%20Zaroff.%20%20The%20hunted%20became%20the%20hunter.%20%20Let%E2%80%99s%20just%20say%20it%20didn%E2%80%99t%20end%20well%20for%20Zaroff."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;annotation=I%20recently%20watched%20the%201932%20movie%20The%20Most%20Dangerous%20Game%20which%20was%20adapted%20from%20a%20short%20story%20written%20by%20Richard%20Connell.%20%20In%20short%2C%20the%20story%20is%20about%20a%20young%20man%2C%20Bob%20Rainsford%2C%20who%20is%20ship%20wrecked%20on%20an%20isolated%20Pacific%20island%20run%20by%20a%20rich%2C%20crazy%2C%20yet%20wily%20Russian%20Count%20named%20Zaroff.%20%20Zaroff%E2%80%99s%20favorite%20hobby%20is%20to%20hunt%20big%20game%2C%20in%20particular%20human%20game%20that%20was%20amply%20supplied%20by%20ship%20wrecked%20people%20that%20washed%20up%20on%20his%20island.%20%20Typically%20the%20Count%20didn%E2%80%99t%20have%20too%20much%20trouble%20bagging%20his%20human%20game.%20%20After%20all%20how%20long%20and%20how%20far%20can%20one%20run%20on%20an%20island%3F%20%20However%2C%20the%20hunt%20of%20Bob%20Rainsford%20%28and%20Fay%20Ray%20%E2%80%93%20of%20King%20Kong%20fame%20-%20as%20his%20helpless%20love%20interest%29%20went%20very%20differently.%20%20Bob%2C%20being%20an%20experienced%20hunter%20himself%2C%20used%20his%20skills%20and%20guile%20to%20turn%20the%20table%20on%20Zaroff.%20%20The%20hunted%20became%20the%20hunter.%20%20Let%E2%80%99s%20just%20say%20it%20didn%E2%80%99t%20end%20well%20for%20Zaroff."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;t=Transforming%20From%20the%20Hunted%20to%20the%20Hunter"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=I%20recently%20watched%20the%201932%20movie%20The%20Most%20Dangerous%20Game%20which%20was%20adapted%20from%20a%20short%20story%20written%20by%20Richard%20Connell.%20%20In%20short%2C%20the%20story%20is%20about%20a%20young%20man%2C%20Bob%20Rainsford%2C%20who%20is%20ship%20wrecked%20on%20an%20isolated%20Pacific%20island%20run%20by%20a%20rich%2C%20crazy%2C%20yet%20wily%20Russian%20Count%20named%20Zaroff.%20%20Zaroff%E2%80%99s%20favorite%20hobby%20is%20to%20hunt%20big%20game%2C%20in%20particular%20human%20game%20that%20was%20amply%20supplied%20by%20ship%20wrecked%20people%20that%20washed%20up%20on%20his%20island.%20%20Typically%20the%20Count%20didn%E2%80%99t%20have%20too%20much%20trouble%20bagging%20his%20human%20game.%20%20After%20all%20how%20long%20and%20how%20far%20can%20one%20run%20on%20an%20island%3F%20%20However%2C%20the%20hunt%20of%20Bob%20Rainsford%20%28and%20Fay%20Ray%20%E2%80%93%20of%20King%20Kong%20fame%20-%20as%20his%20helpless%20love%20interest%29%20went%20very%20differently.%20%20Bob%2C%20being%20an%20experienced%20hunter%20himself%2C%20used%20his%20skills%20and%20guile%20to%20turn%20the%20table%20on%20Zaroff.%20%20The%20hunted%20became%20the%20hunter.%20%20Let%E2%80%99s%20just%20say%20it%20didn%E2%80%99t%20end%20well%20for%20Zaroff."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;Title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;selection=I%20recently%20watched%20the%201932%20movie%20The%20Most%20Dangerous%20Game%20which%20was%20adapted%20from%20a%20short%20story%20written%20by%20Richard%20Connell.%20%20In%20short%2C%20the%20story%20is%20about%20a%20young%20man%2C%20Bob%20Rainsford%2C%20who%20is%20ship%20wrecked%20on%20an%20isolated%20Pacific%20island%20run%20by%20a%20rich%2C%20crazy%2C%20yet%20wily%20Russian%20Count%20named%20Zaroff.%20%20Zaroff%E2%80%99s%20favorite%20hobby%20is%20to%20hunt%20big%20game%2C%20in%20particular%20human%20game%20that%20was%20amply%20supplied%20by%20ship%20wrecked%20people%20that%20washed%20up%20on%20his%20island.%20%20Typically%20the%20Count%20didn%E2%80%99t%20have%20too%20much%20trouble%20bagging%20his%20human%20game.%20%20After%20all%20how%20long%20and%20how%20far%20can%20one%20run%20on%20an%20island%3F%20%20However%2C%20the%20hunt%20of%20Bob%20Rainsford%20%28and%20Fay%20Ray%20%E2%80%93%20of%20King%20Kong%20fame%20-%20as%20his%20helpless%20love%20interest%29%20went%20very%20differently.%20%20Bob%2C%20being%20an%20experienced%20hunter%20himself%2C%20used%20his%20skills%20and%20guile%20to%20turn%20the%20table%20on%20Zaroff.%20%20The%20hunted%20became%20the%20hunter.%20%20Let%E2%80%99s%20just%20say%20it%20didn%E2%80%99t%20end%20well%20for%20Zaroff."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;t=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;s=I%20recently%20watched%20the%201932%20movie%20The%20Most%20Dangerous%20Game%20which%20was%20adapted%20from%20a%20short%20story%20written%20by%20Richard%20Connell.%20%20In%20short%2C%20the%20story%20is%20about%20a%20young%20man%2C%20Bob%20Rainsford%2C%20who%20is%20ship%20wrecked%20on%20an%20isolated%20Pacific%20island%20run%20by%20a%20rich%2C%20crazy%2C%20yet%20wily%20Russian%20Count%20named%20Zaroff.%20%20Zaroff%E2%80%99s%20favorite%20hobby%20is%20to%20hunt%20big%20game%2C%20in%20particular%20human%20game%20that%20was%20amply%20supplied%20by%20ship%20wrecked%20people%20that%20washed%20up%20on%20his%20island.%20%20Typically%20the%20Count%20didn%E2%80%99t%20have%20too%20much%20trouble%20bagging%20his%20human%20game.%20%20After%20all%20how%20long%20and%20how%20far%20can%20one%20run%20on%20an%20island%3F%20%20However%2C%20the%20hunt%20of%20Bob%20Rainsford%20%28and%20Fay%20Ray%20%E2%80%93%20of%20King%20Kong%20fame%20-%20as%20his%20helpless%20love%20interest%29%20went%20very%20differently.%20%20Bob%2C%20being%20an%20experienced%20hunter%20himself%2C%20used%20his%20skills%20and%20guile%20to%20turn%20the%20table%20on%20Zaroff.%20%20The%20hunted%20became%20the%20hunter.%20%20Let%E2%80%99s%20just%20say%20it%20didn%E2%80%99t%20end%20well%20for%20Zaroff."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;title=Transforming%20From%20the%20Hunted%20to%20the%20Hunter&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Ftransforming-from-the-hunted-to-the-hunter%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5254')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5254',true)" class="close">

		  <img onclick="hide_sociable('post-5254',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/transforming-from-the-hunted-to-the-hunter/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/transforming-from-the-hunted-to-the-hunter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stop climbing through the haystack to find the needle: Use a magnet</title>
		<link>http://blogs.rsa.com/stop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=stop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet</link>
		<comments>http://blogs.rsa.com/stop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet/#comments</comments>
		<pubDate>Wed, 16 May 2012 16:30:48 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Big data]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5134</guid>
		<description><![CDATA[As security professionals we are constantly thinking about finding the needle (security incident) in the data haystack.  But what if just used a really powerful magnet?  Potential threats are more targeted, stealthy and dynamic than they ever have been.    Which means you won’t find the needle if you aren’t collecting the hay in which the needle may be hiding.  So, it’s more than just collecting a lot of data, it’s about collecting the right data.]]></description>
				<content:encoded><![CDATA[<p><em>by Barrett Mononen – Sr. Product Marketing Manager, RSA</em></p>
<p>A few weekends back I had the pleasure of going to the local children’s museum with a young nephew of mine. One of the attractions was a magnet from an old air craft carrier’s radar system –it was huge and really powerful. The sign explained what it was and joked, “Finding a needle in the haystack isn’t hard with this.”</p>
<p>This got me thinking. As security professionals we are constantly thinking about finding the needle (security incident) in the data haystack. But what if we just used a really powerful magnet? The needle in this case is the tiniest piece of evidence that an adversary is traversing your network or attempting to inflict digital damage and the haystack represents the mountain of innocuous data that the needle is hidden within. And in the era of big data that haystack isn’t getting any smaller.</p>
<p>The data a typical security analyst has to look at is growing by the second: Logs, packets, critical IT assets, threat intelligence, event data, and data classification feeds, to name some key ones. And on top of that, attackers are getting better at disguising their needles. Potential threats are more targeted, stealthy and dynamic than they have ever been. Which means you won’t find the needle if you aren’t collecting the hay in which the needle may be hiding. So, it’s more than just collecting <em>a lot</em> of data, it’s about collecting the <em>right </em> data. This means log collection AND full packet capture, it means external threat intelligence applied to this data to help identify previously unknown attack sequences and it means enabling analysis on all of this data to help detect threats without signatures.</p>
<blockquote>
<h3 style="text-align: center;"><span style="color: #ff0000;">&#8220;It’s more than just collecting <em>a lot</em> of data, it’s about collecting the <em>right </em> data.&#8221;</span></h3>
</blockquote>
<p>The haystack is growing, the needles are getting smaller, yet more damaging and we’re collecting lots of (the right) data. Now what?</p>
<p>Must be time for the really big magnet, right? Well, not exactly. A lot of organizations have started down that path, but it&#8217;s more than just buying the right magnet. It’s about pointing that magnet at the right sized haystack. To put it more realistically, how about we use tactics to remove a lot of the hay and make our existing “magnets” more powerful? This could make the haystacks more manageable.</p>
<p>Tactics can be applied like removing items within your data set that you know are “good” – or not threatening – to reveal items that have a higher probability of being ”bad”. This method, sometimes called data or traffic carving, can be an incredibly valuable tool. Start a new investigation where you aren’t looking for anything in particular – just looking to remove things you know are good, normal or OK activity. I’ll bet you’ll be surprised at what is left behind – at the very least some activity that is hard to explain.</p>
<p>Now I’m sure we all wish we had an aircraft carrier-sized magnet to find the needle in a haystack, but using the right tactics in combination with stronger tools can actually improve your results.</p>
<p><em>Barrett is a member of the product marketing team focused on the evolution of RSA&#8217;s SIEM and security analysis portfolio and is always looking to bring fresh “insights” to the security management landscape.  Outside of work you can find Barrett at the top of the closest mountain or running his legs off in the nearest road race.</em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;t=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet%20-%20http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=As%20security%20professionals%20we%20are%20constantly%20thinking%20about%20finding%20the%20needle%20%28security%20incident%29%20in%20the%20data%20haystack.%20%20But%20what%20if%20just%20used%20a%20really%20powerful%20magnet%3F%20%20Potential%20threats%20are%20more%20targeted%2C%20stealthy%20and%20dynamic%20than%20they%20ever%20have%20been.%20%20%20%20Which%20means%20you%20won%E2%80%99t%20find%20the%20needle%20if%20you%20aren%E2%80%99t%20collecting%20the%20hay%20in%20which%20the%20needle%20may%20be%20hiding.%20%20So%2C%20it%E2%80%99s%20more%20than%20just%20collecting%20a%20lot%20of%20data%2C%20it%E2%80%99s%20about%20collecting%20the%20right%20data."></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&body=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5134')" id="sociable-post-5134" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;t=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;notes=As%20security%20professionals%20we%20are%20constantly%20thinking%20about%20finding%20the%20needle%20%28security%20incident%29%20in%20the%20data%20haystack.%20%20But%20what%20if%20just%20used%20a%20really%20powerful%20magnet%3F%20%20Potential%20threats%20are%20more%20targeted%2C%20stealthy%20and%20dynamic%20than%20they%20ever%20have%20been.%20%20%20%20Which%20means%20you%20won%E2%80%99t%20find%20the%20needle%20if%20you%20aren%E2%80%99t%20collecting%20the%20hay%20in%20which%20the%20needle%20may%20be%20hiding.%20%20So%2C%20it%E2%80%99s%20more%20than%20just%20collecting%20a%20lot%20of%20data%2C%20it%E2%80%99s%20about%20collecting%20the%20right%20data."></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;bodytext=As%20security%20professionals%20we%20are%20constantly%20thinking%20about%20finding%20the%20needle%20%28security%20incident%29%20in%20the%20data%20haystack.%20%20But%20what%20if%20just%20used%20a%20really%20powerful%20magnet%3F%20%20Potential%20threats%20are%20more%20targeted%2C%20stealthy%20and%20dynamic%20than%20they%20ever%20have%20been.%20%20%20%20Which%20means%20you%20won%E2%80%99t%20find%20the%20needle%20if%20you%20aren%E2%80%99t%20collecting%20the%20hay%20in%20which%20the%20needle%20may%20be%20hiding.%20%20So%2C%20it%E2%80%99s%20more%20than%20just%20collecting%20a%20lot%20of%20data%2C%20it%E2%80%99s%20about%20collecting%20the%20right%20data."></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;annotation=As%20security%20professionals%20we%20are%20constantly%20thinking%20about%20finding%20the%20needle%20%28security%20incident%29%20in%20the%20data%20haystack.%20%20But%20what%20if%20just%20used%20a%20really%20powerful%20magnet%3F%20%20Potential%20threats%20are%20more%20targeted%2C%20stealthy%20and%20dynamic%20than%20they%20ever%20have%20been.%20%20%20%20Which%20means%20you%20won%E2%80%99t%20find%20the%20needle%20if%20you%20aren%E2%80%99t%20collecting%20the%20hay%20in%20which%20the%20needle%20may%20be%20hiding.%20%20So%2C%20it%E2%80%99s%20more%20than%20just%20collecting%20a%20lot%20of%20data%2C%20it%E2%80%99s%20about%20collecting%20the%20right%20data."></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;t=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=As%20security%20professionals%20we%20are%20constantly%20thinking%20about%20finding%20the%20needle%20%28security%20incident%29%20in%20the%20data%20haystack.%20%20But%20what%20if%20just%20used%20a%20really%20powerful%20magnet%3F%20%20Potential%20threats%20are%20more%20targeted%2C%20stealthy%20and%20dynamic%20than%20they%20ever%20have%20been.%20%20%20%20Which%20means%20you%20won%E2%80%99t%20find%20the%20needle%20if%20you%20aren%E2%80%99t%20collecting%20the%20hay%20in%20which%20the%20needle%20may%20be%20hiding.%20%20So%2C%20it%E2%80%99s%20more%20than%20just%20collecting%20a%20lot%20of%20data%2C%20it%E2%80%99s%20about%20collecting%20the%20right%20data."></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;Title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;selection=As%20security%20professionals%20we%20are%20constantly%20thinking%20about%20finding%20the%20needle%20%28security%20incident%29%20in%20the%20data%20haystack.%20%20But%20what%20if%20just%20used%20a%20really%20powerful%20magnet%3F%20%20Potential%20threats%20are%20more%20targeted%2C%20stealthy%20and%20dynamic%20than%20they%20ever%20have%20been.%20%20%20%20Which%20means%20you%20won%E2%80%99t%20find%20the%20needle%20if%20you%20aren%E2%80%99t%20collecting%20the%20hay%20in%20which%20the%20needle%20may%20be%20hiding.%20%20So%2C%20it%E2%80%99s%20more%20than%20just%20collecting%20a%20lot%20of%20data%2C%20it%E2%80%99s%20about%20collecting%20the%20right%20data."></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;t=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;s=As%20security%20professionals%20we%20are%20constantly%20thinking%20about%20finding%20the%20needle%20%28security%20incident%29%20in%20the%20data%20haystack.%20%20But%20what%20if%20just%20used%20a%20really%20powerful%20magnet%3F%20%20Potential%20threats%20are%20more%20targeted%2C%20stealthy%20and%20dynamic%20than%20they%20ever%20have%20been.%20%20%20%20Which%20means%20you%20won%E2%80%99t%20find%20the%20needle%20if%20you%20aren%E2%80%99t%20collecting%20the%20hay%20in%20which%20the%20needle%20may%20be%20hiding.%20%20So%2C%20it%E2%80%99s%20more%20than%20just%20collecting%20a%20lot%20of%20data%2C%20it%E2%80%99s%20about%20collecting%20the%20right%20data."></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;title=Stop%20climbing%20through%20the%20haystack%20to%20find%20the%20needle%3A%20Use%20a%20magnet&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fstop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5134')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5134',true)" class="close">

