McAfee Enterprise Security Manager

McAfee Enterprise Security Manager

Intelligent situational awareness, response, and reporting

Next Steps:

Overview

Effective security starts with real-time visibility into all activity on all systems, networks, databases, and applications. McAfee Enterprise Security Manager enables your business with true, real-time situational awareness and the speed and scale required to identify critical threats, respond intelligently, and ensure continuous compliance monitoring. Security teams now have access to real-time, risk relevant information to obtain a stronger security posture while shortening response time.

Advanced risk and threat detection — Enterprise Security Manager connects evolving threat data with a real-time understanding of the risk, asset importance, and security posture throughout the enterprise. This dynamic context, combined with our highly intelligent correlation engine, provides risk scoring and threat prioritization that continually adapts to the enterprise environment. In addition, available integration with McAfee Global Threat Intelligence (GTI) and McAfee ePolicy Orchestrator (McAfee ePO) software help you detect, correlate, and remediate threats in minutes across your entire IT infrastructure.

Policy-aware compliance management — As compliance requirements evolve, so must your SIEM. Enterprise Security Manager makes compliance management easy with hundreds of pre-built dashboards, complete audit trails, and reports for PCI DSS, HIPAA, NERC-CIP, FISMA, GLBA, SOX, and others. Our support for the Unified Control Framework also allows you to report your policies against more than 240 global regulations and control frameworks.

Critical facts in minutes, not hours — Our highly tuned appliance can collect, process, and correlate billions of events from multiple years and keep all information available locally for immediate ad hoc queries, forensics, rules validation, and compliance.

Global Threat Intelligence — An optional live feed of McAfee GTI IP Reputation data provides valuable, real-time information on external threats gathered from hundreds of millions of sensors around the globe, allowing you to pinpoint malicious activity on your network. Enterprise Security Manager can use the GTI IP Reputation data to quickly identify conditions where an internal host has communicated with a known bad actor.

SC Magazine 5-Star Rating
McAfee Positioned in Leaders Quadrant of the Magic Quadrant for SIEM

Features & Benefits

Monitor one complete picture of security activity

Use one environment to consolidate, correlate, and report on security information from heterogeneous devices at lightning speed.

Manage evolving threats with confidence

Integrate McAfee Global Threat Intelligence services and McAfee Risk Advisor with McAfee Enterprise Security Manager for a prioritized view of events, assets, and countermeasures.

Know how network and security events correlate to real business processes and policies

Provide contextual information (vulnerability scanners, identity, authentication management systems, privacy solutions, or other supported systems) to enrich each event with context, allowing for a better understanding of how network and security events correlate to real business processes and policies.

Set policies, rules, and thresholds that will generate alerts and launch mitigations

Drive instant corrective action, such as issuing new configurations, implementing new policies, and deploying software updates.

Reduce audit effort and expense for multiple regulations

Consolidate audit and compliance activities for over 240 regulations within a single pane of glass for continuous governance and rapid reporting.

Collect the data and context you need throughout your enterprise

Leverage our custom-built database engine and integration with McAfee ePolicy Orchestrator (McAfee ePO) software to extend visibility and control across your entire security and compliance management environment.

System Requirements

For McAfee Enterprise Security Manager integration information, see the ESM Integration data sheet.

Hardware Specifications1ETM-X6ETM-X4ETM-6000ETM-5600ETM-4600-ELMETM-5600-ELMETM-6000-ELM
Collection Rates 300,000 events per second2 150,000 events per second2 70,000 events per second2 50,000 events per second2 1,000 events per second2 2,500 events per second2 5,000 events per second2
Analytical Performance Less than 10 seconds3 Less than 30 seconds3 Less than 1 minute3 Less than 3 minutes3 Less than 3 minutes3 Less than 3 minutes3 Less than 1 minute3
Local Storage 14 TB4 + 3.2 TB Flash 14 TB4 + 800 GB SSD 14 TB4 8 TB4 3 TB4 8 TB4 14 TB4

  1. All McAfee Enterprise Security Manager, Enterprise Log Manager, and additional McAfee SIEM appliance offerings are fault-tolerant appliances, including redundant array of independent disks (RAID) and redundant power supplies.
  2. Based on typical network environments using average event and flow aggregation.
  3. Indicates the average response time to generate a monthly report consisting of all events that occurred over a period of 30 days.
  4. Represents usable event and flow storage, after RAID configuration.

