<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Evaluating Security Startups</title>
	<atom:link href="http://www.zhen.org/zen20/2005/11/21/evaluating-security-startups/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zhen.org/zen20/2005/11/21/evaluating-security-startups/</link>
	<description></description>
	<lastBuildDate>Wed, 28 Jul 2010 14:02:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Raffy</title>
		<link>http://www.zhen.org/zen20/2005/11/21/evaluating-security-startups/comment-page-1/#comment-408</link>
		<dc:creator>Raffy</dc:creator>
		<pubDate>Sun, 22 Jan 2006 09:58:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.zhen.org/blog/?p=147#comment-408</guid>
		<description>Well, I agree with the article. I would love to get rid of my SEM/SIEM/ESM/... solution and have border devices block the ATTACKS. Here&#039;s the catch: Point solutions are:
- a pain to manage (you need to update them all, etc.)
- see only part of the picture (they are POINT-solutions)
- don&#039;t know the business-relevance of the assets they protect (well, you could argue that they should, but have you configured 200 firewalls, 100 NIPS, 2000 HIDS, 2000 Operating Systems, 50 routers, etc. to know the business relevance of all your assets?
- how do you audit? Not at all? Have you had auditors for SOX in house? Well, get those logs from all your boxes and show that they really implement what you are claiming! (Have fun collecting logs from around 1000 different sources)

I could go on and on. I think the problem is that a lot of people still do not have a clue what a SIM/SEM/SIEM/ESM is.</description>
		<content:encoded><![CDATA[<p>Well, I agree with the article. I would love to get rid of my SEM/SIEM/ESM/&#8230; solution and have border devices block the ATTACKS. Here&#8217;s the catch: Point solutions are:<br />
- a pain to manage (you need to update them all, etc.)<br />
- see only part of the picture (they are POINT-solutions)<br />
- don&#8217;t know the business-relevance of the assets they protect (well, you could argue that they should, but have you configured 200 firewalls, 100 NIPS, 2000 HIDS, 2000 Operating Systems, 50 routers, etc. to know the business relevance of all your assets?<br />
- how do you audit? Not at all? Have you had auditors for SOX in house? Well, get those logs from all your boxes and show that they really implement what you are claiming! (Have fun collecting logs from around 1000 different sources)</p>
<p>I could go on and on. I think the problem is that a lot of people still do not have a clue what a SIM/SEM/SIEM/ESM is.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

