![]() |
We are sometimes asked to compare our threat detection and response solutions to those custom assembled by security experts using various open source products. With a wide array of quality point solutions available, it’s natural to consider whether a combination of best-of-breed open source solutions can be a better option for a particular organization, rather than an integrated commercial solution. To start with, RSA is a big fan of open source software and open source threat intelligence, participating in the security sharing process. This collaborative tradition is strong in the security space, as we all battle the same adversaries to protect our organizations, and to keep the internet as safe as possible for everyone. In practical terms, this is a classic “build vs. buy” choice, and boils down to an organization’s preferences, available skills, and risk tolerance. While strong solutions are possible with either choice, the differences are important to understand.
So the choice is ultimately dependent on the organization making the decision. If done really well, a custom-integrated solution can be effective. However, with that choice you have to possess (and retain) the skills to do it. In addition, you make yourself dependent on multiple projects/vendors, increasing the risk that one may cease to maintain a solution, or fail altogether. Our approach is to integrate across our RSA offerings so customers don’t need to worry about that part, and to interoperate with any component a customer chooses to use in place. A common example is a customer adding RSA threat detection and response components to its existing SIEM solution. In this instance the analysis and detection takes place in the RSA framework, so you still get all the benefits of integration. One good piece of advice for anyone considering a threat detection and response solution – really for any IT decision – is to look out five years into the future, and consider changes that may impact your organization. Certainly internal considerations, such as maintenance of employee skills and organizational risk tolerance, will be important. It’s also critical to evaluate the probability that technology partners will continue to support your activities at a predictable and professional level. Remember that security is a process, not an event. When you choose something as critically important as a threat detection and response solution, you need to treat it as an ongoing commitment. It’s important to choose wisely.
Learn more about our threat detection and response capabilities in RSA NetWitness® Suite, as well as our participation in the security sharing process through RSA® Live and Live Connect, RSA® Link and RSA® Research threat intelligence sharing. The post A Security Decision – Build or Buy appeared first on Speaking of Security - The RSA Blog. |