		  <img onclick="hide_sociable('post-5134',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/stop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/stop-climbing-through-the-haystack-to-find-the-needle-use-a-magnet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Monitoring vs. EU Data Privacy – Are We Stuck?</title>
		<link>http://blogs.rsa.com/security-monitoring-vs-eu-data-privacy-are-we-stuck/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=security-monitoring-vs-eu-data-privacy-are-we-stuck</link>
		<comments>http://blogs.rsa.com/security-monitoring-vs-eu-data-privacy-are-we-stuck/#comments</comments>
		<pubDate>Tue, 08 May 2012 20:56:38 +0000</pubDate>
		<dc:creator>SMInsights</dc:creator>
				<category><![CDATA[Government & Policy]]></category>
		<category><![CDATA[Security Information and Event Management (SIEM)]]></category>
		<category><![CDATA[Security Management]]></category>
		<category><![CDATA[data privacy]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[EU data privacy]]></category>
		<category><![CDATA[security monitoring]]></category>

		<guid isPermaLink="false">http://blogs.rsa.com/?p=5073</guid>
		<description><![CDATA[Continuing on the theme from a previous blog, what if the use of state-of-the-art security technologies were believed to conflict with EU data privacy regulations? Are security professionals really to be put in the difficult position of not being able to use the most current security approaches to protect their organizations and users? Is there a way to both protect the organization and its users while respecting the rights of users to not be excessively and unreasonably monitored?]]></description>
				<content:encoded><![CDATA[<p><em>By Matthew Gardiner, Sr. Manager, RSA</em></p>
<p>Continuing on the theme from a <span style="text-decoration: underline;"><strong><a href="http://blogs.rsa.com/smi/eu-data-privacy-regulations-%E2%80%93-are-modern-security-approaches-legally-permissible/" target="_blank">previous blog</a></strong></span>, what if the use of state-of-the-art security technologies were believed to conflict with EU data privacy regulations? Are security professionals really to be put in the difficult position of not being able to use the most current security approaches to protect their organizations and users? Is there a way to both protect the organization and its users while respecting the rights of users to not be excessively and unreasonably monitored?</p>
<p>With the rapid rise of detective oriented security monitoring technologies such as data loss prevention, centralized log collection, and network forensics, security professionals, primarily from Europe, often have become stuck in the uncomfortable position of being “damned if they do and damned if they don’t.” Damned if they don’t use every available means to protect their organizations against advanced threats and damned if they do use technologies which can be construed as collecting, analyzing, and generally “seeing” the personal information and communications of employees and other users.</p>
<p>In other parts of the world, such as the USA, the conflict between security and privacy is not currently so intense and as a consequence security monitoring technologies, like those mentioned above, are in much wider use. Why? The laws and business practices are different, the culture is different, and the use of these technologies is more established. But does this mean that European organizations are destined to be ripe hunting grounds for attackers, who after all are not known for respecting the privacy rights of their victims? Are European organizations really expected to defend against advanced attacks with a hand tied behind their digital backs?</p>
