FAA turns to ArcSight for security event management
The new tool is designed to help it sift through a torrent of security data
Computerworld - The Federal Aviation Administration has just finished putting in place a new security event management system designed to help the agency detect and respond to external and internal threats more efficiently.
The new tool is based on a product from ArcSight Inc. called Enterprise Security Management (ESM) that allows the FAA to centrally monitor, collect and analyze information from multiple network security devices such as firewalls and intrusion-detection systems.
The tool is part of a broader FAA bid to bolster its network defenses and incident-response capabilities after the 9/11 terrorist attacks, according to Michael Brown, director of the Office of Information Systems Security at the FAA.
"We were looking for a way to manage the large volume of information coming from multiple [network] sources [and] do a lot of correlation and data reduction," he said. The goal is to help the agency better manage the large amount of information generated by security systems, Brown said.
ArcSight's ESM, like other products in its class from vendors such as netForensics Inc., NetIQ Corp., and Intellitactics Inc., is designed to help organizations quickly sift through the torrent of data generated by multiple security devices, allowing them to focus on the ones that are most important.
At the FAA, for instance, firewalls, system log files, vulnerability scanners and intrusion-detection systems together generate more than a million alerts a day -- only a very small fraction of which really merit any follow-up, Brown said.
"At the end of the day, after all the analysis has been done, we are looking at roughly 15 to 20 alerts" that really matter, he said.
Apart from transforming raw event data into actionable intelligence for security and network administrators, tools such as those from Cupertino, Calif.-based ArcSight can also be useful for forensic analysis after an attack, he said.
Like other agencies, the FAA -- which is a part of the U.S. Department of Transportation -- is also subject to audits by the Government Accountability Office and is required to implement strong incident-response capabilities under the Federal Information Security Management Act.
The new event management capability will allow the FAA to create an auditable security infrastructure to demonstrate compliance with such requirements, Brown said.
Read more about BI and Analytics in Computerworld's BI and Analytics Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Forrester: Economic Impact of Switching to Google Apps
- Content provided by Google
Read this Forrester report on the "total economic impact" of Google Apps, and learn how switching to Google Apps creates... - Intelligent Systems: Unlocking Hidden Business Value with Data
- An intelligent system enables data to flow across an enterprise infrastructure, spanning the devices where valuable data is gathered from employees and customers,...
- Concepts of NonStop SQL/MX
- For DBAs and developers who are familiar with Oracle solutions and want to learn about NonStop SQL/MX, this whitepaper provides an overview of...
- HP Advanced Information Services for SAP In-Memory Appliance (SAP HANA)
- Organizations are eager to connect the vast amounts of data available within and outside their businesses to compete more effectively and make better... All BI and Analytics White Papers
- Quantifying the Business Value of VMware View - Webcast
- Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price...
- Good to Great - How to Take Business Analytics to the Next Level
- By attending this webcast you will learn how you can implement an effective BA strategy that will deliver maximum strategic value to your...
- Supporting Mobile Productivity With A Limited IT Budget
- Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
- User Experience Monitoring
- In this webinar, you will learn hints & tips for improving end-user response times from Forrester Research analyst, Jean-Pierre Garbani.
- Hints & Tips Cisco
- Overwhelmed by tracking your Vblock, Flexpod or Cisco UCS performance? Spend one hour with Nimsoft to learn how you can eliminate the overhead... All BI and Analytics Webcasts