 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Adventures in Data Center Automation &#187; Reconnex</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/data-center-automation/tag/reconnex/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/data-center-automation</link>
	<description></description>
	<lastBuildDate>Sun, 29 Aug 2010 20:01:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Digging into the DCAB 6 functional areas:  Security and Protection</title>
		<link>http://itknowledgeexchange.techtarget.com/data-center-automation/digging-into-the-dcab-6-functional-areas-security-and-protection/</link>
		<comments>http://itknowledgeexchange.techtarget.com/data-center-automation/digging-into-the-dcab-6-functional-areas-security-and-protection/#comments</comments>
		<pubDate>Sat, 05 Jan 2008 19:40:09 +0000</pubDate>
		<dc:creator>Ryan Shopp</dc:creator>
				<category><![CDATA[ArcSight]]></category>
		<category><![CDATA[Configuresoft]]></category>
		<category><![CDATA[DataCenter]]></category>
		<category><![CDATA[Ecora]]></category>
		<category><![CDATA[EMC]]></category>
		<category><![CDATA[HP Software]]></category>
		<category><![CDATA[IBM Tivoli]]></category>
		<category><![CDATA[LogLogic]]></category>
		<category><![CDATA[nCircle]]></category>
		<category><![CDATA[NetForensics]]></category>
		<category><![CDATA[Reconnex]]></category>
		<category><![CDATA[Skybox Security]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Tripwire]]></category>
		<category><![CDATA[Vericept]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/data-center-automation/digging-into-the-dcab-6-functional-areas-security-and-protection/</guid>
		<description><![CDATA[The massive number of security management vendors make simply covering this portion of the DCAB a very intimidating task. So many technology approaches and different data center technology focuses (e.g., networks vs. system vs. applications etc). I&#8217;ve attempted a first pass at sub-dividing this functional area. I know that do to it&#8217;s vastness, I&#8217;m going [...]]]></description>
				<content:encoded><![CDATA[<p>The massive number of security management vendors make simply covering this portion of the DCAB a very intimidating task.  So many technology approaches and different data center technology focuses (e.g., networks vs. system vs. applications etc).  I&#8217;ve attempted a first pass at sub-dividing this functional area.  I know that do to it&#8217;s vastness, I&#8217;m going to miss tons of vendors I already know about and also stretch the categories a little in my attempt to limit the number of sub-divisions.</p>
<p>Proactive Identification (proactive searching for a potential exposure point that could become a situation) which includes:</p>
<ul>
<li> IP Scanning &#8211; query remotely that simply requires IP address to gather information and determine if their is a potential condition of concern.  Vendors include:  eEye, nCircle,  Nessus, Qualys, McAfee, Rapid7</li>
<li>Configuration/Settings Auditing &#8211; query remotely (using credentials) or having an agent on the system to take a more details look at the configuration files, etc.  Vendors include:  ConfigureSoft, Ecora, nCircle, Tripwire, Solidcore, Skybox Security</li>
<li>Penetration Testing &#8211; remote query attempts to actually expose or harm a data center resource.  Vendor include:  Core Security, HP (former Spi Dynamics), IBM (former Watchfire), Imperva, Mu Security, BreakingPoint Systems</li>
</ul>
<p>Reactive Identification (reactive, collecting of events or watching data flows to identify a condition or re-occuring trend)</p>
<ul>
<li>Security Event Consolidation (aka. SEM) &#8211; unified view of events from a variety of sources with the hope that you can quickly identify a problem and resolve it sooner after it occurred, or seeing something that tells you that problem may be about to happen.  Vendors include:  ArcSight, NetForensics, EMC/RSA</li>
<li>Information Archival &amp; Reporting (aka. SIM) &#8211; archiving and then the analysis and mining of all that event data to identify a re-occurring situation that could be resolved.  This archive is also a great resource for reporting certain compliance situation to auditors.  Vendors include:  ArcSight, NetForensics, LogLogic</li>
<li>Data Leakage &#8211; monitoring activities or traffic flows to identify if sensitive information is being .  Vendors include:  EMC/RSA (Tablus), Reconnex, Symantec (Vontu), Vericept</li>
</ul>
<p>Alright, that will have to do for now.  Identity &amp; Access Management is a whole other area but this will have to do for now.  Wow, I&#8217;m really starting to realize that this DCAB was biting off more then I could honestly chew <img src='http://itknowledgeexchange.techtarget.com/data-center-automation/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   Hopefully, it will prove helpful to someone out there.  When I do start to make updates the best way to manage that may be moving this to a wiki.</p>
<p>Quick status check, I&#8217;ve now taken a first pass on 4 of the 6 functional areas (and most of them require/deserve a return visit sometime soon).  Each functional area alone probably could/would be topic enough for an individual blogger (any volunteers).  I&#8217;ve also had some great recent conversations with people on virtualization, process orchestration and resource reconciliation that i&#8217;m eager to talk about.  So as I&#8217;ve stated before, comments are open for anyone and everyone to add thoughts and commentary.  Which vendors did I miss, what capabilities/functions did I miss as we monitor the security in our data center.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/data-center-automation/digging-into-the-dcab-6-functional-areas-security-and-protection/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
