Embed presentation









This document outlines best and worst practices for security information and event management (SIEM) systems according to Dr. Anton Chuvakin. Some key worst practices include failing to properly define SIEM requirements, assuming the SIEM will run itself without support, and expecting vendors to decide what to log and detect. The best practices include taking a use case approach, starting with simple quick wins, deploying in phases while continually learning and expanding, taking log collection seriously, and preparing to create your own detection content.







