SIEM should never be considered as a sole form of protection.

A mature cybersecurity architecture typically relies on several layers:

Prevention

  • firewall
  • MFA
  • segmentation
  • EDR
  • hardening.

Detection

  • SIEM
  • EDR/XDR
  • IDS
  • monitoring.

Answer

  • SOC
  • SOAR
  • incident procedures.

Resilience

  • backups
  • PRA
  • PCA
  • redundancy.

Governance

  • policies
  • risk management
  • compliance
  • audits.

The SIEM is primarily located in the following layers:detection + investigation + monitoring.

Categories: