ArcSight Roles

Written by

in

A SIEM is tool that allows an organization to have a watchful eye on its territory.
ArcSight is such a robust system that the organization must have many hands adjusting the lenses and apertures of this monitoring device.
The organization assigns roles to manage this system:

ArcSight Administrator.  This role is sometime known as ArcSight Integrator , ArcSight Architect, or ArcSight engineer.  This role will include installation and operational maintenance of the ArcSight system.  They will need to be muliti-disciplined and a bit of a quick study because they must know networking, security, server, and database fundamentals.  They will almost definitely need to be comfortable in multiple operating systems.  They will have to install ESMs, connectors, loggers and other ArcSight products.  They may also need to model the network, develop system resources as well as reports and KB articles as an ArcSight author.

ArcSight Analyst.  This role is a discipline within ArcSight.  Other names include Content developer, ArcSight Security Analyst, ArcSight Operator.  They are responsible for monitoring events and investigating with correlation and research.  They also may conduct incident handling which is a good reason to have skills in SANS GCIH (www.giac.org/certification/certified-incident-handler-gcih) GIAC Certified Incident Handler.  The Analyst will be familiar with the ArcSight Console’s active channels, report/query generating tools and notifications.
www.sans.org/reading_room/whitepapers/incident/

Security Manager.  Also known as the customer, the Business user, they are the management that runs the security operations.  They should be responsible for generating a use case for ArcSight.

ArcSight Consultant. This is a very broad term because the consultant can do either Analyst or Administration.  Consultant work is really based on the needs of the security manager.  Also, the consultant can be an independent contractor or an employee.

Ready to actually get the RMF/ISSO job?

Go from reading about the Risk Management Framework to doing it — with the full video course, the books, and a community of GRC professionals taught by Bruce Brown (CISSP, CGRC).

Get the RMF ISSO Foundations course → Browse the RMF & GRC books Join the free GRC community

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *