A SIEM is never truly “finished”.
The environment is changing:
- new applications
- new servers
- new cloud providers
- new users
- new threats
- new attack techniques.
The rules must therefore change.
False positives must be analyzed.
New scenarios need to be added.
The old rules must be either removed or improved.
SIEM should be viewed as a continuous operational process, not just an IT project.