A company should, in particular, ask itself the following questions:

  • Do we have a centralized view of security events?
  • Do we know how to detect unusual connections?
  • Are we monitoring privileged accounts?
  • Do we keep the logs long enough?
  • Are the logs protected against modification?
  • Are our systems synchronized in time?
  • Do we know how to reconstruct the chronology of an incident?
  • Are we monitoring cloud environments?
  • Are we monitoring identities?
  • Do we have any documented use cases for detection?
  • Are our SIEM rules tested?
  • Are we measuring false positives?
  • Do we have a procedure in place when a critical alert appears?
  • Do we know who analyzes the alerts outside of business hours?
  • Have we tested our ability to detect ransomware?
  • Have we tested the detection of lateral movements?
  • Do we know which MITRE ATT&CK techniques we are capable of detecting?
  • Are our logs sufficiently protected to be used in an investigation?
  • Have we assessed the true cost of storage and analysis?
  • Is our SIEM strategy aligned with our risk analysis?

If several answers are negative, the problem is not necessarily the absence of a SIEM.

It may be more fundamental: the company may still lack a real cybersecurity detection and monitoring strategy.

The SIEM should therefore be considered not as the first step, but as one of the building blocks for constructing this capability.

Categories: