What’s the difference between SEM, SIM and SIEM?
As three very similar yet distinct types of processes, the three acronyms SEM, SIM and SIEM tend to get confused, or cause confusion for those who are relatively unfamiliar with security processes.
Both of these types of information collection have to do with collecting security log information or other similar data for long-term storage, or to analyze the security environment of a network.
The key difference is that in security information management, the technology is simply collecting information from a log, which may consist of various different types of data. In security event management, the technology is looking more closely at specific types of events. For instance, experts often cite a "superuser event" as something that security event management technology would be looking out for. You may imagine technologies specifically designed to look for suspicious authentications, account logons or high-level management access at specific times of the day or night.
The acronym SIEM or security information event management refers to technologies with some combination of security information management and security event management. Since these are already very similar, the broader umbrella term can be useful in describing modern security tools and resources. Again, the key is to differentiate the event monitoring from the general information monitoring. Another key way to distinguish these two is to look at security information management as a kind of long-term or broader process, where more diverse data sets may be analyzed in more methodical ways. Security event management, by contrast, is again looking at the specific types of user events that may constitute red flags or tell administrators specific things about network activity.
More Q&As from our experts
- What is TensorFlow’s role in machine learning?
- Why are companies paying so much for AI professionals?
- Are autonomous vehicles safer than cars operated by humans?
- Security Event Management
- Security Information Management
- Security Incident and Event Management
- Information Assurance
- Wi-Fi Protected Access
- Wi-Fi Protected Access II
Tech moves fast! Stay ahead of the curve with Techopedia!
Join nearly 200,000 subscribers who receive actionable tech insights from Techopedia.