Demos / Tutorials

Demos

Built for big security data, McAfee Global Threat Intelligence for McAfee Enterprise Security Manager (ESM) puts the power of McAfee Labs directly into the security monitoring flow using McAfee’s high-speed, highly intelligent security information and event management (SIEM) solution.

Awards / Reviews

Gartner
McAfee Positioned as a Leader by Gartner in MQ for SIEM Based on Completeness of Vision and Ability to Execute

The security information and event management (SIEM) market is defined by the customer's need to analyze security event data in real time for internal and external threat management, and to collect, store, analyze and report on log data for regulatory compliance and forensics. The vendors that are included in Gartner’s analysis have technologies that have been designed for this purpose, and they actively market and sell these technologies to the security buying center.

SC Magazine Awards 2013
McAfee Enterprise Security Manager Gets 5-Star Rating by SC Magazine

The McAfee Enterprise Security Manager is able to gather, store, and analyze logs and data from a large amount of sources and then correlate events based on rules, possible risk, or historical trends.

Customer Stories

McAfee

McAfee integrates NitroSecurity products into its portfolio, improving its SIEM offering.

Highlights
  • Significantly shortens time to analyze security events from four to six days to less than 10 minutes
  • Decreases time to produce PCI compliance reports from eight to 12 hours to 10 minutes
  • Saves administrative time and manual maintenance while eliminating unnecessary activities
  • Facilitates disaster recovery and allows for proper use of virtual machines
  • Improves the organization’s overall security posture in the industry

News / Events

News

Events

No results found

On Demand

Resources

Brochures

Focus on 5: Threat Intelligence SIEM Requirements

McAfee spoke with customers about integrating SIEM with Threat Intelligence and how it helped their effort to mitigate bad actors.

Focus on 5: SIEM Requirements

Learn about the top five issues with SIEM: Big Security Data, Content and User Awareness, Dynamic Context, Solution Customization, and Business Value.

Data Sheets

Reports

Solution Briefs

Technology Blueprints

White Papers

Community

Forums

No results found

Blogs

  • Join @McAfeeBusiness #SecChat on 5/30 to discuss InfoSec Burnout
    McAfee Enterprise - May 24, 2013
    For an organization, a skilled security team is often the first line of defense against cyber attacks.  Yet veterans of the industry report that burnout is common, citing everything from an isolated day-to-day work environment to long hours and too few objective measures of success. Depending on the individual, burnout might appear as depression, rage, Read more...
  • April #SecChat Recap: The Future of Cyber Education
    McAfee Enterprise - May 22, 2013
    View the story “April #SecChat Recap: The Future of Cyber Education” on Storify
  • Microsoft Patch Tuesday Report: Endpoint Perspective
    Scott Taschler - May 21, 2013
    This month, Microsoft’s Patch Tuesday bundle includes two separate updates for Internet Explorer; the first (MS13-037) is a cumulative update for Internet Explorer. The second is a fix (MS13-038) specifically for a critical bug in IE 8 that hackers and malware have been using to break into Windows computers. This vulnerability first surfaced on May Read more...
  • Getting Assurance in a Time Constrained World
    Kim Singletary - May 20, 2013
    Nothing is as frustrating as when something goes wrong, especially when you have time constraints.  NIST has just released Special Publication 800-53, Revision 4: Security and Privacy Controls for Federal Information Systems and Organizations where a few notable items have been added to increase the confidence that security, practices, procedures and architectures of information systems Read more...
  • CRN Analysis: McAfee Tops Symantec for Endpoint Protection
    Dan Wolff - May 14, 2013
    This week, CRN pitted McAfee and Symantec head-to-head, evaluating both leading enterprise protection vendors for malware and spyware protection, intrusion prevention, channel profitability and more. The result? While Symantec continues to have a strong portfolio, McAfee came out on top for its central policy management through ePolicy Orchestrator, innovation with hardware-based security technologies, and its Read more...