MemotivaCISSP Flashcards: Security Operations, Incident Response, Forensics, Logging

What is a Security Information and Event Management system?

CISSP Flashcards: Security Operations, Incident Response, Forensics, Logging

Audio flashcard · 0:32

Nortren·

What is a Security Information and Event Management system?

0:32

A Security Information and Event Management system, or SIEM, collects, normalizes, correlates, and analyzes log data from across an organization's IT infrastructure in real time. SIEMs aggregate logs from firewalls, servers, endpoints, applications, and network devices into a centralized platform. Correlation rules and analytics identify patterns that indicate security incidents, such as multiple failed login attempts followed by a successful login from an unusual location. SIEMs provide alerting, dashboards, reporting for compliance, and forensic investigation capabilities.
csrc.nist.gov