Security Information and Event Management (SIEM) tools have struggled to meet expectations for proactive, real-time defense because organizations collect overwhelming volumes of logs and events that are difficult to calibrate. Separating benign anomalies from genuine incidents often requires extensive manual tuning, which has made SIEM more effective for auditing and compliance than for rapid response to serious attacks.
Real-Time Security Intelligence (RTSI) emerged as an evolution of SIEM, still based on collecting and correlating activity data, but distinguished by advanced analytics from big data and business intelligence. By applying sophisticated algorithms and shared intelligence, RTSI aims to continuously self-calibrate, detect serious threats more reliably, and enable automatic mitigation when threats are perceived.
A key security priority is protecting privileged access. Rather than attempting exhaustive monitoring everywhere at once, risk mitigation should begin with accounts and entitlements that can cause the greatest damage if compromised—typically administrator or root credentials. Privilege Management (PxM) has therefore become a mandatory element of enterprise security, with vendors offering discovery of privileged accounts, secure vaulting, access monitoring, and in some cases real-time analytics.
IBM Security Privileged Identity Manager (SPIM), launched in 2012 and derived from IBM Identity Manager and Access Manager for Enterprise Single Sign-On, is an appliance-based privileged credential and access management solution. It provides vaulting, centralized administration, workflow-based access requests, automated password rotation, application identity management via an App ID Toolkit, multi-factor authentication, session recording and replay, and reporting via IBM Cognos. SPIM integrates with IBM Guardium for discovery and fine-grained database monitoring, and with IBM QRadar for real-time anomaly detection and automated responses such as credential deactivation. It is deployed as a soft appliance on VMware or Xen and targets large enterprise environments, though it can be architecturally complex and may require additional IBM licensing for recertification and advanced detection/response.
See All Locations
See All Locations