The Jim Wells County Commissioners Court authorized the purchase and implementation of a Splunk security information and event management (SIEM) system after a presentation from Core Recon and a remote security analyst.
Dylan Posey, identified on the record as a security analyst with Core Recon, described the SIEM as a 24/7 monitoring capability that collects logs from firewalls, desktops, servers and cloud apps and correlates events to detect attacks. “This helps things get caught in minutes and not hours,” Posey said, noting the county’s need to speed incident detection and to meet state and federal requirements for systems that touch criminal-justice information.
Robert Silva of the county IT department presented the quote and implementation plan. The record lists a year-one implementation quote of $24,640.17 and an anticipated annual license cost around $24,000 thereafter. Silva said the county’s recent DPS/CJIS audit found noncompliance risks and that remaining CJIS compliance was a driver for the purchase.
A commissioner moved and seconded approval of the SIEM purchase; the court approved the motion on a voice vote. Staff said implementation would begin promptly, with the aim of meeting CJIS requirements and improving detection and logging capabilities.
Next steps: IT and Core Recon will carry out the implementation roadmap, pursue available grant funding noted in presentation materials, and report back to the court on progress and budget implications.