FIM Test: A Method for Distinguishing True FIM Capabilities in a Crowd of Claims


In a previous blog, we presented NIST’s benchmark definition of integrity monitoring.
The conclusion was clear: Many vendor claims of file integrity monitoring (FIM) capabilities do not match this definition.

[…Keep reading]

FIM Test: A Method for Distinguishing True FIM Capabilities in a Crowd of Claims

FIM Test: A Method for Distinguishing True FIM Capabilities in a Crowd of Claims

In a previous blog, we presented NIST’s benchmark definition of integrity monitoring.
The conclusion was clear: Many vendor claims of file integrity monitoring (FIM) capabilities do not match this definition.
Change detection across system components, including files, is crucial and implemented in many tools, including EDR/XDR. However, while these systems often claim FIM capabilities, file change detection alone falls short of true FIM.

*** This is a Security Bloggers Network syndicated blog from Cimcor Blog authored by Dan Schaupner. Read the original post at: https://www.cimcor.com/blog/fim-test-a-method-for-distinguishing-true-fim-capabilities

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.