A mature SIEM project should include, in particular:
1. Asset Mapping
Knowing what you own.
2. Risk Analysis
Identify what needs to be protected as a priority.
3. Definition of use cases
Determine what you want to detect.
4. Logging Strategy
Determine what data is needed.
5. Data Collection Architecture
Define how the data will be retrieved.
6. Standardization
Make the events comparable.
7. Detection
Develop relevant rules.
8. Prioritization
Define what requires intervention.
9. Procedures
Determine what to do when an alert appears.
10. Tests
Validate detection capabilities.
11. Measurement
Monitor performance.
12. Continuous Improvement
To develop capabilities.