<blockquote>
<h3 style="padding-left: 30px;"><strong><span style="color: #003366;"><em>&#8220;But does this mean that European organizations are destined to be ripe hunting grounds for attackers, who after all are not known for respecting the privacy rights of their victims?&#8221;</em></span></strong></h3>
</blockquote>
<p>What European organizations should do is to use advanced security technologies, but in ways that are sensitive, respectful, and compliant with the laws, culture, and practices of the countries in which they are operating. They must work closely with their data privacy officers and their workers’ councils on the why, what, when, and how of their security program to make sure it is well-designed, operated, and most importantly, understood. Security monitoring versus data privacy is a tricky question, but one that we are working on here at RSA. Being stuck is not an option.</p>
<p><em>Matthew Gardiner is on the product marketing team at RSA and is focused on the evolution of the SOC and RSA’s solutions which help SOC analysts be more effective and efficient in their jobs. You can follow him on twitter @jmatthewg1234.</em></p>
<!-- Start Sociable --><div class="sociable"><ul class='clearfix'><li><a title="Facebook" class="option1_16" style="background-position:-48px 0px" rel="nofollow" target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;t=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F"></a></li><li><a title="Twitter" class="option1_16" style="background-position:-144px -16px" rel="nofollow" target="_blank" href="http://twitter.com/intent/tweet?text=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F%20-%20http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F%20  "></a></li><li><a title="LinkedIn" class="option1_16" style="background-position:-144px 0px" rel="nofollow" target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;source=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals&amp;summary=Continuing%20on%20the%20theme%20from%20a%20previous%20blog%2C%20what%20if%20the%20use%20of%20state-of-the-art%20security%20technologies%20were%20believed%20to%20conflict%20with%20EU%20data%20privacy%20regulations%3F%20Are%20security%20professionals%20really%20to%20be%20put%20in%20the%20difficult%20position%20of%20not%20being%20able%20to%20use%20the%20most%20current%20security%20approaches%20to%20protect%20their%20organizations%20and%20users%3F%20Is%20there%20a%20way%20to%20both%20protect%20the%20organization%20and%20its%20users%20while%20respecting%20the%20rights%20of%20users%20to%20not%20be%20excessively%20and%20unreasonably%20monitored%3F"></a></li><li><a title="email" class="option1_16" style="background-position:-80px 0px" rel="nofollow" target="_blank" href="https://mail.google.com/mail/?view=cm&fs=1&to&su=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&body=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&ui=2&tf=1&shva=1"></a></li></ul><div onMouseout="fixOnMouseOut(this,event,'post-5073')" id="sociable-post-5073" style="display:none;">   

    <div style="top: auto; left: auto; display: block;" id="sociable">



		<div class="popup">

			<div class="content">

				<ul><li style="heigth:16px;width:16px"><a title="Myspace" class="option1_16" style="background-position:0px -16px" rel="nofollow" target="_blank" href="http://www.myspace.com/Modules/PostTo/Pages/?u=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;t=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F"></a></li><li style="heigth:16px;width:16px"><a title="Delicious" class="option1_16" style="background-position:-16px 