SIEM means:

Security Information and Event Management

In French:

security information and event management.

A SIEM is a platform that allows, among other things:

  • collect events;
  • centralize the logs;
  • normalize the data;
  • search for events;
  • to correlate several events;
  • detect suspicious behavior;
  • generate alerts;
  • prioritize incidents;
  • to facilitate investigations;
  • preserve historical records;
  • produce reports;
  • contribute to compliance processes;
  • to provide support to the SOC and CERT/CSIRT teams.

The SIEM concept historically resulted from the merging of two families of functions:

SIM — Security Information Management

The SIM was primarily geared towards:

  • the collection;
  • archiving;
  • research;
  • historical analysis;
  • report generation.

SEM — Security Event Management

The SEM was more oriented towards:

  • real-time monitoring;
  • the correlation;
  • detection;
  • the alerts;
  • the response to events.

Modern SIEM combines these different capabilities.

NIST already describes SIEM as a centralized logging technology capable of performing filtering, aggregation, normalization, and analysis of events from multiple sources.

Categories: