Kent Farries & Ikenna Nwafor, TransAlta, sit with Dave Vellante and John Walls at Splunk .conf 2017 in Washington, D.C
#splunkconf17 #theCUBE
https://siliconangle.com/2017/11/27/best-defense-good-offense-case-new-data-security-platforms-splunkconf17/
The best defense is a good offense: The case for new data security platforms
Sec officers’ fundraising platform
A data platform for security, as opposed to a simple tool, might be a swifter sell across departments, and to management too.
TransAlta Corporation is a power generator and wholesale marketing company based in Calgary, Canada. Before 2009, cyber security was not a high priority for the company, Kent Farries, IT security at TransAlta, told theCUBE. In that year, it first implemented a security information event management solution. (A SIM is basically log management.) Farries and his colleagues found that the SIM did not turn up the information needed to detect and respond to threats.
The problem is that a SIM is vertical; it is built to serve one purpose, Farries said. It’s a security tool for the security team. Drawing in and dispersing data logs to other departments can be rickety, he said. The company eventually switched to Splunk for better cross-department data management, he said.
“It’s a platform for us, so we bring all the data in, it’s consumed by IT security, it’s consumed by DevOps and operations,” Farries said. The desktop team can also use it to detect application problems. Security can use all data brought in from any endpoint for detection and forensics capabilities, he said. “So for us it’s like a fabric, a foundation.”
Security can freely build use cases on the fly with the Splunk platform, says Ikenna Nwafor, senior information security specialist at TransAlta. Historically, this was far from the case, he said. “We would most likely need to engage a third party contractor […], somebody who is a specialist in that field,” he said.
Cross-department utility and a holistic view of security programs highlight another Splunk benefit: “Being able to communicate with the stats to senior management around getting the necessary buy-in to proceed with whatever initiatives we want […],” Nwafor said.
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Splunk.conf 2017. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Register For Splunk.conf 2017
Please fill out the information below. You will recieve an email with a verification link confirming your registration. Click the link to automatically sign into the site.
You’re almost there!
We just sent you a verification email. Please click the verification button in the email. Once your email address is verified, you will have full access to all event content for Splunk.conf 2017.
I want my badge and interests to be visible to all attendees.
Checking this box will display your presense on the attendees list, view your profile and allow other attendees to contact you via 1-1 chat. Read the Privacy Policy. At any time, you can choose to disable this preference.
Select your Interests!
add
Upload your photo
Uploading..
OR
Connect via Twitter
Connect via Linkedin
EDIT PASSWORD
Share
Forgot Password
Almost there!
We just sent you a verification email. Please verify your account to gain access to
Splunk.conf 2017. If you don’t think you received an email check your
spam folder.
In order to sign in, enter the email address you used to registered for the event. Once completed, you will receive an email with a verification link. Open this link to automatically sign into the site.
Sign in to gain access to Splunk.conf 2017
Please sign in with LinkedIn to continue to Splunk.conf 2017. Signing in with LinkedIn ensures a professional environment.
Are you sure you want to remove access rights for this user?
Details
Manage Access
email address
Community Invitation
Kent Farries & Ikenna Nwafor, TransAlta | Splunk .conf 2017
Kent Farries & Ikenna Nwafor, TransAlta, sit with Dave Vellante and John Walls at Splunk .conf 2017 in Washington, D.C
#splunkconf17 #theCUBE
https://siliconangle.com/2017/11/27/best-defense-good-offense-case-new-data-security-platforms-splunkconf17/
The best defense is a good offense: The case for new data security platforms
Sec officers’ fundraising platform
A data platform for security, as opposed to a simple tool, might be a swifter sell across departments, and to management too.
TransAlta Corporation is a power generator and wholesale marketing company based in Calgary, Canada. Before 2009, cyber security was not a high priority for the company, Kent Farries, IT security at TransAlta, told theCUBE. In that year, it first implemented a security information event management solution. (A SIM is basically log management.) Farries and his colleagues found that the SIM did not turn up the information needed to detect and respond to threats.
The problem is that a SIM is vertical; it is built to serve one purpose, Farries said. It’s a security tool for the security team. Drawing in and dispersing data logs to other departments can be rickety, he said. The company eventually switched to Splunk for better cross-department data management, he said.
“It’s a platform for us, so we bring all the data in, it’s consumed by IT security, it’s consumed by DevOps and operations,” Farries said. The desktop team can also use it to detect application problems. Security can use all data brought in from any endpoint for detection and forensics capabilities, he said. “So for us it’s like a fabric, a foundation.”
Security can freely build use cases on the fly with the Splunk platform, says Ikenna Nwafor, senior information security specialist at TransAlta. Historically, this was far from the case, he said. “We would most likely need to engage a third party contractor […], somebody who is a specialist in that field,” he said.
Cross-department utility and a holistic view of security programs highlight another Splunk benefit: “Being able to communicate with the stats to senior management around getting the necessary buy-in to proceed with whatever initiatives we want […],” Nwafor said.