
Sign up to save your podcasts
Or


The worlds of IT security and operations are being pulled together and AI is a catalyst that's making it happen. The focus on observability that's been part of the DevOps movement, is playing an important role in improving security effectiveness and Scott Crawford, Mark Ehr and Mike Fratto return to look at how this is happening with host Eric Hanselman. Security teams have always wrestled with making effective use of telemetry data from the infrastructure and applications they are securing. Correlating data from just the security tooling is hard enough, let alone adding operational data to the mix. Security Information and Event Management (SIEM) systems came into existence many years ago specifically to address this problem, but they were complex to configure and operate and needed tending to stay accurate. The volumes of data coming from observability initiatives was promising, but new approaches were required and AI and ML have been key to unlocking that value.
Once again, we've hit an opportunity where it's all about the data and getting it to where it can be put to work. The Open Telemetry project simplified data interchange, but the question remained as to where all of this data had to live. It's not practical to get all of the data in one place, but data fabrics and federation can manage access effectively. Better correlation opens the door to many possibilities, including building a single source of truth for IT assets. There's a lot of benefit to bringing security and operations together.
More S&P Global Content:
For S&P Global subscribers:
Credits:
By S&P Global Market Intelligence4.9
2828 ratings
The worlds of IT security and operations are being pulled together and AI is a catalyst that's making it happen. The focus on observability that's been part of the DevOps movement, is playing an important role in improving security effectiveness and Scott Crawford, Mark Ehr and Mike Fratto return to look at how this is happening with host Eric Hanselman. Security teams have always wrestled with making effective use of telemetry data from the infrastructure and applications they are securing. Correlating data from just the security tooling is hard enough, let alone adding operational data to the mix. Security Information and Event Management (SIEM) systems came into existence many years ago specifically to address this problem, but they were complex to configure and operate and needed tending to stay accurate. The volumes of data coming from observability initiatives was promising, but new approaches were required and AI and ML have been key to unlocking that value.
Once again, we've hit an opportunity where it's all about the data and getting it to where it can be put to work. The Open Telemetry project simplified data interchange, but the question remained as to where all of this data had to live. It's not practical to get all of the data in one place, but data fabrics and federation can manage access effectively. Better correlation opens the door to many possibilities, including building a single source of truth for IT assets. There's a lot of benefit to bringing security and operations together.
More S&P Global Content:
For S&P Global subscribers:
Credits:

1,942 Listeners

2,688 Listeners

1,647 Listeners

1,084 Listeners

1,834 Listeners

6 Listeners

1,450 Listeners

40 Listeners

9 Listeners

6 Listeners

658 Listeners

226 Listeners

27 Listeners

28 Listeners

9 Listeners

4 Listeners

63 Listeners

29 Listeners

11 Listeners

9,935 Listeners

4 Listeners

5,520 Listeners

197 Listeners

1 Listeners

60 Listeners

179 Listeners

148 Listeners

6 Listeners

3 Listeners

0 Listeners

6 Listeners

5 Listeners

5 Listeners

48 Listeners