Sunteți pe pagina 1din 2

Data Sheet

McAfee Enterprise Security Manager


Discover. Respond. Comply.

Effective security starts with real-time visibility into all activity on all systems,
networks, databases, and applications. McAfee Enterprise Security Manager enables
your business with true, real-time situational awareness and the speed and scale
Key Advantages required to identify critical threats, respond intelligently, and continuous compliance
Actionable information in
minutes instead of hours monitoring. McAfee Global Threat Intelligence (McAfee GTI) and McAfee ePolicy
Massive data collection across Orchestrator (McAfee ePO) software integration help you detect, correlate, and
a wide range of information
sources
remediate threats in minutes across your entire IT infrastructure.
Real-time threat and risk
McAfee Enterprise Security Manager revolutionizes Massive Data Collection
data integration and event
correlation
security information and event management A single McAfee Receiver can collect up to
Immediate access to years of
(SIEM) by integrating security intelligence with 18,000events per second. The McAfee Enterprise
event and flow data information management for enterprise situational Security Manager itself can support multiple
Supports monitoring and awareness. We connect a real-time understanding distributed receivers, and is able to handle
reporting against more than of the world outsidethreat data, reputation hundreds of thousands of events per second
240 regulations data, and vulnerability newswith a real-time without compression or aggregation. With
Integrated tools for improved
understanding of the systems, data, and activities aggregation, a single appliance can support tensof
security workflow inside your enterprise. millions of events per secondenough to address
Flexible, hybrid delivery options
the demands of the largest enterprisenetworks.
include physical and virtual IT can finally have complete and correlated access
appliances to the content and context needed for fast risk-
High-availability options
Advanced Risk and Threat Detection
based decisions, investing resources to best effect
Whether its network traffic, user activity, or
in a dynamic threat landscape.
application use, any variation from normal activity
Since the compliance burden continues to evolve, could indicate that a threat is imminent, and your
we consolidate audit and compliance activities network is at risk. McAfee Enterprise Security
within a single pane of glass to keep audit effort Manager calculates baseline activity for all collected
and expense to a minimum. We make it easier to information across the enterprisein real time
achieve, maintain, and document compliance with and alerts you of potential threats before they occur,
unified support for the more than 240 regulations while at the same time analyzing that data for
in the Unified Compliance Framework. patterns that could indicate a larger threat.

Critical Facts in Minutes, Not Hours Context and Content Awareness


Our highly tuned database appliance can collect, When contextual information is availablefrom
process, and correlate billions of log events from vulnerability scanners, identity and authentication
multiple years with other data streams at the management systems, privacy solutions, or other
speed enterprises require. McAfee Enterprise supported systemseach event is enriched with
Security Manager is able to store billions of events that context, allowing for a better understanding
and flows, keeping all information available of how network and security events correlate to
for immediate ad hoc queries, forensics, rules real business processes and policies.
validation, and compliance.
McAfee Enterprise Security Managers scalability
Rapid access to long-term storage of event data and performance enables collection of more
is critical for investigating low-and-slow attacks, information from more sources, including
searching for indications of advanced persistent application content such as documents,
threats, or attempting to remediate a failed transactions, and communications, providing deep
compliance auditall of which require visibility forensics value. All that information is heavily
into historical data and full access to the complete indexed, normalized and correlated to detect a
details of each specific event. wider range of risks and threats.
Connecting Your IT Infrastructure McAfee Global Threat Intelligence Improved Event Management and Workflows
Two-way integration with An optional live feed of McAfee GTI IP Reputation Automated actions let you use prioritization to
McAfee ePO software extends data provides valuable, real-time information on manage security as risks change. For example, a
visibility and control across external bad actors gathered from hundreds of watch list can be set to flag dangerous activities, such
your entire security and millions of sensors around the globe allowing you to as contact with a known bad IP address. Or, you
compliance management pinpoint malicious activity on your network. McAfee might use McAfee ePO to take a range of corrective
environment. McAfee ESM can use the GTI IP Reputation data to quickly actions: issue new configurations, implement new
Enterprise Security Manager can identify conditions where an internal host has policies, or deploy a softwareupdate.
automatically detect and collect
communicated with a known bad actor.
data from McAfeeePO-managed To enhance security operations, McAfee Enterprise
data sources. Security Manager also provides integrated tools
Decisions Based on Risk and Asset Value
McAfee Enterprise Security for configuration and change management, case
Integration with McAfee Risk Advisor enables real-
Manager can also feed events management, and centralized management of
time risk management. Complementing the McAfee
(including correlated events) policyeverything needed to improve workflow and
GTI assessment of external risk factors, McAfee
back into the McAfee ePO facilitate daily information security operations.
Risk Advisor (MRA) scores internal assets based on
system, which can then be assigned value, providing you an environmental risk
transferred to other SIEMs, Policy-Aware Compliance Management
assessment. MRA provides accurate risk scores of
IT governance, risk, and McAfee Enterprise Security Manager makes
end points based on asset configuration, vulnerability,
compliance solutions, and and deployed controls along with available compliance management easy with hundreds of
McAfee Security Innovation countermeasure options. pre-built dashboards, complete audit trails, and
Alliance partner products. reports for PCI-DSS, HIPAA, NERC-CIP, FISMA,
The McAfee ESM correlation engine associates the GLBA, SOX, and others. Our support for the
external GTI threat feeds with the internal MRA Unified Control Framework also allows you to
risk scores to surface the events that matter to your report your policies against more than 240 global
organization, saving you time and alerting you faster
regulations and controlframeworks.
to potential problems. Visual indicators show trend
activity across all dashboards for at-a-glance analysis.

Figure 1. Dynamic baselines indicate anomalies at a glance.

System Specifications
Hardware ETM-X6 ETM-X4 ETM-6000 ETM-5600
Specifications

Collection Rates 300,000 events 150,000 events 70,000 events 50,000 events
persecond1 persecond1 persecond1 persecond1

Analytical Performance Less than 10seconds2 Less than 30seconds2 Less than 1minute2 Less than 3minutes2

For more information, visit Local Storage 14 TB3 + 3.2 TB Flash 14 TB3 + 800 GB SSD 14 TB3 8 TB3

mcafee.com/ESM. 1
Based on typical network environments using average event and flow aggregation.
2
Indicates the average response time to generate a monthly report consisting of all events that occurred over a period of 30 days.
3
Represents usable event and flow storage, after RAID configuration.

2821 Mission College Boulevard McAfee, the McAfee logo, ePolicy Orchestrator, McAfee ePO, McAfee Global Threat Intelligence, and McAfee GTI are registered trademarks or
Santa Clara, CA 95054 trademarks of McAfee, Inc. or its subsidiaries in the United States and other countries. Other marks and brands may be claimed as the property
888 847 8766 of others. The product plans, specifications and descriptions herein are provided for information only and subject to change without notice,
www.mcafee.com and are provided without warranty of any kind, express or implied. Copyright 2012 McAfee, Inc.
47101ds_esm_0612_fnl_ETMG

S-ar putea să vă placă și