SIEM

Security Information and Event Management (SIEM)

Effective security starts with real-time visibility into all activity on all systems, networks, databases, and applications. McAfee Enterprise Security Manager enables your business with true, real-time situational awareness and the speed and scale required to identify critical threats, respond intelligently, and ensure continuous compliance monitoring. Security teams now have access to real-time, risk relevant information to obtain a stronger security posture while shortening response time.

Advanced risk and threat detection — Enterprise Security Manager connects evolving threat data with a real-time understanding of the risk, asset importance, and security posture throughout the enterprise. This dynamic context, combined with our highly intelligent correlation engine, provides risk scoring and threat prioritization that continually adapts to the enterprise environment. In addition, available integration with McAfee Global Threat Intelligence (GTI) and McAfee ePolicy Orchestrator (McAfee ePO) software help you detect, correlate, and remediate threats in minutes across your entire IT infrastructure.

Policy-aware compliance management — As compliance requirements evolve, so must your SIEM. Enterprise Security Manager makes compliance management easy with hundreds of pre-built dashboards, complete audit trails, and reports for PCI DSS, HIPAA, NERC-CIP, FISMA, GLBA, SOX, and others. Our support for the Unified Control Framework also allows you to report your policies against more than 240 global regulations and control frameworks.

Critical facts in minutes, not hours — Our highly tuned appliance can collect, process, and correlate billions of events from multiple years and keep all information available locally for immediate ad hoc queries, forensics, rules validation, and compliance.

Global Threat Intelligence — An optional live feed of McAfee GTI IP Reputation data provides valuable, real-time information on external threats gathered from hundreds of millions of sensors around the globe, allowing you to pinpoint malicious activity on your network. Enterprise Security Manager can use the GTI IP Reputation data to quickly identify conditions where an internal host has communicated with a known bad actor.

McAfee Enterprise Security Manager

Intelligent situational awareness, response, and reporting

Monitor one complete picture of security activity

Use one environment to consolidate, correlate, and report on security information from heterogeneous devices at lightning speed.

Manage evolving threats with confidence

Integrate McAfee Global Threat Intelligence services and McAfee Risk Advisor with McAfee Enterprise Security Manager for a prioritized view of events, assets, and countermeasures.

Know how network and security events correlate to real business processes and policies

Provide contextual information (vulnerability scanners, identity, authentication management systems, privacy solutions, or other supported systems) to enrich each event with context, allowing for a better understanding of how network and security events correlate to real business processes and policies.

Set policies, rules, and thresholds that will generate alerts and launch mitigations

Drive instant corrective action, such as issuing new configurations, implementing new policies, and deploying software updates.

Reduce audit effort and expense for multiple regulations

Consolidate audit and compliance activities for over 240 regulations within a single pane of glass for continuous governance and rapid reporting.

Collect the data and context you need throughout your enterprise

Leverage our custom-built database engine and integration with McAfee ePolicy Orchestrator (McAfee ePO) software to extend visibility and control across your entire security and compliance management environment.

siem 2