LogMatters - November 2010



LogMatters - November 2010


LogLogic Email Banner 2010 



LogMatters - November 2010


Happy back-to-work to our American friends, and happy still-not-Christmas to the rest of you!


It’s been a hectic time here at Logging Towers. While some of you were stuffing yourselves with turkey, and the rest were working hard at your day jobs, we went on a bit of a blitz. Since we last spoke we’ve rebuilt our blog, attended 6 trade shows, did something cool with McAfee, Cisco and VMware that will see the light of day soon, and released another virtual appliance.


Gorka wrote a great piece in PC World about how to use logs after a data breach, Bill and I talked with ZDnet about how to find hidden gems, and we got all legal about the Cloud over at TechTarget. Speaking of Bill…ever wondered what he looks like? Click to see him talk logs on the terrible green-screen. On a more pleasing note, eWeek said some nice things about us (press the ‘I Like’ button please), and we even offered to give away a copy of The Beatles’ back-catalogue (offer still valid if you want to have a go).


All of this activity, of course, has a common theme – Visibility and Control. You don’t have enough, and we’re working to make sure that the industry addresses your issues. In fact, you should sign up for our Bloor webinar to hear about IT data legislation, or take a look at how we expand the scope of Cisco Security MARS, or how we extend McAfee ePO. After you’ve done that, put your free toys away and take a look at what an enterprise IT data management tool can do for you.


We have a few more really interesting things in the works before we get the turkey out again for Christmas, so sign up for our blog and stay connected.


Thanks,
Andy Morris
Director, Product Marketing

On LogBlog


FireSheep, Sidejacking and Logging


I read a story today in eWeek about sidejacking and FireSheep. The headline read “Firesheep and Sidejacking Not Just a WiFi Problem”. Most of the articles I read on this security hole are very vague on how it all works. Whereas, the info on the FireSheep site makes it very clear what was happening. Essentially they are stealing someone else’s web session identity (sidejacking) - and it’s done VERY easily. After the fear passed, it also became clear to me that you could use LogLogic’s products to catch this merely by correlating the SESSIONID to the IP, and if those changed, to take note of it.


Read more.


Compliance for the Masses: Bloor/LogLogic Webinar


We’re holding a webinar on the challenges faced by companies who have to make changes to their business operations due to compliance issues. For IT departments, the pressure to deliver a secure IT infrastructure against a background of constantly changing compliance and regulatory demands is tough, and not helped by a reduction in budgets to achieve this everchanging goal. By attending this webinar you will have a chance to learn about the realities of achieving an acceptable level of compliance for you organization.


Read more.



Logging and PCI: Key Issues


Among other things, PCI DSS mandates creating system logs and reviewing them from all systems in scope for PCI compliance. One should always remember that log collection and review are also critical for good security operations and incident response. In this article, we will focus on operational aspects of logging and log management for PCI compliance.


Read more.



Win The Beatles' back catalogue!


Woohoo, it’s officially international Beatles day over at Apple. To spread the joy we’re giving away all 256 items that make up the Beatles Box Set over on iTunes.


Read more.



Cloud Expo: Way Cool Stuff, and Seven Versions of the Same Company

By Bill Roth

I have a love/hate relationship with trade shows. On the one hand, I love them. I love meeting customers and prospects, and I love the shameless boosterism that it entails. On the other hand, as someone who has to manage to a budget and deliver ROI, I hate them. The ROI never works out. From a numbers point of view, they are nearly always a waste of money. (Except in Europe. I am still looking into that one.)


Read more.



SEM: A quick reality check
By Christophe Briguet


SIEM products are intended to target mature companies that understand log management and SEM, and want to add real value to their data by deploying a system for correlation and analysis. Ideally, the deployment of a SEM solution is the ultimate stage of log monitoring; security information is monitored in real-time for immediate alerting and incident response.


Read more.



