19

True Cost of Cheap FIM

Embed Size (px)

Citation preview

Page 1: True Cost of Cheap FIM
Page 2: True Cost of Cheap FIM

Introduction: What is FIM?

Common Costs of Cheap FIM

Tripwire True FIM solutions.

Page 3: True Cost of Cheap FIM
Page 4: True Cost of Cheap FIM

2017 - FIM

1997 - Change Audit

2001 - VISA CISP

2004 - PCI DSS 1.0

2006 – PCI DSS 1.1

Page 5: True Cost of Cheap FIM
Page 6: True Cost of Cheap FIM
Page 7: True Cost of Cheap FIM
Page 8: True Cost of Cheap FIM
Page 9: True Cost of Cheap FIM
Page 10: True Cost of Cheap FIM
Page 11: True Cost of Cheap FIM
Page 12: True Cost of Cheap FIM
Page 13: True Cost of Cheap FIM

The overhead on the

endpoint will be too great

ENDPOINT OVERLOAD

FIM will only monitor files on an

operating system

OPERATING SYSTEM

Deploying FIM will generate too

many alerts and false positives

FALSE POSITIVES

Detecting a change doesn’t help

with my security posture

SECURITY POSTURE

No context given around

a detected change on the

endpoint

CONTEXT

Page 14: True Cost of Cheap FIM

Lack of available API’s or integrations

reduces value in the greater security

eco-system

Eco-system Integrations

FIM will only monitor files on a subset of

systems often limited to 100 or less.

Scalability

Open source FIM doesn’t have

the QA, documentation, or

company backing a commercial

product has.

Product Quality

Not all products have the ability to protect

themselves much less the data in your

environment.

Introduced Vulnerabilities

Lack of reporting renders

collected change data

useless.

Reporting

Page 15: True Cost of Cheap FIM

Concerns & Capabilities

True FIM

Solutions

Open Source

Solutions

Bargain-Basement

Solutions

Detects file changes in windows

Reports on file changes

Delivers "who" data & Context

Supports multiple OS's

Reduces Alerts & Noise

Provides Real-time Changes

Ensures Tool Quality & Security

Integrates with policy solutions

Advanced Integrity Reporting

Scalable

Page 16: True Cost of Cheap FIM

Configuration &

Compliance

Management

Log

Management

Vulnerability

Management

Page 17: True Cost of Cheap FIM

Continuous

Monitoring

Operational

Cost Reduction

Threat Detection

and Response

Automation

Risk

Reduction

Context

Page 18: True Cost of Cheap FIM

There is more than just monitoring files—don’t forget Databases, Active Directory,

Virtual Infrastructures, Network Devices and many other custom rules

File Integrity Monitoring is not an onerous task but a foundational control necessary to

achieve integrity and build trust in the security of your systems

Integration with existing technology strengthens and validates the

findings that integrity monitoring solution identifies

Page 19: True Cost of Cheap FIM

tripwire.com | @TripwireInc