Skip to main content

Onderwerp

SIEM

Security Information and Event Management (SIEM) provides the ability to gather security data from information system components and present that data as actionable information via a single interface. SIEM software products and services combine Security Information Management (SIM) and Security Event Management (SEM). They provide real-time analysis of logfiles and security alerts generated by applications and network hardware. Vendors sell SIEM as software, as appliances, or as managed services.

SIEM products often do data aggregation (log management), analysis and alerting (for instance through correlation of events), data presentation through dashboards, are also used to contain security data (retention) and generate reports for compliance purposes. Some have forensic data analysis features included. The biggest challenge is limiting the number of false positives that can overflow the user and finetuning it to the IT- and threat landscape.

Related Keywords: Monitoring, Event Correlation, Managed Security Service Provider (MSSP), information assurance, log management, Security as a service (SECaaS)