Security Intelligence Can Help Enterprises Improve Risk Management and Incident Detection/Response

ESG Research reveals best practices.  Information security intelligence another driver for big data security analytics.

Author(s): Jon Oltsik

Published: December 14, 2012

According to ESG Research, 65% of organizations use external threat intelligence (i.e,. open source or commercial threat information) as part of their overall security analytics activities.  This is yet another factor driving the intersection of big data and security analytics. 

Of those enterprises that consume commercial threat intelligence, 29% say that it is “highly effective” in helping their organization address risk while another 66% say that commercial intelligence is “somewhat effective” in helping their organization address risk.

So how do some of the organizations use commercial threat intelligence so that it is “highly effective” in helping them reduce IT risk?  ESG did some further data analysis to find out.  It turns out that in these enterprises:

  1. Security intelligence is used to support other security objectives.  Rather than use security intelligence as secondary data sources, “highly effective” organizations tended to have specific use cases and metrics for security intelligence.  For example, many included security intelligence in formal risk management programs in order to fine-tune security controls, launch impromptu vulnerability scans, or lock down systems.
  2. Security intelligence feeds are integrated into SIEM and GRC tools.  “Highly effective” push data feeds directly into their security management and analytics technologies in order to correlate external threat intelligence with internal status and activities.  Interestingly, these firms are also replacing security point tools with centralized enterprise-class security management systems.  Clearly these “highly effective” organizations are also on the leading edge of big data security analytics.
  3. Highly effective organizations share security intelligence across the organizations.  These enterprises seem to get their money’s worth as they make sure that security, risk, compliance, privacy, IT, and executive managers have access to customized views of security intelligence that can help them with their individual tasks and responsibilities.
  4. Highly effective organizations supplement security intelligence with external expertise.  Risk management and incident detection/response are difficult activities requiring resources and expertise.  Given the current security skills shortage, “highly effective” enterprises are most likely to turn to professional and/or managed service providers for help in these areas.

Leading security vendors like IBM, McAfee, RSA, Sourcefire, and Symantec provided out-of-the-box security intelligence in their latest security management technologies.  There are numerous industry Information Sharing and Analysis Centers (ISACs) for exchanging security data.  The U.S. Federal government wants to increase public/private partnerships for security data sharing.  All of these efforts are intended to make new sources of security data “highly effective” resources for risk management and incident detection/response.  Following the 4 steps described above could really help industry consortiums and individual organizations achieve these goals. 

Read our complete ESG Research Brief, Security Intelligence a Key Component of Big Data Security Analytics, for more findings from ESG’s research about security intelligence.

Comments (0)

Post Comment



  • Leave this field empty

*All views and opinions expressed in ESG blog posts are intended to be those of the post's author and do not necessarily reflect the views of Enterprise Strategy Group, Inc., or its clients. ESG bloggers do not and will not engage in any form of paid-for blogging. Click to see our complete Disclosure Policy.

Phone:
508-381-5166

E-mail

Jon Oltsik is an ESG senior principal analyst and the founder of the firm’s Information Security and Networking services. With 25 years of technology industry experience, Jon is widely recognized as an expert in threat and security management as well as all aspects of network security. Recently, Jon has been an active participant with cybersecurity issues, legislation, and technology within the U.S. federal government. Prior to joining ESG, Jon was the founder and principal of Hype-Free Consulting. He has also held senior management positions at GiantLoop Network, Forrester Research, Epoch Systems, and EMC Corporation.

Full Biography

NEWSLETTER

Enter your email address, and click subscribe