Not all alerts present the same level of risk.

An unusual connection on a desktop computer does not necessarily have the same impact as an unusual connection on:

  • a domain controller;
  • a financial server;
  • a customer database;
  • an industrial system;
  • a backup server.

The SIEM must therefore incorporate the concept of criticality.

An alert can be enhanced with:

  • the criticality of the asset;
  • the user's identity;
  • the level of privilege;
  • the location;
  • the IP address;
  • threat intelligence information;
  • the history of behavior.

This allows for a better determination of events that require immediate intervention.

Categories: