Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - You Need More Than a SIEM
Articles

You Need More Than a SIEM

ISBuzz TeamBy ISBuzz TeamJune 9, 2014Updated:September 4, 20144 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
2013 SIEM MQ
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

“I don’t know why my boss bought this. No one has time to use this!”

“I have enough people. But, no one knows how to operate this system, and vendors can’t help!”

These are common complaints of some of my previous customers. Perhaps they resonate with someone out there, as well. Either way, we are not too naive to think that our 24/7 monitoring protocol can be accomplished simply by purchasing a Security Information and Event Management (SIEM) system. When we talk about securing our organization, specifically in Managed Security Services (MSS), we are implicitly referring to three different elements. SIEM is just one of these.

(1) People

Like the second example complaint presented above, my company once purchased a SIEM that fell under the top position in the SIEM Magic Quadrant. But, no one knew how to operate it. Why? Most of the time, a training package does come with a purchase. The problem is that the quality of the training package varies, and in any circumstance, it takes time for our staff to absorb and implement the knowledge gained therefrom. Thus, we need to make sure that the vendor is able to provide quality training and that they are willing to commit 100% to help when our staff is having issues with the product. Of course, a person who knows how to operate the SIEM is not enough for our MSS team. We need to have security analysts, incident handlers, and malware analysts, among other personnel. It is even better to have a developer on the team to assist with any automated tasks.

(2) Technology

SIEM belongs in this element. Often, we will look for a product in the top position of its Magic Quadrant. However, that is not the case all time. There are lots of products to consider, and we need whatever solution we choose to perform its functions properly and reliably. Basically a SIEM collects all logs from our security devices that include firewall, IDPS, routers, proxy, etc. We need to ensure that the critical information stored on these devices will not be leaked by the SIEM. After all, if a router can have backdoors, the same possibility goes for SIEM. Also, we need to ensure that no data loss occurs, and that the logs are not intercepted during transmission. Different security environments require different technologies. Choose wisely!

(3) Process

Process connects people to technology. Without an efficient process, MSS will fail. We can create our own process or implement any existing framework to smoothen MSS. Based on my experience, Information Technology Infrastructure Library (ITIL) is a pretty good choice. The set of practices in this framework can be tuned to suit your MSS even if it is designed for IT service management. However, having an efficient process is not enough. You need to ensure that your team follows the process. As a result, the process should be codified in a handbook that all members in your team can remember and follow.

You need a team to secure your organization, not merely a product. Of course, it is undeniable that a good product can boost your team’s performance. So, next time you are about to buy a SIEM, make sure you consider the three elements listed above – People, Technology and Process.

By Ong Yew Chuan, Info Sec Enthusiast

Professional Biography:

OngYewChuanAn Information Security enthusiasm. Have 3 years of experience working in a Managed Security Services (MSS) company. Now working as a researcher in one of the public universities in Malaysia, focusing in security and social networks. Posed few professional certificates which included ECSA, CEH, CHFI and ITIL.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}