*Magic Quadrant for Security Information and Event Management, Kelly Kavanagh et al., 8 February 2020
Gartner does not endorse any vendor, product or service depicted in any Gartner Research publication. Nor does it advise technology users to select only those vendors with the highest ratings or other designation. Gartner Research publications consist of the opinions of Gartner Research and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

A new form of security operation realized through collaboration between humans and machines

Security Communication Vol.5

July 1, 2020

Macnica /Delivering security information that would be nice to know

  1. Top 10 UEBA Security Use Cases
  2. What is "SOAR", a solution that realizes a system where operators can concentrate on the work that "people" should do?

1. Top 10 UEBA Security Use Cases

UEBA (User and Entity Behavior Analytics) is one of the fastest growing areas of enterprise security, growing at a compound annual growth rate of 48% according to Gartner. Modern enterprise IT security solutions use this technology to detect and neutralize advanced threats that traditional solutions fail to address.

In this article, we will introduce the top 10 security use cases using UEBA.

2. What is "SOAR", a solution that realizes a system where operators can concentrate on the work that "people" should do?

In recent years, cyber threats such as targeted attacks have become more sophisticated, increasing the burden on security operations. The shortage of security engineers and IT personnel and the lack of skills are becoming serious, and the current situation is that they are approaching their physical and mental limits. As one of the solutions, the automation of security operations by SOAR (Security Orchestration and Automated Response) is attracting attention. SOAR is a security operation platform that works with various security products. By introducing SOAR, companies can obtain many benefits such as "automation of operations", "speeding up incident response", and "resolving lack of skills".