cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Kyaw_Myo_Oo
Advocate I

Beyond the Hype: CISA's Practical Guide to SIEM & SOAR Implementation – What Are Your Key Takeaways?

Dear All,

 

Today, CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre and other international and U.S. partners, released new guidance for organizations seeking to procure Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms.

This guidance includes the following three resources:

Implementing SIEM and SOAR Platforms – Executive Guidance outlines how executives can enhance their organization’s cybersecurity framework by implementing these technologies to improve visibility into network activities, enabling swift detection and response to cyber threats.

Implementing SIEM and SOAR Platforms – Practitioner Guidance focuses on how practitioners can quickly identify and respond to potential cybersecurity threats and leverage these technologies to streamline incident response processes by automating predefined actions based on detected anomalies.

Priority Logs for SIEM Ingestion – Practitioner Guidance offers insights for prioritizing log ingestion into a SIEM, ensuring that critical data sources are effectively collected and analyzed to enhance threat detection and incident response capabilities tailored for organizations.

CISA encourages organizations to review this guidance and implement the recommended best practices to strengthen their cybersecurity. For access to the guidance documents,

Guidance for SIEM and SOAR Implementation

 

 

Question for discussion:

 

CISA's guidance aims to help organizations effectively implement SIEM and SOAR. In your experience, what is the single biggest challenge organizations face when trying to get real value out of their SIEM or SOAR investments, even with good guidance?

 

It's always great to learn from each other, share experiences, and stay updated. Let's learn and explore together!

 

 

Kyaw Myo Oo
Information Security Officer , CB BANK PCL
CCIE #58769 | CISSP | CRISC | PMP | CCSM | SAA-C03 | PCNSE
https://www.linkedin.com/in/kyaw-myo-oo/
4 Replies
akkem
Contributor III

Thank you for the details.
Asset inventory and ownership present significant challenges when implementing SIEM/SOAR and establishing proactive monitoring (IMHO).
TribesmanJohn
Newcomer II

I think one of the problems here is simply the costs involved for SIEM/SOAR when at scale. 

 

While I can't go into specifics, I work for an organisation with a relatively large number of endpoints and servers and to implement the priority logs would require a yearly investment of at least 7 figures. The priorities of of the organisation simply do not have that sort of money to put into a commercial SIEM platform.

 

Similarly while there are freely available open source solutions out there, if you are generating terabytes of priority logs on a daily basis, you will need a suitable hardware platform to store and process these, and you will also need staff to manage it. This again may be budget-prohibitive and may also scare executive off with the lack of commercial support.

 

It's a difficult challenge to overcome - certainly one I don't have answers to. 🙂

 

Kyaw_Myo_Oo
Advocate I

It is very crucial. Thank you for sharing your time and expertise on this topic with us @akkem.

I'm eager to hear more insights from other members of the group.

 

 

 

 

Kyaw Myo Oo
Information Security Officer , CB BANK PCL
CCIE #58769 | CISSP | CRISC | PMP | CCSM | SAA-C03 | PCNSE
https://www.linkedin.com/in/kyaw-myo-oo/
Kyaw_Myo_Oo
Advocate I

The lack of commercial support for open-source is another excellent point that often scares off executive leadership, making the justification even harder. You're right, it's a very difficult challenge to overcome.

 

Thank you for sharing your time and expertise on this topic with us @TribesmanJohn.

 

I would love to hear more insights from other members of the group.

 

 

Kyaw Myo Oo
Information Security Officer , CB BANK PCL
CCIE #58769 | CISSP | CRISC | PMP | CCSM | SAA-C03 | PCNSE
https://www.linkedin.com/in/kyaw-myo-oo/