Security
Spire in Action

June 19, 2006
"Security Metrics Workshop"
InfoSecurity Canada
Toronto, Canada

May 24, 2006
"Multiple Panels"
SecureWorld Expo
Chicago, IL

May 2, 2006
"Multiple Panels"
SecureWorld Expo
Atlanta, GA

April 19, 2006
"Multiple Panels"
SecureWorld Expo
Philadelphia, PA

April 13, 2006
"Security Metrics"
ISC2 Training
San Jose, CA

March 15, 2006
"Multiple Panels"
SecureWorld Expo
Boston, MA

March 9, 2006
"Security Metrics that Matter"
Archer Technologies User Conference
Orlando, FL

February 17, 2006
"Quantifying Risk - Security Metrics"
RSA Conference
San Jose, CA

December 14, 2005
"Multiple Panels"
SecureWorld Expo
Dallas, TX

December 8, 2005
"Vulnerability Management Panel"
InfoSecurity NY
New York, NY



  

security mystery revealed...
  ph. 610.644.9064 - petelind@spiresecurity.com   
home fourdisciplines services research ouranalysts briefingrequest events
Four Disciplines of Security Management

There are four basic disciplines of security management that provide the broad coverage necessary to protect any enterprise computing environment:

Identity Management (12 o'clock) - Identity Management is the practice of managing users and their corresponding user accounts. This discipline provides a basic level of control over who has access to the various networks and platforms in an enterprise. The flagship product category for Identity Management is user provisioning with web access control as the workhorse.

Vulnerability Management (6 o'clock) - Vulnerability Management is the security professional's strategic defense. This discipline focuses on identifying and remediating vulnerabilities or weaknesses in the components of any computing environment. The flagship product for Vulnerability Management is vulnerability assessment, with firewalls as the workhorse.

Threat Management (3 o'clock) - Threat Management is how we catch the bad guys. This discipline focuses on identifying and responding to anamolous and malicious events that occur throughout the network. The flagship product for Threat Management is security event management, with antivirus and intrusion detection as workhorses.

Trust Management (9 o'clock) - Trust Management is the practice of protecting and enabling activities that are of high risk to the enterprise. This discipline centers around encryption and access control techniques to create a secure process for authorized individuals. The flagship of Trust Management is Public Key Infrastructure (PKI), with Virtual Private Networks (VPNs) as the workhorse.

©2003 Spire Security LLC