Top Banner
1 A burden or a blessing? Implement Security Logging & Monitoring 13 March 2014 Ingeborg Kortekaas 20 March 2014
12

Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

Feb 06, 2018

Download

Documents

docong
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

1 1 1

A burden or a blessing?

Implement Security Logging & Monitoring

13 March 2014

Ingeborg Kortekaas

20 March 2014

Page 2: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

2

Introduction

Ingeborg Kortekaas

Corporate Information Security Officer at NIBC

NIBC Bank N.V. (NIBC) is an entrepreneurial bank that

offers Corporate Banking and Consumer Banking

Headquartered in The Hague, also offices in Brussels,

Frankfurt and London

Number of employees ± 600

Who am I?

Page 3: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

3

Table of Contents

Background 4

Objectives 5

Approach 6

Security Intelligence 7

Initial findings 8

Final outcome 9

Considerations 10

Next Steps 11

Questions 12

What is it about?

Page 4: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

4

Background

Tightened statutory requirements

Increased supervision by regulators

Our former Managed Security Service (MSS) provider did

not meet NIBC’s expectations and requirements

Our former MSS needed an upgrade which could only be

executed with a new installation due to new technology

Unavailability of resources or specific knowledge within

NIBC to do it ourselves

What was good enough yesterday, is no longer sufficient today

Page 5: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

5

Ability to show compliance and increase level of security

Objectives

Tracking user activities to prevent, detect and minimize the

impact of a data compromise

Allowing thorough tracking, alerting and analysis when

something does go wrong

Determining the cause of a compromise

Page 6: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

6

Approach Risk-based approach, CIA-rating is leading

Page 7: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

7

Security intelligence Iterative process that’s never finished

Delivers actionable and comprehensive insights

– allows you to make informed, proactive decisions

– helps to reduce security risks and operational costs

Page 8: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

8

Initial findings

Insights

– Valuable knowledge about system activities and system

changes

Behavioral change

– Awareness that changes are logged and monitored

– Accountability in advance

Monitoring mechanisms

– Ability to monitor the proper execution of processes

Big brother is watching you

Page 9: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

9

Ability to show compliance and increased level of security

Final outcome

Compliance Demonstrability

Optimized IT processes Increased security

Page 10: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

10

Think carefully before you make a decision

Considerations

Involvement of business

Keep it simple

Connect output to existing processes

Governance is key

Page 11: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

11

Next steps Roadmap security logging & monitoring

Tranche 0: Former situation with limited effectiveness

Tranche 1:

Basic SIEM, comply with policies

Tranche 2:

Evaluate solution, add additional systems, increase knowledge

Tranche 3:

Ability to use reporting and collection of data for complex analysis

Tranche 4: Dashboard to monitor compliance, ability to direct detection

2013 2014 2015

Page 12: Implement Security Logging & Monitoring - IBM · PDF file13 March 2014 Ingeborg Kortekaas ... also offices in Brussels, ... Delivers actionable and comprehensive insights

12

Questions Do you want to know more?