Anton's 2020 SIEM Best
and Worst Practices
Dr. Anton Chuvakin
@anton_chuvakin and https://medium.com/anton-on-security
Chronicle / Google Cloud
(ex-Gartner for Technical Professionals until 2019)
2020 SIEM in Context
What is SIEM today?
Does SIEM matter today?
Do you still need it?
What will happen in the future?
Best / Worst Practices?
A Recent SIEM Problems Poll
https://twitter.com/securitybrew/status/1283924416888479746
SIEM Worst Practices
1. Skip the SIEM requirements definition phase - just buy something
2. Assume that the SIEM will deploy/manage/run itself and security
value will just materialize
3. Expect that IT and other teams will always support your
SIEM/detection/monitoring project
4. Expect the vendor to decide what you need to log and what to
detect
5. Plan to rely on ML and other “magic” provided in the box
SIEM Best Practices
1. Practice a use case approach, and “output-driven” SIEM
2. Start with “quick wins” and simple use cases
3. Deploy using a phased approach, learn, expand, learn more
4. Take log collection seriously and review often
5. Expect the log/telemetry data grow faster than you expect :-)
6. Prepare to create your own detection content and/or tune
existing content
Q&A
Just for Laughs - 2011 Version of the Same...
https://www.slideshare.net/anton_chuvakin/five-best-and-five-worst-practices-for-siem-by-dr-anton-chuvakin-8721331

Anton's 2020 SIEM Best and Worst Practices - in Brief

  • 1.
    Anton's 2020 SIEMBest and Worst Practices Dr. Anton Chuvakin @anton_chuvakin and https://medium.com/anton-on-security Chronicle / Google Cloud (ex-Gartner for Technical Professionals until 2019)
  • 2.
    2020 SIEM inContext What is SIEM today? Does SIEM matter today? Do you still need it? What will happen in the future?
  • 3.
    Best / WorstPractices?
  • 4.
    A Recent SIEMProblems Poll https://twitter.com/securitybrew/status/1283924416888479746
  • 5.
    SIEM Worst Practices 1.Skip the SIEM requirements definition phase - just buy something 2. Assume that the SIEM will deploy/manage/run itself and security value will just materialize 3. Expect that IT and other teams will always support your SIEM/detection/monitoring project 4. Expect the vendor to decide what you need to log and what to detect 5. Plan to rely on ML and other “magic” provided in the box
  • 6.
    SIEM Best Practices 1.Practice a use case approach, and “output-driven” SIEM 2. Start with “quick wins” and simple use cases 3. Deploy using a phased approach, learn, expand, learn more 4. Take log collection seriously and review often 5. Expect the log/telemetry data grow faster than you expect :-) 6. Prepare to create your own detection content and/or tune existing content
  • 7.
  • 8.
    Just for Laughs- 2011 Version of the Same... https://www.slideshare.net/anton_chuvakin/five-best-and-five-worst-practices-for-siem-by-dr-anton-chuvakin-8721331

Editor's Notes

  • #3 https://blogs.gartner.com/anton-chuvakin/2017/08/14/lets-define-siem/
  • #5 Other write-ins: Log collection challenges Mismatched expectations