Security Information and Event Management
Also known as:SIEM
Security Information and Event Management: Collects and correlates security events for monitoringMonitoringThe continuous observation of systems, identities, networks, and controls for relevant changes., alerting, and evidence gathering. This capability supports the early detectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. of suspicious activity. Effective results require high-quality data sourcesData SourceA system, sensor, log, or repository that supplies data for security analysis and decisions., aligned detection logicDetection LogicRules, queries, models, and conditions used to identify suspicious behavior., triage, and continuous optimizationContinuous OptimizationOngoing tuning of rules, processes, and resources using measured operational results..
How it works and where it fits
Security Information and Event Management connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- Security Operations CenterSecurity Operations CenterA central function for the continuous monitoring, analysis, and response to security events.: A central function for the continuous monitoring, analysis, and response to security events.
- Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.
- Threat HuntingThreat HuntingSearches for previously undetected attacker activity based on hypotheses.: Searches for previously undetected attacker activity based on hypotheses.
- Continuous MonitoringContinuous MonitoringOngoing monitoring and assessment of security states, events, and deviations.: Ongoing monitoring and assessment of security states, events, and deviations.