skip to content
Security monitoring with Cisco security MARS Preview this item
ClosePreview this item
Checking...

Security monitoring with Cisco security MARS

Author: Gary Halleen; Greg Kellogg
Publisher: Indianapolis, IN : Cisco Press, ©2007.
Series: Cisco Press networking technology series.
Edition/Format:   Print book : EnglishView all editions and formats
Rating:

(not yet rated) 0 with reviews - Be the first.

Subjects
More like this

Find a copy online

Links to this item

Find a copy in the library

&AllPage.SpinnerRetrieving; Finding libraries that hold this item...

Details

Material Type: Internet resource
Document Type: Book, Internet Resource
All Authors / Contributors: Gary Halleen; Greg Kellogg
ISBN: 9781587052705 1587052709
OCLC Number: 134992316
Notes: Includes index.
Description: xix, 6-316 pages : illustrations ; 23 cm.
Contents: Foreword IntroductionPart I Introduction to CS-MARS and Security Threat MitigationChapter 1 Introducing CS-MARSIntroduction to Security Information Management The Role of a SIM in Today's Network Common Features for SIM Products Desirable Features for SIM ProductsChallenges in Security Monitoring Types of Events MessagesUnderstanding CS-MARS Security Threat Mitigation System Topology and Visualization Robust Reporting and Rules Engine Alerts and Mitigation Description of TerminologyCS-MARS User Interface Dashboard Network Status My ReportsSummaryChapter 2 Regulatory Challenges in DepthHealth Insurance Portability and Accountability Act of 1996 (HIPAA) Who Is Affected by HIPAA? What Are the Penalties for Noncompliance? HIPAA Security Rule HIPAA Security Rule and Security Monitoring Gramm-Leach-Bliley Act of 1999 (GLB Act) Who Is Affected by the GLB Act? What Are the Penalties for Noncompliance with GLB? The GLB Act Safeguards Rule The GLB Safeguards Rule and Security Monitoring The Sarbanes-Oxley Act of 2002 (SOX) Who Is Affected by Sarbanes-Oxley? What Are the Penalties for Noncompliance with Sarbanes-Oxley? Sarbanes-Oxley Internal Controls Payment Card Industry Data Security Standard (PCI-DSS) Who Is Affected by the PCI Data Security Standard? What Are the Penalties for Noncompliance with PCI-DSS? The PCI Data Security Standard Compliance Validation Requirements Summary Chapter 3 CS-MARS Deployment ScenariosDeployment Types Local and Standalone Controllers Global Controllers Sizing a CS-MARS Deployment Special Considerations for Cisco IPSs Determining Your Events per Second Determining Your Storage Requirements Considerations for Reporting Performance Considerations for Future Growth and Flood Conditions Planning for Topology Awareness CS-MARS Sizing Case Studies Retail Chain Example State Government Example Healthcare Example Summary Part II CS-MARS Operations and ForensicsChapter 4 Securing CS-MARSPhysical Security Inherent Security of MARS Appliances Security Management Network MARS Communications Requirements Network Security Recommendations Ingress Firewall Rules Egress Firewall Rules Network-Based IDS and IPS Issues Summary Chapter 5 Rules, Reports, and QueriesBuilt-In Reports Understanding the Reporting Interface Reporting Methods The Query Interface Creating an On-Demand Report Batch Reports and the Report Wizard Creating a Rule About Rules Creating the Rule Creating Drop Rules About Drop Rules Creating the Drop Rule Summary Chapter 6 Incident Investigation and ForensicsIncident Handling and Forensic Techniques Initial Incident Investigation Viewing Incident Details Finishing Your Investigation False-Positive Tuning Deciding Where to Tune Tuning False Positives in MARS Summary Chapter 7 Archiving and Disaster RecoveryUnderstanding CS-MARS Archiving Planning and Selecting the Archive Server Configuring the Archiving Server Configuring CS-MARS for Archiving Using the Archives Restoring from Archive Restoring to a Reporting Appliance Direct Access of Archived Events Retrieving Raw Events from Archive Summary Part III CS-MARS Advanced TopicsChapter 8 Integration with Cisco Security ManagerConfiguring CS-Manager to Support CS-MARS Configuring CS-MARS to Integrate with CS-Manager Using CS-Manager Within CS-MARS Summary Chapter 9 Troubleshooting CS-MARSBe Prepared Troubleshooting MARS Hardware Beeping Noises Degraded RAID Array Troubleshooting Software and Devices Unknown Reporting Device IP Check Point or Other Logs Are Incorrectly Parsed New Monitored Device Logs Still Not Parsed How Much Storage Is Being Used, and How Long Will It Last? E-Mail Notifications Sent to Admin Group Never Arrive MARS Is Not Receiving Events from Devices Summary Chapter 10 Network Admission ControlTypes of Cisco NAC NAC Framework Host Conditions Understanding NAC Framework Communications Configuration of CS-MARS for NAC Framework Reporting Information Available on CS-MARS Summary Chapter 11 CS-MARS Custom ParserGetting Messages to CS-MARS Determining What to Parse Adding the Device or Application Type Adding Log Templates First Log Template Second and Third Log Templates Fourth and Fifth Log Templates Additional Messages Adding Monitored Device or Software Queries, Reports, and Rules Queries Reports Rules Custom Parser for Cisco CSC Module Summary Chapter 12 CS-MARS Global ControllerUnderstanding the Global Controller Zones Installing the Global Controller Enabling Communications Between Controllers Troubleshooting Using the Global Controller Interface Logging In to the Controller Dashboard Drilling Down into an Incident Query/Reports Local Versus Global Rules Security and Monitor Devices Custom Parser Software Upgrades Global Controller Recovery Summary Part IV AppendixesAppendix A Querying the ArchiveAppendix B CS-MARS Command ReferenceAppendix C Useful WebsitesIndex 1587052709 TOC 6/11/2007
Series Title: Cisco Press networking technology series.
Responsibility: Gary Halleen, Greg Kellogg.
More information:

Reviews

User-contributed reviews
Retrieving GoodReads reviews...
Retrieving DOGObooks reviews...

Tags

Be the first.
Confirm this request

You may have already requested this item. Please select Ok if you would like to proceed with this request anyway.

Linked Data


Primary Entity

<http://www.worldcat.org/oclc/134992316> # Security monitoring with Cisco security MARS
    a schema:Book, schema:CreativeWork ;
   library:oclcnum "134992316" ;
   library:placeOfPublication <http://experiment.worldcat.org/entity/work/data/102962473#Place/indianapolis_in> ; # Indianapolis, IN
   library:placeOfPublication <http://id.loc.gov/vocabulary/countries/inu> ;
   schema:about <http://experiment.worldcat.org/entity/work/data/102962473#Topic/computersicherheit> ; # Computersicherheit
   schema:about <http://dewey.info/class/005.8/e22/> ;
   schema:about <http://experiment.worldcat.org/entity/work/data/102962473#Topic/computer_security_evaluation> ; # Computer security--Evaluation
   schema:about <http://experiment.worldcat.org/entity/work/data/102962473#Topic/rechnernetz> ; # Rechnernetz
   schema:about <http://id.worldcat.org/fast/872488> ; # Computer security--Evaluation
   schema:about <http://id.worldcat.org/fast/872341> ; # Computer networks--Security measures
   schema:about <http://id.loc.gov/authorities/subjects/sh94001277> ; # Computer networks--Security measures
   schema:about <http://experiment.worldcat.org/entity/work/data/102962473#Topic/cisco> ; # Cisco
   schema:bookFormat bgn:PrintBook ;
   schema:contributor <http://viaf.org/viaf/38824700> ; # Greg Kellogg
   schema:copyrightYear "2007" ;
   schema:creator <http://viaf.org/viaf/31447006> ; # Gary Halleen
   schema:datePublished "2007" ;
   schema:exampleOfWork <http://worldcat.org/entity/work/id/102962473> ;
   schema:inLanguage "en" ;
   schema:isPartOf <http://experiment.worldcat.org/entity/work/data/102962473#Series/cisco_press_networking_technology_series> ; # Cisco Press networking technology series.
   schema:name "Security monitoring with Cisco security MARS"@en ;
   schema:productID "134992316" ;
   schema:publication <http://www.worldcat.org/title/-/oclc/134992316#PublicationEvent/indianapolis_in_cisco_press_2007> ;
   schema:publisher <http://experiment.worldcat.org/entity/work/data/102962473#Agent/cisco_press> ; # Cisco Press
   schema:url <http://bvbr.bib-bvb.de:8991/F?func=service&doc_library=BVB01&doc_number=016778236&line_number=0001&func_code=DB_RECORDS&service_type=MEDIA> ;
   schema:url <http://catdir.loc.gov/catdir/toc/ecip0718/2007021272.html> ;
   schema:workExample <http://worldcat.org/isbn/9781587052705> ;
   wdrs:describedby <http://www.worldcat.org/title/-/oclc/134992316> ;
    .


Related Entities

<http://experiment.worldcat.org/entity/work/data/102962473#Place/indianapolis_in> # Indianapolis, IN
    a schema:Place ;
   schema:name "Indianapolis, IN" ;
    .

<http://experiment.worldcat.org/entity/work/data/102962473#Series/cisco_press_networking_technology_series> # Cisco Press networking technology series.
    a bgn:PublicationSeries ;
   schema:hasPart <http://www.worldcat.org/oclc/134992316> ; # Security monitoring with Cisco security MARS
   schema:name "Cisco Press networking technology series." ;
   schema:name "Cisco Press networking technology series" ;
    .

<http://id.loc.gov/authorities/subjects/sh94001277> # Computer networks--Security measures
    a schema:Intangible ;
   schema:name "Computer networks--Security measures"@en ;
    .

<http://id.worldcat.org/fast/872341> # Computer networks--Security measures
    a schema:Intangible ;
   schema:name "Computer networks--Security measures"@en ;
    .

<http://id.worldcat.org/fast/872488> # Computer security--Evaluation
    a schema:Intangible ;
   schema:name "Computer security--Evaluation"@en ;
    .

<http://viaf.org/viaf/31447006> # Gary Halleen
    a schema:Person ;
   schema:familyName "Halleen" ;
   schema:givenName "Gary" ;
   schema:name "Gary Halleen" ;
    .

<http://viaf.org/viaf/38824700> # Greg Kellogg
    a schema:Person ;
   schema:familyName "Kellogg" ;
   schema:givenName "Greg" ;
   schema:name "Greg Kellogg" ;
    .

<http://worldcat.org/isbn/9781587052705>
    a schema:ProductModel ;
   schema:isbn "1587052709" ;
   schema:isbn "9781587052705" ;
    .


Content-negotiable representations

Close Window

Please sign in to WorldCat 

Don't have an account? You can easily create a free account.