SIEM
SIEM systems are integrated data correlation tools that help in integrating different systems and collecting, analyzing, and alerting based on intelligent thresholds. SIEM systems can be used to detect malicious events based on pre-defined signatures or behavior. SIEM systems allow risk practitioners to identify risk and bring it to the attention of management before it materializes by correlating it with similar events.
An important consideration for implementing a SIEM system is the regular monitoring and fine-tuning of alerting rules to reduce false-positive alerts as much as possible. This constant fine-tuning ensures that the risk practitioner is only focusing on important alerts that require action.
A SIEM system can translate all the logs in management reports and dashboards that are important for management reporting, can support compliance requirements for log retention, and will be helpful for forensic analysis. The risk manager should ensure that the logs are...