Not all alerts present the same level of risk.
An unusual connection on a desktop computer does not necessarily have the same impact as an unusual connection on:
- a domain controller;
- a financial server;
- a customer database;
- an industrial system;
- a backup server.
The SIEM must therefore incorporate the concept of criticality.
An alert can be enhanced with:
- the criticality of the asset;
- the user's identity;
- the level of privilege;
- the location;
- the IP address;
- threat intelligence information;
- the history of behavior.
This allows for a better determination of events that require immediate intervention.