Classification
2- Complexity
- High
- Impact area
- Organizational
A conceptual framework for centralized collection, correlation and analysis of security logs and events to detect and respond to incidents.
360° overview
Six perspectives place the building block in context. The numbers show where each perspective continues in the reading path.
The building block at a glance
Security Information and Event Management (SIEM)
360°
Integrations
Cloud provider logging (AWS CloudWatch, Azure Monitor)
+2
Centralize collection of relevant telemetry with reliable timestamps
Value stream stage: Run