5 Security Hurdles to Clear Before Choosing a Cloud Provider
By Dimitri McKay


Over the past year, the IT world has seemingly fallen head over heels for the cloud. Cloud computing has great potential in terms of collaboration and efficiency, and it's already delivering strong results for organizations that have leveraged the cloud model. For all the hype, though, it's important not to overlook one of the most basic yet crucial aspects of the cloud: setting up a reliable SLA (service level agreement) that ensures your organization's data is as secure in the cloud as it is in your own data center.


Read more.



PCI DSS 2.0 is here


PCI DSS defines itself as “a set of comprehensive requirements for enhancing payment account data security." However, in many real-world implementations of PCI DSS controls, the focus is on reducing the risk to transactions by limiting the number of systems that deal with card data. The most important concept in PCI DSS is “scope” – which refers to all of the systems, applications and networks where PCI DSS controls apply. PCI DSS is currently transitioning from version 1.2.1 to version 2.0. The new version (2.0) will be enacted on January 2011 and was published last week.


Read more.

Upcoming Events


McAfee Focus in Paris — CNIT, La Défense - Paris, France


logo_mcafee
 
December 2, 2010


McAfee Focus 2010: the conference for Information Security systems' professionals. Come and discover how to grow your business confidently. A unique day to learn about the most recent security innovations. Workshops with various themes on McAfee's technical innovations are proposed, along with customers' testimonials and other partners' presentations, such as LogLogic.


Register here.



National Guard Bureau Joint IT Conference — Location: TBD


EC_LogMatters_Oct_Q410_NatnlGuard


December 6 - 9, 2010


The 10th annual National Guard Bureau Joint Information Technology Conference is supported by the Air National Guard and the Army National Guard. The program includes both Information Technology (IT) and communications management representatives from all 54 states and U.S. territories.


More Information Coming Soon.

In the News


IT Exchange Zone Blog
Resolve Network Security and Access
LogLogic as an important vendor in tracking unsupported applications and devices on a network.
November 18, 2010

PCWorld
How to Use Logs for Forensics After a Data Breach
Despite the best precautions, it is impossible to protect your network against every attack. When the inevitable happens, your log data can be critical for identifying the cause of the breach and collecting evidence for use in the legal system. That is, if your logs were properly configured before the breach happened.
November 10, 2010

ZDNet Virtually Speaking Blog
LogLogic finds hidden gems
LogLogic’s Bill Roth and Andy Morris stopped by to present what LogLogic is doing and give me some insight into how their technology works. It is clear that today, the company is focusing on conducting a deep dive into log files and other non-structured data created by system software, application frameworks, database software and applications themselves to learn a great deal about what they’re doing on a real time basis.
November 5, 2010

Search Data Center
Old-style rules and red tape derail private cloud project
Stuart Radnidge had high hopes for the private cloud. The infrastructure architect for a large multinational financial services firm in the U.K. said he believed adding cloud computing technologies, like self-service provisioning, automated virtual machine creation and chargeback, on top of virtualized infrastructure, would bring terrific time and cost savings to IT and the business users it served.
November 4, 2010

Search Security
Organisations unaware of Good Practice Guide 13 monitoring guidelines
Mandatory guidelines for the protective monitoring of public-sector IT systems have yet to be implemented in the majority of organisations, and, as a result, government IT systems may not be prepared to detect and thwart emerging threats, or guard adequately against data leakage.
October 29, 2010

About LogLogic, Inc.
LogLogic® (www.loglogic.com) is the leader in log management and security event management solutions. More than 1,000 customers worldwide entrust their most sensitive log data to LogLogic’s award-winning products. For updates from the Company, visit the blog or follow LogLogic on Twitter.

All trademarks mentioned in this email are the property of their respective owners.

 

LogLogic, Inc.
110 Rose Orchard Way
Suite 200
San Jose, CA 95134
United States
US Toll Free: 888 347 3883
Tel: +1 408 215 5900
Fax: +1 408 321 8717
    LogLogic EMEA
47-53 rue Raspail
92594 Levallois Cedex
France
Tel: +33.0.426.232.525
Fax: +33.0.147.155.509