We must also avoid making excessive promises.

A SIEM does not guarantee that an attack will be detected.

Its capacity depends in particular on:

  • the quality of the logs
  • their availability
  • rules
  • configuration
  • techniques used by the attacker
  • of the available visibility
  • analysts' skills
  • of the context.

A SIEM should therefore be considered as a detection and visibility capability, and not as an absolute guarantee of security.

Categories: