Abstract

The aim of the study is to increase the efficiency of information security management of economic entities that use Security Information and Event Management (SIEM) systems by identifying and solving the main problems of introducing these systems into the management of information security practices of economic entities [1-3]. Materials and research methods . Based on the analysis of scheme of the typical architecture of the SIEM system and the standard process of introducing the SIEM system into practice of managing information security of various types of economic entities, the main problems of the installation and configuration of the SIEM system are determined, and ways to solve them are substantiated. During the installation and configuration of the SIEM system, the team of customers and contractors may experience the following typical problems. The process of installing and configuring the SIEM system as part of a systematic approach is considered as a set of interconnected resource-based procedures that implement the installation and configuration of individual components of the SIEM system. Out of the whole set of these procedures, the procedures to be automated are determined. To determine the rational structure of the process of automated installation and configuration of the SIEM system, a method of network planning and management is proposed [4-5], which also allows you to evaluate the effectiveness of implementing the SIEM system in the practice of managing information security of economic entities based on the development and calculation of network schedules. Results. In this work, we developed ways to solve the problems of introducing SIEM systems into information security management practice: simplifying the SIEM system, which is a rejection of rarely used modules and rebuilding the architecture of the SIEM system; automation of the process of typical installation and general setup of the SIEM system, which represents the development of a methodology for automating the procedure of typical installation and general setup of the SIEM system and software module that implements the developed methodology; a combined approach, which is a joint application of the two above approaches, which allows you to bring the SIEM system closer as a product to the “box option. The paper presents reasonable proposals for improving the implementation of the SIEM system, based on the development and application of automated procedures for the typical installation and configuration of the SIEM system, which reduces the time spent on the implementation of the SIEM system, increases the convenience of performing these procedures, and in general can lead to the “boxed version of the solution for a product of this class of information security event management systems. Conclusion. The proposed ways to solve the problems of implementing SIEM systems in the practice of managing information security of economic entities based on the optimization of the installation and configuration of SIEM systems can accelerate the distribution and implementation of information security event management systems and increase efficiency by automating standard installation procedures and SIEM system settings.

Highlights

  • Целью исследования является повышение эффективности управления информационной безопасностью субъектов экономической деятельности, которые используют Security Information and Event Management (SIEM)-системы, за счет выявления и решения основных проблем внедрения этих систем в практику управления информационной безопасностью с учетом специфических особенностей и типовых характеристик последних [1,2,3]

  • The aim of the study is to increase the efficiency of information security management of economic entities that use Security Information and Event Management (SIEM) systems by identifying and solving the main problems of introducing these systems into the management of information security practices of economic entities [1,2,3]

  • To determine the rational structure of the process of automated installation and configuration of the SIEM system, a method of network planning and management is proposed [4,5], which allows you to evaluate the effectiveness of implementing the SIEM system in the practice of managing information security of economic entities based on the development and calculation of network schedules

Read more

Summary

Introduction

Целью исследования является повышение эффективности управления информационной безопасностью субъектов экономической деятельности, которые используют SIEM-системы, за счет выявления и решения основных проблем внедрения этих систем в практику управления информационной безопасностью с учетом специфических особенностей и типовых характеристик последних [1,2,3]. Ядром таких решений являются системы класса SIEM – Security Information and Event Management – Системы управления событиями безопасности [6,7,8]. Для оценки основных проблем внедрения SIEM-систем в работе проанализированы основные особенности архитектуры типового процесса внедрения системы управления событиями безопасности.

Objectives
Results
Conclusion
Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call