With the spread of cloud use and remote work, corporate IT environments are becoming more complex every year. As a result, the importance of security information and event management (SIEM) for cross-sectional visibility and analysis of logs and alerts is rapidly increasing.
On the other hand, there are many voices such as "I don't know which SIEM to choose" or "I have introduced it but I can't use it."
In this article, we will summarize and explain the ideas when selecting a SIEM and the points to keep in mind in practice.
1. Clarify what you want to achieve with your SIEM
The most important part of SIEM selection is verbalizing what you expect from a SIEM.
Common implementation purposes include:
- Early detection of security incidents and prevention of damage spread
- I want to centrally manage logs from multiple systems and products.
- Trail management for audit and internal control response
- Improving the efficiency and sophistication of SOC (Security Operation Center) operations
If "putting in a SIEM" becomes the purpose itself,
Alerts are coming out but no one is watching, No one can analyze
It is easy to fall into such a state.
Organize the threats you want to detect, the assets you want to protect, and the people who will actually operate them, and then move on to product comparisons.
2. Check Log Collection Coverage and Future Scalability
The value of a SIEM is largely determined by which logs can be collected.
Here are the main points to check:
- Can I import cloud (Azure/AWS/GCP) logs as standard?
- Collaboration with major security products such as EDR, FW, Proxy, and IdP
- Can it be extended with APIs and connectors?
- Is it possible to link products that are scheduled to be introduced in the future?
Especially in companies that are using the cloud,
Whether or not a cloud-native SIEM is an important decision.
3. Enrichment of detection rules and ease of tuning
SIEM is not a "deploy and end" tool, but a tool that grows while operating.
Let's check from the following perspectives.
- Quantity and quality of standard detection rules
- Is it easy to tune to reduce false positives and over-detections?
- Can you add or modify your own rules?
- Is correlation analysis and behavior detection possible?
As a common mistake,
"There are too many alerts to respond to, and I end up not seeing them."
There is a case where
It is very important that the design is possible to assume actual operation and assume improvement.
4. Look at compatibility with your company's operational system (in-house or SOC)
SIEM is a product that is difficult to provide enough value on its own.
The following points should be sorted out in advance:
- Is it possible to monitor 24 hours a day, 365 days a year?
- Who will respond to the first and second responses to alerts?
- Judgment and escalation flow when an incident occurs
If it is difficult to operate in-house,
Using a combination of SIEM and SOC services is also a viable option.
When tools and operations are divided,
"There are alerts, but I don't know how to judge."
You need to be careful because it is easy to get into this state.
5. Understand the cost structure and estimate it in the medium to long term
SIEM costs tend to be more inflated than upfront costs.
Typical cost factors include:
- Pay-as-you-go billing based on the amount of logs ingested (GB/day/GB/month)
- Log retention period (retention)
- Advanced analytics and visualization options
Even if there is no problem at the beginning of the introduction,
As the amount of logs increases, there are many cases where the cost is higher than expected.
It is important to estimate in anticipation of future system growth and log growth.
Summary: SIEM selection is not "tool selection" but "operational design"
The important thing in SIEM selection is to think about the following flow:
- What is SIEM used for?
- What logs do you want to collect and what do you want to detect?
- Who operates and makes decisions and how?
- Is the cost acceptable in the medium to long term?
SIEM is a security foundation that is continuously improved, not just an end of implementation.
Please review your company's security maturity and operational system to select the best SIEM.
Colorkrew Security supports Microsoft Sentinel, a SIEM provided by Microsoft, from deployment to operation.
It is also possible to design the optimal implementation of logs and analysis policies that should be acquired while considering costs.
In addition, Microsoft Sentinel does not incur additional usage charges if it stops collecting logs.
It is also suitable for small starts, such as "I want to build an environment first and see what kind of analysis is possible."
If you are considering using or implementing Microsoft Sentinel, please feel free to contact us.