Neil Desai
BSides Knoxville 2015Trying to do proper monitoring is more than just turning on the logs and let the SIEM sort it out. Unfortunately that is what many companies do and then wonder why they fail and make the headlines. There is a gap between installing a point product (IDS/IPS, AV, firewall, etc.) and properly monitoring the events from that solution. I have seen many companies making the same mistakes: turning on the firehose of events and then thinking the are good to go. This talk will go over the missing element in a creating a good monitoring solution.
Back to BSides Knoxville 2015 listIf you would like to republish one of the articles from this site on your webpage or print journal please contact IronGeek.
Copyright 2020, IronGeek