SIEM Assessment via Yes, No approaches

In many cases lots of companies need to assess the right product for using as the right tools as Security Incident and Event Management tools (SIEM), that is considered as the core product of the Security Operations Center (SOC). here there are 4 main general category to consider yes no questions. This approaches is the easiest way to assess and find the right SIEM tools.

The 4 main categories includes : 1-User Experience 2-Technical Capabilities 3-Scalabilities and Performance 4-Cost Efficiency

I share the table as below, please feel free to use it or reach out to me in case you need some support.

Note: Please keep in mind that it is just a sample, and might be different question based on your requirement. Also The yes, No question approaches is the easiest way and it is not recommended.

#CategoryQuestion
1User ExperienceDoes the SIEM provide a user-friendly interface?
2User ExperienceDoes the SIEM provide a user-friendly installation process?
3User ExperienceIs the installation process well documented?
4User ExperienceCan the SIEM provide contextual information for events?
5User ExperienceDoes the SIEM support customization and personalization?
6User ExperienceCan the SIEM provide a unified view of security events?
7User ExperienceDoes the SIEM support role-based access control?
8User ExperienceCan the SIEM provide collaboration features for users?
9User ExperienceDoes the SIEM provide a knowledge base or library?
10User ExperienceCan the SIEM integrate with incident management tools?
11User ExperienceDoes the SIEM provide a dashboard or reporting tool?
12User ExperienceCan the SIEM provide a search function with NLP?
13User ExperienceDoes the SIEM support a community of users and experts?
14User ExperienceCan the SIEM provide training or support resources?
15User ExperienceCan you easily make your own cutom dashboards and search queries based on your needs?
16User ExperienceDoes SIEM provide Asset Management mapping for asset properties such as IP address and Asset Name and other related properties and associate theme with user accounts?
17User ExperienceIntegration with other security controls: Does the SIEM support integration with other enterprise security tools?
18User ExperienceThreat Intelligence Feed Usage: Does the SIEM support threat intelligence feeds ?
19User ExperienceDoes the SIEM support  integration with other TIPs such as MISP or TheHive?
20User ExperienceDoes the SIEM have automated tracking capabilities for MITRE techniques/tactics? (can provide more than lateral movement as c2c, execution etc.)
21User ExperienceFull Coverage of Incident Management Process: Does the SIEM cover the full incident management process?
22User ExperienceIncident Timeline: Does the SIEM provide a full incident time-line and ability to define custom correlation to show the time-line of an incident based on different data sources? is it easy to understand?
23User ExperienceDoes the SIEM provide incident prioritization?
24User ExperienceDoes the SIEM provide features for tracking changes?
25User ExperienceDoes the SIEM provide profiling system states/assets, and AI/ML-based detection?
26User ExperienceDoes the SIEM provide AI/ML-based detection?
27User ExperienceForensics Capabilities: Does the SIEM provide forensics capabilities including working with raw logs, import/export data, and data analysis?
28User ExperienceDoes the SIEM provide compliance reporting for well-known baselines? (PCIDSS, HIPA etc.)
29User ExperienceIs the SIEM able to integrate all types of compliance policies?
30User ExperienceDoes the product come with an inbuilt Incident Management & Workflow System to track the
policy violations and exceptions?
31User ExperienceDoes the product uses AI techniques to analyze, correlate security incidents?
32User ExperienceDoes the product has intelligence to correlate logs and provide proactive incidents, alerts
notifications, even before actual incident happens?
33User ExperienceDoes the product support Investigation & Triage support?
34User ExperienceDoes the product support incident creation & tracking?
35User ExperienceDoes the SIEM documentation good enough to follow up and do the required jobs?
36User ExperienceIs the SIEM architecture clear to understand about different components and connections?
37User ExperienceDo you find the SIEM fetures good for threat hunting and investigation?
38
39
40Technical CapabilitiesDoes the product collect and normalize logs on premises?
41Technical CapabilitiesDoes the product collect and normalize logs on cloud infrastructure?
42Technical CapabilitiesCan the SIEM support multiple data sources?
43Technical CapabilitiesCan the SIEM support multiple deployment models?
44Technical CapabilitiesDoes the SIEM provide advanced threat intelligence?
45Technical CapabilitiesCan the SIEM integrate with other security technologies?
46Technical CapabilitiesDoes the SIEM provide an open architecture?
47Technical CapabilitiesCan the SIEM scale horizontally and vertically?
48Technical CapabilitiesDoes the SIEM provide encryption and data masking?
49Technical CapabilitiesCan the SIEM provide a threat hunting feature?
50Technical CapabilitiesDoes the SIEM support log data compression and optimization?
51Technical CapabilitiesCan the SIEM provide compliance reporting and auditing?
52Technical CapabilitiesDoes the SIEM provide a roadmap or vision for future capabilities?
53Technical CapabilitiesCan the SIEM provide a customizable workspace for different users?
54Technical CapabilitiesDoes the SIEM support a wide range of data types and formats?
55Technical CapabilitiesCan the SIEM support data ingestion and processing at scale?
56Technical CapabilitiesDoes the SIEM provide a wide range of use cases and pre-built content?
57Technical CapabilitiesCan the SIEM provide a low false positive rate and high true positive rate?
58Technical CapabilitiesDoes the SIEM provide a flexible and robust query language?
59Technical CapabilitiesCan the SIEM provide deep visibility and correlation of security events?
60Technical CapabilitiesDoes the SIEM provide runbooks for incidents?
61Technical CapabilitiesCan the SIEM provide detailed analytics and insights?
62Technical CapabilitiesDoes the SIEM detect and display security events for at least the last 30 days?
63Technical CapabilitiesDoes the SIEM provide clear and meaningful data visualization?
64Technical CapabilitiesDoes the SIEM support custom parsing for events which are not parsed natively by indexing engine?
65Technical CapabilitiesAre custom parser supported and is vendor support available to help generating parsers?
66Technical Capabilitiesis all common data formats are supported by default (CEF, Syslog, etc.)?
67Technical CapabilitiesHistorical Data Usage: Is the SIEM able to use historical data for timelines and correlations related to long-term or slow attacks?
68Technical CapabilitiesDoes the SIEM provide historical data usage with reasonable performance?
69Technical CapabilitiesDoes the SIEM provide log retention in compliance with customer’s (fidor) log retention policy?
70Technical CapabilitiesBusiness Data Processing: Is the SIEM able to process application data (threats for Business logic or buisness fraud, etc.) in case of business need?
71Technical CapabilitiesIs the SIEM able to do real-time security monitoring, alerting?
72Technical CapabilitiesIs the SIEM able to do real-time searching?
73Technical CapabilitiesData Processing and Trends/Anomalies: Is the SIEM able to process and display trends and anomalies based on our requirement?
74Technical CapabilitiesIs it easy to customize and fine tune the trends and anomalies displayed on SIEM?
75Technical CapabilitiesFlexible Query Writing: Is the SIEM flexible to write queries for analysis on different types of data?
76Technical CapabilitiesIntegration with Other Tools: Does the SIEM support easy integration with other enterprise security controls such as vulnerability scanners and asset inventory/monitoring tools?
77Technical CapabilitiesAPI Support: Does the SIEM have API support ?
78Technical CapabilitiesDoes the vendor provide well-structured documentation for API?
79Technical CapabilitiesDoes the product offer log retention?
80Technical CapabilitiesDoes the product offer log Rotation?
81Technical CapabilitiesDoes the product offer scheduled search?
82Technical CapabilitiesDoes the product manage log storage and archival?
83Technical CapabilitiesDoes the SIEM provide automatically assign offenses to analysts?
84Technical CapabilitiesDoes the SIEM provide assign SLA time to offenses?
85Technical CapabilitiesCan you easily make you dashboard from different types of data sources as you wish?
86Technical CapabilitiesIs the SIEM able to create incident timeline or provide a feature to you to do so ?
87Technical CapabilitiesIs the product modular ? and able to add more feature via new modules? (UBA, Correlation Engine, Logger, etc.)
88
89
90Scalability and performanceCan the SIEM handle a significant increase in data volume without adding significant additional resources?
91Scalability and performanceCan the SIEM add additional nodes to a cluster without requiring significant downtime?
92Scalability and performanceDoes the SIEM offer load balancing and data distribution across multiple nodes in a cluster?
93Scalability and performanceCan the SIEM operate across multiple regions without significant performance degradation?
94Scalability and performanceCan the SIEM handle large volumes of event and log data without significantly increasing query times?
95Scalability and performanceDoes the SIEM provide real-time monitoring and alerting capabilities for high-priority security events?
96Scalability and performanceCan the SIEM perform real-time threat analysis at scale without significant performance degradation?
97Scalability and performanceDoes the SIEM provide automated scaling and resource allocation to optimize performance and cost?
98Scalability and performanceCan the SIEM integrate with cloud-based data sources and platforms to enable efficient data ingestion?
99Scalability and performanceDoes the SIEM support high-availability and fault-tolerance to ensure uptime and data integrity?
100Scalability and performanceDoes the SIEM has auto-scalability feature as SaaS platform?
101
102
103
104Cost Efficiency:Is the SIEM cost-effective compared to other solutions?
105Cost Efficiency:Does the SIEM require a lot of resources to run effectively?
106Cost Efficiency:Does the SIEM require specialized hardware or software to run?
107Cost Efficiency:Is the SIEM licensing model affordable for the organization?
108Cost Efficiency:Does the SIEM provide a good return on investment?
109Cost Efficiency:Does the SIEM provide a transparent pricing model with no hidden fees or charges?
110Cost Efficiency:Can the SIEM provide cost savings by consolidating security event management across multiple systems?
111Cost Efficiency:Does the SIEM provide a low total cost of ownership over the long term, taking into account maintenance, support, and upgrade costs?
112Cost Efficiency:Can the SIEM provide a fast return on investment by reducing the time and effort required to manage and respond to security incidents?
113Cost Efficiency:Does the SIEM provide a flexible deployment model, such as on-premises, cloud-based, or hybrid, to meet different business needs?
114Cost Efficiency:Does the SIEM provide a clear and transparent pricing model?

Leave a comment