Business Driver: Sarbanes-Oxley, PCI DSS and Gramm-Leach-Bliley Act (GLBA)
Challenges: Massive scale and distribution of 18,000 Unix servers and 6,000 Windows servers
Reporting by event, machine, time and date, severity and show differences from average patterns
Required solution to be self-auditing and provide a means to verify that logs or log reports have been reviewed
Results: Corporate compliance and audit policies being met
Business Driver: Sarbanes-Oxley, Insider Abuse
Challenges: Over 3,500 servers distributed worldwide
Over 200G of collected event data daily
Reports to map to compliance requirements
Required 100% accuracy of data collected
Results:
Business Driver: Sarbanes-Oxley, FFIEC
Replace homegrown SQL Server-based system
Challenges: High velocity of data during peak processing periods with over 80G daily from worldwide sources
Corporate mandate to reduce storage costs
No DBA support
Results:
Business Driver: Sarbanes-Oxley, GLBA
Detect fraudulent web access attempts
Challenges: Hundreds of millions of log records from heterogeneous sources
Incident response time must be in minutes
Results:
Business Driver: Payment Card Industry Data Security Standards (PCI DSS)
Challenges: Heterogeneous credit card data sources including custom applications
Results: Met PCI DSS Compliance
Business Driver: Worldwide network and data security
Challenges: Massive data collection of 200G
Online retention of 12 months of entire log record to support legal requirements
Results: Meeting security requirements and able respond to incidents by being able to search over 8B records in 2 minutes
Business Driver: Network and data security over systems containing detailed information on US citizens
Challenges: Massive data collection of 200GB
Online retention of 12 months of entire log record to support legal requirements
Results: Meeting security requirements and able respond to incidents by being able to search over 8B records in 2 minutes