Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Know Your Data – Step One to Proper SIEM Selection
Articles

Know Your Data – Step One to Proper SIEM Selection

ISB Editorial StaffBy ISB Editorial StaffApril 20, 2016Updated:July 8, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

As IT systems become entrenched in almost every aspect of every business (yes, I know you have a friend of a friend who does fine carpentry and takes orders on paper… but I’ll bet even he relies on some IT systems to ensure he gets paid.), the need for Security Information and Event Management (SIEM) systems becomes almost mandatory.  Even a very small count of systems and technologies can quickly produce more logging information than any human can hope to, much less want to, review and process so using automated systems and even MORE computers makes complete sense.  Add to this, many industries or transactions involve compliance issues which require retention and monitoring of various security events and you quickly find that someone in the organization is researching top 10’s, ‘magic quadrants’, or some other reviews to determine their course of action.

Before building functional matrices and product scorecards, the best first step is to really look at the data your organization generates.

Know the systems you have.

Depending on the organization, the maturity level and the business model, you may have workstations, servers, network hardware and security devices, mobile platforms, application sets and a vast host of other systems.  Even in virtualized environments and cloud based SAAS solutions, business models where ownership or management of IT systems is kept to an absolute minimum, you will still contend with log management and monitoring issues.  Questions which need to be answered include:

  • What data is being generated?
  • How is data being transmitted, collected and stored?
  • How common is the data you have?
    • Do you rely on well-known vendors?
    • Do you create or maintain custom applications or platforms?
  • How MUCH data are you generating?

Answering these questions is the first step in setting the boundaries for your selection process.   Vendors specialize in many aspects of the SIEM spectrum and there’s little to be gained considering a solution which touts its ease of use based on common log sources if you know you need to support extensive custom logs and events.  Conversely, an organization with single-vendor solutions for PC, server and network solutions may not need to bear the added expense of solutions focused on flexibility.

Know the data you want to and need to keep.

As stated in the original paragraph, we work and operate amongst IT systems which generate vast quantities of data and it’s easy to develop a desire to store everything on the off chance you might need to or be able to use it later.   The biggest issues become the unexpected performance and price impacts you may incur.  Again, given your organizations regulatory requirements, there may be certain data you must keep and timeframes you must keep it.  Beyond that, there are certainly Use Cases promoted or supported by vendors and/or beneficial to your organization which require specific data sets.  These may develop and expand over time, requiring the inclusion of additional information. Making the effort to identify these needs and the progression of development and tailoring your data collection and retention accordingly can have significant impact on SIEM solution choices and this also leads into a final aspect of data knowledge.

Know what you want to do with your data.

Data abounds and use cases abound.  While certain alerting and correlations are either requirements or fairly straightforward correlations from common data sets, it’s worthwhile to take the time in the early stages to consider just what you want from your data.  Put another way, how intimate do you want to become with your data?    If information management is core to your business model, then the security or operational aspects gleaned from extensive review and processing of your data sets could give you a distinct economic advantage over your competition or avoid crippling losses from an undetected breach.  A deep understanding of your data sets and developing plans on how and how extensively you intend to inspect your logs will directly affect your SIEM selection criteria.

Ultimately, securing your IT systems and data is an exercise in risk management.   Although it can be difficult to project an ROI against an ‘avoided loss’, it’s clear that developing budgetary constraints is a requirement.  By taking the time to first learn about your logging data and developing a plan for what reporting is needed and then desired, you can tailor your SIEM selection criteria for your environment and match any given vendor’s strengths against your requirements.

[su_box title=”About Keith Lawman” style=”noise” box_color=”#336588″][short_info id=”67042″ desc=”true” all=”false”][/su_box]

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Understanding Cloud Access Security Brokers (CASB)

March 28, 202410 Mins Read

Decoding Cloud Security Posture Management (CSPM)

March 28, 202411 Mins Read

Master Cloud Compliance Tools: Achieve Regulatory Success

March 28, 202411 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}