What are the core benefits of Trend Micro Deep Security System Security per Server (VM) Corporate?
Central management – All servers managed from the on-premises Deep Security Manager.
Change detection – Alerts on unexpected file, registry, service and port changes.
Log analysis – Parses operating system and application logs for security events.
Platform coverage – Agents for Windows and Linux physical, virtual, cloud servers.
SIEM forwarding – Sends integrity and log events to syslog-based SIEM tools.
Important note – No anti-malware or intrusion prevention in this package.
Integrity Monitoring – Detects changes to files, registry, services, processes, ports and software.
Log Inspection – Analyses operating system and application logs and correlates security events.
Deep Security Manager – Web-based console for policies, events, alerts and reports.
Deep Security Agent – One agent enforces the policies on Windows and Linux servers.
Event forwarding – Integrity and log inspection events can be forwarded via syslog.
Important – No anti-malware, web reputation, firewall or intrusion prevention included.
Deep Security System Security covers the system-level controls of Deep Security Software, integrity monitoring and log inspection, and is administered on premises through the Deep Security Manager console. Deep Security is now offered under the TrendAI brand, and TrendAI Vision One Endpoint Security – Server & Workload Protection is the cloud-managed successor platform to which Deep Security Manager offers a built-in migration path.
Evidence of changes – Baseline comparison shows what changed on a server and when.
Less manual log review – Rules and decoders filter relevant events from large log volumes.
Rule recommendations – Recommendation scans suggest rules matching installed systems and applications.
Existing SIEM integration – Events flow into existing SIEM platforms instead of a separate silo.
On-premises data control – Events stay in your own Deep Security Manager database.
Expandable in place – Further Deep Security modules activate in the same console and agent.
System Security suits organisations that run their own server infrastructure and have staff who can operate Deep Security Manager, including its database and rule tuning. It is most useful where auditors or customers ask for file integrity monitoring and central log evidence on servers. Small businesses without IT staff will usually find a self-hosted management server too much overhead for this scope.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Occasional | Common | Standard |
| File integrity monitoring and log evidence on servers | Rarely required | Often required | Usually required |
| This product fits | Limited | ✓ | ✓ |
Since 1 April 2025, the revised Information Security Act has required operators of critical infrastructure, such as energy suppliers, hospitals and public authorities, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Most private companies outside these sectors are not directly subject to this obligation, but often face similar expectations through customer contracts. Deep Security System Security supports the detection and reconstruction part of such a report: integrity monitoring shows which files, services or registry entries changed, and log inspection provides the time-stamped events needed to describe what happened. It does not detect or block malware, does not shield vulnerabilities, and does not create or submit the report itself. This information does not constitute legal advice; affected organisations should clarify their obligations with a legal specialist or directly with BACS.
No product makes a company compliant with the NIS 2 Directive, because the directive requires organisational risk management, not just software. Article 21 of the directive lists measure categories including risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, access control, cryptography and assessment of the effectiveness of security measures. System Security contributes to incident handling and effectiveness assessment by recording unauthorised system changes and security-relevant log events on protected servers, which can feed the 24-hour early warning the directive sets for significant incidents. It does not cover malware protection, vulnerability handling, backup and business continuity, encryption, multi-factor authentication or staff training, so these measures need other controls.
Yes, for the monitoring and evidence part of a typical supplier security questionnaire. System Security lets you answer questions on file integrity monitoring for servers, centralised collection and analysis of system logs, alerting on unauthorised configuration changes, and forwarding of security events to a SIEM. It does not let you answer questions on anti-malware for servers, intrusion prevention or virtual patching, endpoint detection and response, patch management, disk encryption, multi-factor authentication or backup. Where anti-malware and vulnerability shielding are the open items, moving to Deep Security Enterprise closes them with the same agent and console, which is simpler than adding a second vendor's server agent. Patch management, encryption, multi-factor authentication and backup require separate products in any case.
The decisive difference is threat prevention: System Security detects and records changes and log events, while Deep Security Enterprise also blocks malware and network attacks. Enterprise adds anti-malware with web reputation as well as the firewall and intrusion prevention modules, including virtual patching that shields known vulnerabilities until a patch is installed. Both packages use the same Deep Security Manager and the same agent, so switching does not require a new deployment. System Security is the narrower choice when another server anti-malware product is already in place and only monitoring and log evidence are missing.
| Capability | System Security | Enterprise |
|---|---|---|
| Integrity monitoring | ✓ | ✓ |
| Log inspection | ✓ | ✓ |
| Anti-malware | ✕ | ✓ |
| Web reputation | ✕ | ✓ |
| Host firewall | ✕ | ✓ |
| Intrusion prevention and virtual patching | ✕ | ✓ |
| Deep Security Manager console | ✓ | ✓ |
System Security does not prevent attacks on its own: without anti-malware or intrusion prevention, a compromised server is reported rather than stopped, which is the most common reason for a later move to Deep Security Enterprise. Deep Security Manager runs on your own infrastructure, so installing, maintaining and updating the manager and its database remains your responsibility. Agentless integrity monitoring through the Deep Security Virtual Appliance depends on VMware NSX, and the appliance reaches end of extended support on 31 December 2027, or earlier if VMware ends support for NSX 4.x first. Operating systems whose vendor support has ended receive only limited agent support, although integrity monitoring and log inspection rule updates continue for a defined period. New cloud-managed deployments are directed by the vendor to TrendAI Vision One Endpoint Security – Server & Workload Protection rather than to Deep Security Software.
Log Inspection reads Windows event logs and Linux syslog files, as well as application logs from web servers, mail servers, SSH, Samba and FTP services. Custom application logs can be added with your own rules and decoders.
Yes, integrity monitoring and log inspection can monitor Docker and Kubernetes objects for changes and security events. Runtime malware protection and intrusion prevention for containers require the corresponding additional modules.
Deep Security Manager supports multi-tenancy with separated tenant policies, but Multi-Tenant is a separate Deep Security package. System Security alone covers the monitoring functions, not the isolated tenant environments.
Trend Micro Deep Security System Security per Server (VM) Corporate, Trend Micro, TrendAI, Deep Security, server security, file integrity monitoring, log inspection, Deep Security Manager
Integrity monitoring and log inspection for Windows and Linux servers, managed in Deep Security Manager. Anti-malware is not included.
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies