Skip to main content
REF-SOL-007

SIEM

Collects and analyzes data from multiple sources to give real time insight into the security of a network, correlating events that would look harmless in isolation.

Definition

One place the whole estate reports into.

Security Information and Event Management collects and analyzes data from multiple sources to give real-time insight into the security of a network. It is used to detect and respond to threats as they happen, and to analyze historical data for incidents that were missed at the time.

Implementing one requires planning against your actual environment: the size and complexity of the network, and the type of data that has to be collected and analyzed. The onboarding and deployment service exists to get the platform running and to use its capabilities fully, rather than leaving most of them switched off.

Deployment

Five phases.

1

Requirements Gathering

Initial assessment of what needs to be monitored.

2

Design

Plan the system architecture.

3

Implementation

Deploy the platform.

4

Fine-tuning

Optimize configuration and reduce noise.

5

Training

Enable your team to operate the platform day to day.

Data Source Integration Custom Rules & Alerts Reports & Dashboards Tool Integration Training & Documentation
A column of log storage servers with drive activity lights
Deliverables

What you receive.

01

Data sources integrated

Every source that generates security events and logs wired in: firewalls, intrusion detection systems, and servers.

02

Custom rules and alerts

Rules written to detect incidents in your environment, and alerts that notify the security team when they fire.

03

Reports and dashboards

Customized views of your security posture, including the statistics and trends behind the events.

04

Integration with other tools

Connected to vulnerability scanners and threat intelligence feeds so the platform reads more than its own data.

05

Training and documentation

Your users trained on operating the platform, with documentation for ongoing operations and maintenance.

FAQ

Common questions.

What does a SIEM give us that individual tools do not?

Correlation. It collects and analyzes data from multiple sources, which surfaces events that look harmless on their own but form a pattern when read together.

How do you stop it generating constant noise?

Fine-tuning is a dedicated deployment phase, optimizing the configuration and reducing false positives before the platform is handed to your team.

Is the deployment planned around our environment?

Yes. Requirements gathering establishes what needs to be monitored, and the design phase plans the system architecture around that before anything is implemented.

What do we receive at handover?

Data source integration, custom rules and alerts, reports and dashboards, integration with your existing tools, and training with documentation.

Ready to scope SIEM?

Request an Assessment
Request an Assessment Email Us