0px" rel="nofollow" target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;notes=Continuing%20on%20the%20theme%20from%20a%20previous%20blog%2C%20what%20if%20the%20use%20of%20state-of-the-art%20security%20technologies%20were%20believed%20to%20conflict%20with%20EU%20data%20privacy%20regulations%3F%20Are%20security%20professionals%20really%20to%20be%20put%20in%20the%20difficult%20position%20of%20not%20being%20able%20to%20use%20the%20most%20current%20security%20approaches%20to%20protect%20their%20organizations%20and%20users%3F%20Is%20there%20a%20way%20to%20both%20protect%20the%20organization%20and%20its%20users%20while%20respecting%20the%20rights%20of%20users%20to%20not%20be%20excessively%20and%20unreasonably%20monitored%3F"></a></li><li style="heigth:16px;width:16px"><a title="Digg" class="option1_16" style="background-position:-32px 0px" rel="nofollow" target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;bodytext=Continuing%20on%20the%20theme%20from%20a%20previous%20blog%2C%20what%20if%20the%20use%20of%20state-of-the-art%20security%20technologies%20were%20believed%20to%20conflict%20with%20EU%20data%20privacy%20regulations%3F%20Are%20security%20professionals%20really%20to%20be%20put%20in%20the%20difficult%20position%20of%20not%20being%20able%20to%20use%20the%20most%20current%20security%20approaches%20to%20protect%20their%20organizations%20and%20users%3F%20Is%20there%20a%20way%20to%20both%20protect%20the%20organization%20and%20its%20users%20while%20respecting%20the%20rights%20of%20users%20to%20not%20be%20excessively%20and%20unreasonably%20monitored%3F"></a></li><li style="heigth:16px;width:16px"><a title="Reddit" class="option1_16" style="background-position:-64px -16px" rel="nofollow" target="_blank" href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F"></a></li><li style="heigth:16px;width:16px"><a title="StumbleUpon" class="option1_16" style="background-position:-112px -16px" rel="nofollow" target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F"></a></li><li style="heigth:16px;width:16px"><a title="Google Bookmarks" class="option1_16" style="background-position:-96px 0px" rel="nofollow" target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;annotation=Continuing%20on%20the%20theme%20from%20a%20previous%20blog%2C%20what%20if%20the%20use%20of%20state-of-the-art%20security%20technologies%20were%20believed%20to%20conflict%20with%20EU%20data%20privacy%20regulations%3F%20Are%20security%20professionals%20really%20to%20be%20put%20in%20the%20difficult%20position%20of%20not%20being%20able%20to%20use%20the%20most%20current%20security%20approaches%20to%20protect%20their%20organizations%20and%20users%3F%20Is%20there%20a%20way%20to%20both%20protect%20the%20organization%20and%20its%20users%20while%20respecting%20the%20rights%20of%20users%20to%20not%20be%20excessively%20and%20unreasonably%20monitored%3F"></a></li><li style="heigth:16px;width:16px"><a title="HackerNews" class="option1_16" style="background-position:-128px 0px" rel="nofollow" target="_blank" href="http://news.ycombinator.com/submitlink?u=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;t=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F"></a></li><li style="heigth:16px;width:16px"><a title="MSNReporter" class="option1_16" style="background-position:-176px 0px" rel="nofollow" target="_blank" href="http://reporter.es.msn.com/?fn=contribute&amp;Title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;URL=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;cat_id=6&amp;tag_id=31&amp;Remark=Continuing%20on%20the%20theme%20from%20a%20previous%20blog%2C%20what%20if%20the%20use%20of%20state-of-the-art%20security%20technologies%20were%20believed%20to%20conflict%20with%20EU%20data%20privacy%20regulations%3F%20Are%20security%20professionals%20really%20to%20be%20put%20in%20the%20difficult%20position%20of%20not%20being%20able%20to%20use%20the%20most%20current%20security%20approaches%20to%20protect%20their%20organizations%20and%20users%3F%20Is%20there%20a%20way%20to%20both%20protect%20the%20organization%20and%20its%20users%20while%20respecting%20the%20rights%20of%20users%20to%20not%20be%20excessively%20and%20unreasonably%20monitored%3F"></a></li><li style="heigth:16px;width:16px"><a title="BlinkList" class="option1_16" style="background-position:0px 0px" rel="nofollow" target="_blank" href="http://www.blinklist.com/index.php?Action=Blink/addblink.php&amp;Url=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;Title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F"></a></li><li style="heigth:16px;width:16px"><a title="Sphinn" class="option1_16" style="background-position:-96px -16px" rel="nofollow" target="_blank" href="http://sphinn.com/index.php?c=post&amp;m=submit&amp;link=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F"></a></li><li style="heigth:16px;width:16px"><a title="Posterous" class="option1_16" style="background-position:-32px -16px" rel="nofollow" target="_blank" href="http://posterous.com/share?linkto=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;selection=Continuing%20on%20the%20theme%20from%20a%20previous%20blog%2C%20what%20if%20the%20use%20of%20state-of-the-art%20security%20technologies%20were%20believed%20to%20conflict%20with%20EU%20data%20privacy%20regulations%3F%20Are%20security%20professionals%20really%20to%20be%20put%20in%20the%20difficult%20position%20of%20not%20being%20able%20to%20use%20the%20most%20current%20security%20approaches%20to%20protect%20their%20organizations%20and%20users%3F%20Is%20there%20a%20way%20to%20both%20protect%20the%20organization%20and%20its%20users%20while%20respecting%20the%20rights%20of%20users%20to%20not%20be%20excessively%20and%20unreasonably%20monitored%3F"></a></li><li style="heigth:16px;width:16px"><a title="Tumblr" class="option1_16" style="background-position:-128px -16px" rel="nofollow" target="_blank" href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;t=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;s=Continuing%20on%20the%20theme%20from%20a%20previous%20blog%2C%20what%20if%20the%20use%20of%20state-of-the-art%20security%20technologies%20were%20believed%20to%20conflict%20with%20EU%20data%20privacy%20regulations%3F%20Are%20security%20professionals%20really%20to%20be%20put%20in%20the%20difficult%20position%20of%20not%20being%20able%20to%20use%20the%20most%20current%20security%20approaches%20to%20protect%20their%20organizations%20and%20users%3F%20Is%20there%20a%20way%20to%20both%20protect%20the%20organization%20and%20its%20users%20while%20respecting%20the%20rights%20of%20users%20to%20not%20be%20excessively%20and%20unreasonably%20monitored%3F"></a></li><li style="heigth:16px;width:16px"><a title="Google Reader" class="option1_16" style="background-position:-112px 0px" rel="nofollow" target="_blank" href="http://www.google.com/reader/link?url=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;title=Security%20Monitoring%20vs.%20EU%20Data%20Privacy%20%E2%80%93%20Are%20We%20Stuck%3F&amp;srcURL=http%3A%2F%2Fblogs.rsa.com%2Fsecurity-monitoring-vs-eu-data-privacy-are-we-stuck%2F&amp;srcTitle=Speaking+of+Security+-+The+RSA+Blog+and+Podcast+The+Security+Blog+for+Security+Professionals"></a></li><li style="heigth:16px;width:16px"><a class="option1_16" style="cursor:pointer;background-position:-64px 0px" rel="nofollow" title="Add to favorites - doesn't work in Chrome"  onClick="javascript:AddToFavorites();"></a></li><li style="heigth:16px;width:16px"><a style="cursor:poainter" rel="nofollow"   onMouseOver="more(this,'post-5073')"><img  src="http://blogs.rsa.com/wp-content/plugins/sociable/images/option1/16/more.png" title="email" alt="email" /></a></li></ul>			

			</div>        

		  <a style="cursor:pointer" onclick="hide_sociable('post-5073',true)" class="close">

		  <img onclick="hide_sociable('post-5073',true)" title="close" src="http://blogs.rsa.com/wp-content/plugins/sociable/images/closelabel.png">

		  </a>

		</div>

	</div> 

  </div></div><div class='sociable' style='float:none'><ul class='clearfix'><li id="Google_p"><g:plusone annotation="bubble" href="http://blogs.rsa.com/security-monitoring-vs-eu-data-privacy-are-we-stuck/" size="medium"></g:plusone></li></ul></div><!-- End Sociable -->]]></content:encoded>
			<wfw:commentRss>http://blogs.rsa.com/security-monitoring-vs-eu-data-privacy-are-we-stuck/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
