SIEM stands for "Security Information and Event Management". It is a set of tools and services that offer a holistic view of any organisation's information security. It works by combining two technologies:
Security information Management(SIM)
, which collects data from the log files and runs an analysis on the security vulnerabilities and reports them, and Security Event Management(SEM)
which monitors any system on a areal-time basis and also keeps the network admins notified about the threats. SIEM
is used to identify threats and anomalies in the network, cyber attacks from gigs of data.SIEM requirement in Cyber Security
Cyber Security Incident detection: SIEM is the primary tool used in teh detection of security incidents by collecting logs from all the data sources across the network and triggers an alert on successful match of condition defined in the correlation rule. In other words, it triggers an alert in case any network anomaly is detected in the network.
Regulatory Compliance: Its is also used to comply with many security compliances like,
PCIDSS (Payment Card Industry Data Security Standard)
, ISO
, HIPPA
and ensure that the company assets within the network meet the requirement of the compliance.Effective Incident Management: Dashboard logging, Search Queries, reports are some of the features that
SIEM
tools provide which allow the security professionals to handle the security breaches.SIEM Architecture:
SIEM architecture
. It has a correlation engine where we define a correlation rule where we match a specific rule and trigger and alert based on the match. It is a centralized management to identify and monitor different cyber attacks based on the condition which we define in the rule.Some of the
SIEM
platforms provided by different vendors in the market: