SIEM and SOAR systems Flashcards
What does SIEM stand for
SEcurity information and event management
What does SIEM do?
It gathers a immense amount of data, with the ability to do firewalls, IDS, IPS solutions. Then you can log, aggregate, normalized, and review. The main components are security Infomation management and Security Event management.
What is the SIM (security Information Management?
Collects and stores then aggregates log data for your review
What is a SEM (Security Event Managemet)
collects any threats or events that are occuring, then aggregate and then normalize for your review
What is security orchestration automation response?
It is a very manual response that provides an automated response, with a streamiline the response process while used in conjuction with a SIEM