Section 23.222 Security Information and Event Management (SIEM) Flashcards
Objective 4.4 Explain security alerting and monitoring concepts and tools
SIEM (Security Information and Event Management)
A solution for real-time or near-real-time analysis of security alerts generated by network hardware and applications
■ SIEM helps correlate various events and incidents from system logs
Importance of Log Reviews
Critical for security assurance
■ Logs should be reviewed regularly and routinely, not just after an incident or as part of an instant response
SIEM Functionality
■ Correlates and analyses log data
■ Consolidates data from various systems into a centralized database or repository
■ Detects patterns indicating security threats
■ Generates alerts for security teams to investigate
Agent-Based vs. Agentless SIEM
Agent-Based
● Software agents are installed on each system to collect and send log data
● Provides real-time data and detailed information
Agent-Based vs. Agentless SIEM
Agentless
● Log data is collected directly from systems using standard protocols
● Reduces maintenance but may not collect real-time or detailed data
SIEM Implementation Considerations
■ Log all relevant events and filter out irrelevant data
■ Establish and document the scope of events
■ Develop use cases to define threats
■ Plan incident response actions for different events
■ Establish a ticketing process to track flagged events
■ Schedule regular threat hunting to detect unnoticed events
■ Provide auditors and analysts with an evidence trail
Common SIEM Solutions
Splunk
● Big data information gathering and analysis tool
● Offers connectors for various data systems
● Provides search processing language for data analysis
● Comes with pre-configured templates and dashboards
Common SIEM Solutions
ELK (Elastic Stack)
A collection of free and open-source SIEM tools, including the following
○ Elasticsearch
○ Logstash
○ Kibana
○ Beats
Components work together for log collection, storage, analysis, and visualisation
Common SIEM Solutions
ArcSight
SIEM log management and analytics software
● Suitable for compliance reporting for regulations like HIPAA, SOX, and PCI DSS
Common SIEM Solutions
QRadar
● A SIEM log management, analytics, and compliance reporting platform created by IBM
● Offers a dashboard for data visualisation and analysis