The SIEM is often considered one of the central components of a:

Security Operations Center—SOC.

The SOC's mission includes, among other things:

  • monitor the environment;
  • detect threats;
  • analyze the alerts;
  • investigate the incidents;
  • coordinate the response;
  • improve detection capabilities.

SIEM provides a large part of the raw material needed for this activity.

The chain can be simplified as follows:

Sources → SIEM → Detection → Alert → Analysis → Investigation → Response

However, a SIEM is not a SOC.

A SIEM without processes, relevant rules, and analysts can produce a huge number of alerts without significantly improving security.

Categories: