A SIEM project can fail if the company starts directly with:

“Which SIEM are we going to buy?”

The first question should rather be:

“What threat scenarios do we want to detect?”

Afterwards :

“What data do we need to collect to detect them?”

Then :

“How will we analyze and process the alerts?”

And finally:

“Which technology meets these needs?”

This approach helps avoid the syndrome of:SIEM installed but useless.

Categories: