Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

CISA Releases Guidance on SIEM and SOAR Implementation

The guidance outlines the benefits and challenges or SIEM and SOAR platforms, and shares implementation recommendations.

Newly released guidance from the US and Australian governments aims to provide organizations with advice on how to improve their security posture through implementing SIEM and SOAR platforms.

The US cybersecurity agency CISA in collaboration with the Australian Cyber Security Centre (ACSC) this week released fresh recommendations for organizations looking to procure SIEM and SOAR platforms, which collect and analyze log data from the network, and identify anomalous behavior and automate response.

SIEM and SOAR platforms provide increased visibility over an organization’s information and communication technology (ITC) environment and help with the detection of cybersecurity incidents, enabling defenders to respond to them early.

When properly implemented, SIEM appliances automate the collection of log data from sources scattered across the network, making it easier for security teams to navigate. 

SOAR solutions, on the other hand, apply predefined playbooks that “combine incident response and business continuity plans to determine automatic actions” and aid incident responders. 

SIEM and SOAR platforms are designed to integrate with one another, as the latter leverages data collected, centralized, and analyzed by the former. SOAR solutions may also be integrated with other security tools, CISA and ACSC say.

Advertisement. Scroll to continue reading.

To aid organizations in understanding the importance of SIEM and SOAR platforms and in implementing them, the two agencies published three new guiding documents: one aimed at executive decision-makers and two meant for cybersecurity practitioners.

The guidance for executives defines SIEM and SOAR platforms, outlines their benefits and challenges, and shares implementation recommendations considered relevant. 

The guidance for practitioners covers SIEM/SOAR implementation and priority logs, providing recommendations on the best practices for implementing these platforms, as well as on the logs that should be prioritized for SIEM ingestion.

The documents, the agencies say, are mainly intended for use within government entities, but the recommended actions apply to any organization looking to implement and leverage SIEM and SOAR. 

Related: Vulnerabilities in CISA KEV Are Not Equally Critical: Report

Related: CISA Says Russian Hackers Targeting Western Supply-Lines to Ukraine

Related: Vulnerability Exploitation Probability Metric Proposed by NIST, CISA Researchers

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.