EMC’s CIRT: Smart People Solving Complex Problems with RSA/Archer Integration

by Jeff Glasco – May 12, 2010

Complex problems are everywhere, as witnessed in the headlines of the past week. How do you plug a hole gushing 200,000 barrels of oil a day when it’s a mile deep in the ocean? How do you implement controls to prevent mysterious 1000 point drops in the DOW? How do you bail out an entire country’s economy amidst rioting?

For many of us, the answer is straightforward: We look to our smart people to come up with a solution. Our smart people are being forced to become even smarter as they stare down modern problems. I hear it’s even causing some of our not-so-smart people to smarten up and contribute to the cause. (I got a letter in the mail last week asking me to step up my game.)

I had the opportunity to work with some of these smart people at EMC, prior to its acquisition of Archer (yes, EMC was a customer first). EMC’s Critical Incident Response Team (a.k.a. “The CIRT”) looked for new ways to identify and respond to security events in the organization. They had a vision for streamlining their incident investigation processes by integrating RSA’s industry leading SIEM product, enVision, with Archer GRC business process management capabilities.

EMC’s CIRT elevated their incident-triage capability by minimizing manual data aggregation processes and providing business context to technical alerts from enVision. They sought to enrich alert data in order to move beyond a vulnerability-driven context model and toward an exposure-driven model of security management. The result is a triage process that allows EMC to prioritize resources based on business impact and data exposure. They’re now able to view the business operational impact of incidents through the single lens of an Archer dashboard and operate incident management processes in a cross-functional GRC domain.

EMC’s CIRT continues to evolve their enVision and Archer integration architecture, providing the RSA enVison and Archer GRC product teams with a unique opportunity to build on a proven solution—one that was crafted by smart people to tackle complex problems facing global organizations. You could say we’ve been inspired, and now we have new teams of smart people creating solutions that leverage RSA enVision and Archer to help organizations tackle an ever-expanding pool of GRC-related issues.

A few of our resident smart people will present new solutions for tackling risk and compliance challenges through the integration of RSA enVision and Archer in an upcoming webcast. Please join our own Steve Schlarman along with Sam Curry and Paul Stamp of RSA as they expand on the opportunities for your organization.

Here are the details of this event:

When: Tuesday, May 18 at 2 p.m. US Eastern
Registration: http://info.rsasecurity.com/2010Am/webcast/100518_Archer_Compliance/online.html

Published May 12 2010, 02:48 PM by Sarah Nord (Historical)

Comments

 

EMC???s CIRT: Smart People Solving Complex Problems with RSA/Archer Integration | Forge network said:

Pingback from  EMC???s CIRT: Smart People Solving Complex Problems with RSA/Archer Integration | Forge network

May 17, 2010 8:21 AM
 

Twitter Trackbacks for EMC???s CIRT: Smart People Solving Complex Problems with RSA/Archer Integration [archer.com] on Topsy.com said:

Pingback from  Twitter Trackbacks for                 EMC???s CIRT: Smart People Solving Complex Problems with RSA/Archer Integration         [archer.com]        on Topsy.com

May 12, 2010 3:25 PM

Leave a Comment

 

About Sarah Nord (Historical)

As Archer Marketing Communications Manager for RSA, The Security Division of EMC, Sarah Nord oversees the planning, development, delivery and analysis of strategic marketing programs. She also serves as senior writer and editor for RSA Archer marketing content, including web copy, press releases, data sheets, case studies and blog posts. Sarah holds a BA in Professional Writing and an MA in Writing from Missouri State University. She is also RSA Archer Certified.