<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>eIQviews &#187; security monitoring</title>
	<atom:link href="http://blog.eiqnetworks.com/tag/security-monitoring/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.eiqnetworks.com</link>
	<description>Perspectives on Security and Compliance Management from eIQnetworks</description>
	<lastBuildDate>Mon, 14 Dec 2009 13:04:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.eiqnetworks.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/9a3baa02baa3289d9a8c9a6a0eb652a5?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>eIQviews &#187; security monitoring</title>
		<link>http://blog.eiqnetworks.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.eiqnetworks.com/osd.xml" title="eIQviews" />
	<atom:link rel='hub' href='http://blog.eiqnetworks.com/?pushpress=hub'/>
		<item>
		<title>The Best Security Reacts Quickly to Change</title>
		<link>http://blog.eiqnetworks.com/2009/10/22/the-best-security-reacts-quickly-to-change/</link>
		<comments>http://blog.eiqnetworks.com/2009/10/22/the-best-security-reacts-quickly-to-change/#comments</comments>
		<pubDate>Thu, 22 Oct 2009 18:18:13 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[User Issues]]></category>
		<category><![CDATA[Gartner]]></category>
		<category><![CDATA[John Pescatore]]></category>
		<category><![CDATA[react faster]]></category>
		<category><![CDATA[security monitoring]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=297</guid>
		<description><![CDATA[I&#8217;m certainly not above lifting verbatim research that I believe is helpful to security and compliance practitioners. And the title of this post was lifted from Gartner&#8217;s John Pescatore&#8217;s post entitled &#8220;Who Moved My Soap – The Best Security Reacts Quickly to Change.&#8221; Now I could go forth with all sorts of don&#8217;t drop the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=297&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m certainly not above lifting verbatim research that I believe is helpful to security and compliance practitioners. And the title of this post was lifted from Gartner&#8217;s John Pescatore&#8217;s post entitled &#8220;<a href="http://blogs.gartner.com/john_pescatore/2009/10/21/who-moved-my-soap-the-best-security-reacts-quickly-to-change/" target="_blank">Who Moved My Soap – The Best Security Reacts Quickly to Change</a>.&#8221; Now I could go forth with all sorts of don&#8217;t drop the soap in DisneyWorld jokes, but that would obscure the real point, which is not about Pescatore&#8217;s hygienic preferences.</p>
<p>Security professionals are not driving the ship. The business folks are. So security folks that are resistant to the ebbs and flows of business will not be successful. We have to face the reality that we (as security professionals) need to adapt our defenses both to the actions of our adversaries, as well as the reality of our businesses. Budgets come and go, projects are re-scoped, and priorities change. That&#8217;s business. That&#8217;s life. Deal with it.</p>
<p>But you cannot adapt in a vacuum. In order to react quickly (which sounds very similar to my personal REACT FASTER mantra), an organization needs to understand what they are looking for. That means they need to be monitoring as much as they can, establishing what is &#8220;normal&#8221; in their environment and then watching for what is NOT normal. Things change all the time, but if you don&#8217;t know HOW they are changing, there is no way you&#8217;ll be able to understand WHY things have changed, and therefore you&#8217;ve got no shot to address the issue&#8230;before it&#8217;s too late.</p>
<p>Oh yeah, did I mention I&#8217;m a big fan of security monitoring?</p>
<br />Posted in Security, User Issues Tagged: Gartner, John Pescatore, react faster, security monitoring <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/297/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=297&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/10/22/the-best-security-reacts-quickly-to-change/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>
	</item>
		<item>
		<title>Ten Reasons Log Data is Not Enough #6: You can&#8217;t monitor what you can&#8217;t see&#8230;</title>
		<link>http://blog.eiqnetworks.com/2009/10/05/ten-reasons-log-data-is-not-enough-6-you-cant-monitor-what-you-cant-see/</link>
		<comments>http://blog.eiqnetworks.com/2009/10/05/ten-reasons-log-data-is-not-enough-6-you-cant-monitor-what-you-cant-see/#comments</comments>
		<pubDate>Mon, 05 Oct 2009 22:10:28 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Log Management Series]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[extrusion monitoring]]></category>
		<category><![CDATA[network flow]]></category>
		<category><![CDATA[rogue devices]]></category>
		<category><![CDATA[security monitoring]]></category>
		<category><![CDATA[vulnerability scanning]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=285</guid>
		<description><![CDATA[Let&#8217;s have a candid discussion about rogue devices, shall we? You know, the unauthorized access point plugged into a port in a conference or under someone&#8217;s desk. Or maybe the network behind the off-shore contractors you have maintaining legacy applications. Perhaps someone is running a side business during work hours on a device they bring [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=285&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Let&#8217;s have a candid discussion about rogue devices, shall we? You know, the unauthorized access point plugged into a port in a conference or under someone&#8217;s desk. Or maybe the network behind the off-shore contractors you have maintaining legacy applications. Perhaps someone is running a side business during work hours on a device they bring from home ON YOUR NETWORK.</p>
<p><a href="http://www.flickr.com/photos/foxtongue/2657434642/" target="_blank"><img class="alignleft" style="margin:10px;" title="Blindfolded Typing Competition originally uploaded by foxtongue" src="http://farm4.static.flickr.com/3285/2657434642_543c30685f_m_d.jpg" alt="" width="240" height="173" /></a>Each of these scenarios (regardless of how contrived) happen each day. And every new device presents a significant risk to your environment. Which means you need to be constantly watching for these devices and make sure they are not wreaking havoc. In fact, this is one of the key use cases for network access control (NAC). Of course, that technology is struggling, but it&#8217;s not because of the lack of a problem to solve.</p>
<p>So if you are looking at a <a href="http://www.eiqnetworks.com/solutions/log_management.shtml" target="_blank">log management</a> or <a href="http://www.eiqnetworks.com/solutions/security_information_and_event_management.shtml" target="_blank">security information and event management</a> (<a href="http://www.eiqnetworks.com/solutions/siem.shtml" target="_blank">SIEM</a>) product, won&#8217;t that tell you about new devices? Won&#8217;t it see something funky and flag it? Well, actually no it doesn&#8217;t. Log Management requires logs and your typical rouge device isn&#8217;t too interested in forwarding its logs to much of anything. That&#8217;s right, each managed device needs to be configured to push log files to the log management product. If that doesn&#8217;t happen, the SIEM is blissfully unaware anything is going on &#8211; until a number of managed devices are compromised &#8211; which is too late.</p>
<p>Yes, network devices (at least the right ones) can detect rogue devices and potentially quarantine those until the proper authorization is presented. But what if you don&#8217;t have NAC or can&#8217;t afford to upgrade your entire switching infrastructure? That&#8217;s right, you need to go beyond log data.</p>
<p>As mentioned in <a href="http://blog.eiqnetworks.com/2009/09/17/ten-reasons-log-data-is-not-enough-4-network-blind-mice/" target="_blank">reason #4 about network flows</a>, the network never lies. So we&#8217;ve got to look for new network devices and then kick off a scan to figure out what it is and whether it&#8217;s authorized. eIQ SecureVue makes that pretty simple. You can set a policy to check for any new IP addresses within a specific time period. Then from right within SecureVue, you can kick off a vulnerability scan to figure out what is the story with that device. Once you figure out what it is, then you can understand whether it should be there.</p>
<p>Additionally, you can set network flow policies to check for traffic leaving the network from unmanaged devices. This kind of extrusion monitoring will tell you if a device is moving data off the network. Maybe they should be, maybe not. But the point is to gain situational awareness of what&#8217;s happening in your environment. And just looking at the log data is not going to get you there.</p>
<br />Posted in Log Management Series, Security Tagged: extrusion monitoring, network flow, rogue devices, security monitoring, vulnerability scanning <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/285/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=285&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/10/05/ten-reasons-log-data-is-not-enough-6-you-cant-monitor-what-you-cant-see/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://farm4.static.flickr.com/3285/2657434642_543c30685f_m_d.jpg" medium="image">
			<media:title type="html">Blindfolded Typing Competition originally uploaded by foxtongue</media:title>
		</media:content>
	</item>
		<item>
		<title>eIQcast Episode 20: Seeing Through the Clouds</title>
		<link>http://blog.eiqnetworks.com/2009/09/30/eiqcast-episode-20-seeing-through-the-clouds/</link>
		<comments>http://blog.eiqnetworks.com/2009/09/30/eiqcast-episode-20-seeing-through-the-clouds/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 12:32:14 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[eIQcast]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[security monitoring]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[VMWare]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=282</guid>
		<description><![CDATA[In this the 20th episode of the eIQcast, eIQnetworks SVP of Strategy Mike Rothman discusses some of the challenges of cloud computing with Ross Levanto. Mike goes into the issues of maintaining visibility when networks and systems reside in someone else&#8217;s data center, and some of the mechanisms eIQ is adding to SecureVue to help [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=282&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><span style="vertical-align:text-top;"><a href="http://www.flickr.com/photos/travelphotos/439869138/" target="_blank"><img class="alignright" style="margin:10px;" title="Rays of light originally uploaded by laurenz" src="http://farm1.static.flickr.com/173/439869138_1737e2a40e_m_d.jpg" alt="" width="240" height="160" /></a>In this the 20th episode of the eIQcast, eIQnetworks SVP of Strategy Mike Rothman discusses some of the challenges of cloud computing with Ross Levanto. Mike goes into the issues of maintaining visibility when networks and systems reside in someone else&#8217;s data center, and some of the mechanisms eIQ is adding to SecureVue to help customers address this issue.</span></p>
<p><span style="vertical-align:text-top;"><a href="http://www.eiqnetworks.com/news/Cloud_security_Final.shtml" target="_blank">Yesterday eIQ announced a new capability within SecureVue to provide enhanced visibility for virtualized data centers and cloud computing models.</a> SecureVue now includes a mapping feature which allows security professionals to keep track of which virtual machines are running on specific hardware devices, which facilitates the investigation and remediation for issues within a virtual data center. Check out the release for more detail on http://www.eiqnetworks.com.</span></p>
<p><span style="vertical-align:text-top;">Running time: 11:40</span></p>
<p><a href="http://eiqcast.podomatic.com/" target="eiqcast"><img src="http://www.podomatic.com/images/share/player_logo.jpg" border="0" alt="" /></a></p>
<p>Direct Link:   <a href="http://eiqcast.podOmatic.com/entry/2009-09-30T05_17_07-07_00" target="_blank"> http://eiqcast.podOmatic.com/entry/2009-09-30T05_17_07-07_00</a></p>
<p><em>Don’t be like Dick and check out eIQ’s video at <a href="http://www.logdataisnotenough.com/" target="_blank">logdataisnotenough.com</a></em></p>
<br />Posted in Compliance, eIQcast, Security Tagged: cloud computing, security monitoring, virtualization, VMWare <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/282/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=282&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/09/30/eiqcast-episode-20-seeing-through-the-clouds/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://farm1.static.flickr.com/173/439869138_1737e2a40e_m_d.jpg" medium="image">
			<media:title type="html">Rays of light originally uploaded by laurenz</media:title>
		</media:content>

		<media:content url="http://www.podomatic.com/images/share/player_logo.jpg" medium="image" />
	</item>
		<item>
		<title>Security Best Practices, Linkous-style</title>
		<link>http://blog.eiqnetworks.com/2009/09/25/security-best-practices-linkous-style/</link>
		<comments>http://blog.eiqnetworks.com/2009/09/25/security-best-practices-linkous-style/#comments</comments>
		<pubDate>Fri, 25 Sep 2009 19:14:38 +0000</pubDate>
		<dc:creator>Mike Rothman</dc:creator>
				<category><![CDATA[Compliance]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[john linkous]]></category>
		<category><![CDATA[networkworld]]></category>
		<category><![CDATA[security convergence]]></category>
		<category><![CDATA[security management]]></category>
		<category><![CDATA[security monitoring]]></category>

		<guid isPermaLink="false">http://blog.eiqnetworks.com/?p=279</guid>
		<description><![CDATA[eIQ&#8217;s own security and compliance evangelist John Linkous took some time to step away from his bully pulpit to contribute a list of practices for Linda Musthaler&#8217;s Network World column. Although he&#8217;s no Jim Bakker, John can sling security fire and brimstone with the best of them. He provides some good food for thought for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=279&subd=eiqviews&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 250px"><a href="http://www.flickr.com/photos/coba/1825369/" target="_blank"><img style="margin:10px;" title="Random Wacky Street Preacher originally uploaded by coba" src="http://farm1.static.flickr.com/2/1825369_8199f69fe2_m_d.jpg" alt="Secure Your Stuff or you will be a pillar of salt" width="240" height="141" /></a><p class="wp-caption-text">Secure Your Stuff or you&#39;ll be a pillar of salt</p></div>
<p>eIQ&#8217;s own security and compliance evangelist John Linkous took some time to step away from his bully pulpit to contribute a list of practices for <a href="http://www.networkworld.com/newsletters/techexec/2009/090925-musthaler.html" target="_blank">Linda Musthaler&#8217;s Network World column</a>. Although he&#8217;s no Jim Bakker, John can sling security fire and brimstone with the best of them. He provides some good food for thought for any security professional. Check it out and be converted.</p>
<br />Posted in Compliance, Security Tagged: john linkous, networkworld, security convergence, security management, security monitoring <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eiqviews.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eiqviews.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eiqviews.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eiqviews.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eiqviews.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eiqviews.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eiqviews.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eiqviews.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eiqviews.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eiqviews.wordpress.com/279/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.eiqnetworks.com&blog=5062284&post=279&subd=eiqviews&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.eiqnetworks.com/2009/09/25/security-best-practices-linkous-style/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike</media:title>
		</media:content>

		<media:content url="http://farm1.static.flickr.com/2/1825369_8199f69fe2_m_d.jpg" medium="image">
			<media:title type="html">Random Wacky Street Preacher originally uploaded by coba</media:title>
		</media:content>
	</item>
	</channel>
</rss>