Security Informationa and Event Monitoring with OSSIM

Hands-on Session 8 presented by TunisCERT

Wednesday — December 2nd, 2009 14:00

Wednesday — December 2nd, 2009 16:00

Security Information and Event Monitoring become a basic service for information system security management to provide real-time monitoring, alerts, log management as well as threat management by providing data correlation and analysis gathered from network security devices and applications. This session will cover the practical steps for deploying some open source solutions for security events monitoring. The main product will be OSSIM (Open Source Security Information Monitoring) as a mature solution for security event management; which will be coupled with several sensors such as Nagios and Snort.

Presenters

  • Haythem El Mir (Technical Department / NACS, TN) TN

    Haythem EL MIR is the technical manager of the National Agency for Computer Security (NACS), responsible on the national IT security projects, critical infrastructure protection, cyberspace monitoring, etc. With more than 7 years of experience as an information security professional; he acted as a member in the starting team which founded the NACS and the Tunisian CERT. He is now responsible on the national IT security projects, critical infrastructure protection, cyberspace monitoring, etc. He’s also involved in assisting several African countries in building and improving their information security capabilities Haythem is a certified information security professional CISSP, he is a security trainer and he is working as a consultant.