Effective security starts with real-time visibility into all activity on all systems, networks, databases, and applications. McAfee Enterprise Security Manager enables your business with true, real-time situational awareness and the speed and scale required to identify critical threats, respond intelligently, and ensure continuous compliance monitoring. Security teams now have access to real-time, risk relevant information to obtain a stronger security posture while shortening response time.
Advanced risk and threat detection — Enterprise Security Manager connects evolving threat data with a real-time understanding of the risk, asset importance, and security posture throughout the enterprise. This dynamic context, combined with our highly intelligent correlation engine, provides risk scoring and threat prioritization that continually adapts to the enterprise environment. In addition, available integration with McAfee Global Threat Intelligence (GTI) and McAfee ePolicy Orchestrator (McAfee ePO) software help you detect, correlate, and remediate threats in minutes across your entire IT infrastructure.
Policy-aware compliance management — As compliance requirements evolve, so must your SIEM. Enterprise Security Manager makes compliance management easy with hundreds of pre-built dashboards, complete audit trails, and reports for PCI DSS, HIPAA, NERC-CIP, FISMA, GLBA, SOX, and others. Our support for the Unified Control Framework also allows you to report your policies against more than 240 global regulations and control frameworks.
Critical facts in minutes, not hours — Our highly tuned appliance can collect, process, and correlate billions of events from multiple years and keep all information available locally for immediate ad hoc queries, forensics, rules validation, and compliance.
Global Threat Intelligence — An optional live feed of McAfee GTI IP Reputation data provides valuable, real-time information on external threats gathered from hundreds of millions of sensors around the globe, allowing you to pinpoint malicious activity on your network. Enterprise Security Manager can use the GTI IP Reputation data to quickly identify conditions where an internal host has communicated with a known bad actor.
Use one environment to consolidate, correlate, and report on security information from heterogeneous devices at lightning speed.
Integrate McAfee Global Threat Intelligence services and McAfee Risk Advisor with McAfee Enterprise Security Manager for a prioritized view of events, assets, and countermeasures.
Provide contextual information (vulnerability scanners, identity, authentication management systems, privacy solutions, or other supported systems) to enrich each event with context, allowing for a better understanding of how network and security events correlate to real business processes and policies.
Drive instant corrective action, such as issuing new configurations, implementing new policies, and deploying software updates.
Consolidate audit and compliance activities for over 240 regulations within a single pane of glass for continuous governance and rapid reporting.
Leverage our custom-built database engine and integration with McAfee ePolicy Orchestrator (McAfee ePO) software to extend visibility and control across your entire security and compliance management environment.
For McAfee Enterprise Security Manager integration information, see the ESM Integration data sheet.
| Hardware Specifications1 | ETM-X6 | ETM-X4 | ETM-6000 | ETM-5600 | ETM-4600-ELM | ETM-5600-ELM | ETM-6000-ELM |
|---|---|---|---|---|---|---|---|
| Collection Rates | 300,000 events per second2 | 150,000 events per second2 | 70,000 events per second2 | 50,000 events per second2 | 1,000 events per second2 | 2,500 events per second2 | 5,000 events per second2 |
| Analytical Performance | Less than 10 seconds3 | Less than 30 seconds3 | Less than 1 minute3 | Less than 3 minutes3 | Less than 3 minutes3 | Less than 3 minutes3 | Less than 1 minute3 |
| Local Storage | 14 TB4 + 3.2 TB Flash | 14 TB4 + 800 GB SSD | 14 TB4 | 8 TB4 | 3 TB4 | 8 TB4 | 14 TB4 |
Built for big security data, McAfee Global Threat Intelligence for McAfee Enterprise Security Manager (ESM) puts the power of McAfee Labs directly into the security monitoring flow using McAfee’s high-speed, highly intelligent security information and event management (SIEM) solution.
The security information and event management (SIEM) market is defined by the customer's need to analyze security event data in real time for internal and external threat management, and to collect, store, analyze and report on log data for regulatory compliance and forensics. The vendors that are included in Gartner’s analysis have technologies that have been designed for this purpose, and they actively market and sell these technologies to the security buying center.
The McAfee Enterprise Security Manager is able to gather, store, and analyze logs and data from a large amount of sources and then correlate events based on rules, possible risk, or historical trends.
McAfee integrates NitroSecurity products into its portfolio, improving its SIEM offering.
Topics : Security Management, SIEM
Topics : Network Security, Endpoint Protection, SIEM
Topics : Risk & Compliance, Security Management, SIEM
Topics : SIEM
Topics : Risk & Compliance, Security Management, SIEM
Topics : SIEM
McAfee spoke with customers about integrating SIEM with Threat Intelligence and how it helped their effort to mitigate bad actors.
Learn about the top five issues with SIEM: Big Security Data, Content and User Awareness, Dynamic Context, Solution Customization, and Business Value.