| SECURITY INFORMATION MANAGER |
Prevent, Inform and Comply |
|
| Symantec Security Information Manager 4.6 enables organizations to collect, store, and analyze log data as well as monitor and respond to security events to meet IT risk and compliance requirements. It can collect and normalize a broad scope of event data and correlate the impact of incidents based on the criticality to business operations or level of compliance to various mandates. |
| |
| Log management and data retention |
| Symantec Security Information Manager enables
organizations to collect, store, and analyze log data as
well as monitor and respond to security events to meet
IT compliance requirements. Flexible archiving, querying
and reporting provide organizations the means to
manage logs from every source. It can archive
data faster than traditional databases because it is
optimized for one function - to save a high volume of
events. |
|
| Incident management |
| Symantec Security Information Manager helps
organizations to collect, store and analyze log and
intelligence data in order to identify and respond to
critical malicious activities after, during or even before
they occur. By combining existing protection and
prevention device and application data with external
intelligence on malicious activities occurring globally, it
can deliver comprehensive insight into what incidents
are occurring or are most likely to occur. |
|
| Data collection |
| Symantec Security Information
Manager uses over 150 predefined source collectors and
provides flexible options for customizing the additional
Data Sheet: Compliance and Security Management
Symantec™ Security Information Manager
collection of unique source logs. This enhanced
collection process, combined with Symantec Security
Information Manager’s optimized archiving and event
processing capabilities provide a highly scalable ability
to centralize large amounts of diverse log data. |
|
| Benefits |
- Provides analysts with a graphic display of the progress of an attack to facilitate quicker analysis
- Supports providing security management services to multiple divisions and/or geographies
- Leverages an enterprise's existing asset model to provide insights into which parts of the organization are affected by an incident
|
|