From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,900 courses taught by industry experts.

Security data analytics

Security data analytics

- In this lesson, we're going to discuss security data analytics. Now, security data analytics consists of the tools used to collect aggregate, correlate, and analyze large amounts of data and information from across your devices and your enterprise architecture in order to identify security incidents and perform threat detection. To achieve this, you're normally going to utilize a security event and information management system, known as a SIEM, at a minimum, or, you may use a more complex security data analytics platform. These systems are used to collect data from numerous sources like endpoint protection software, identity and access management, or IAM tools, threat feeds, network traffic, IDS and IPS sensors, cloud platforms, applications used across your enterprise, and many other data sources. These platforms are going to be used first to collect all that data and then to normalize it and consolidate it for further analysis. Since everything we collect is coming from different…

Contents