We can consider several levels of maturity.

Level 1 — Collection

The company collects the logs.

Level 2 — Centralization

The logs are grouped together.

Level 3 — Alerting

Some rules generate alerts.

Level 4 — Correlation

Several events are analyzed together.

Level 5 — Threat Detection

The detections are built around attack scenarios.

Level 6 — Threat Hunting

Analysts are actively looking for suspicious behavior.

Level 7 — Automation

Some responses are automated.

Level 8 — Continuous Improvement

Detection systems are regularly tested, measured, and improved. The level of maturity naturally depends on the context and resources of the organization.

Categories: