Security Information and Event Management (SIEM) is a conceptual framework for collecting, correlating, and analyzing security logs and events. It enables detection, investigation, and response to security incidents as well as compliance reporting. SIEM systems aggregate telemetry from diverse sources and provide centralized monitoring and forensic analysis.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
A SIEM collects, correlates, and analyzes security-relevant events from many sources.
SIEM grew by combining security information management and security event management to analyze log data centrally for monitoring and response. NIST SP 800-92 covers foundations of security log management.
Logs and events are collected, normalized, retained, and correlated centrally. Rules and analytics produce investigation leads; usefulness depends on source quality, timing, context, and response processes. SIEM is a monitoring and analysis component, not complete protection.
Distributed security events are brought together for detection and investigation.
Normalization, correlation, and rules turn raw events into analytical leads.
Results depend on log coverage, integrity, retention, and operational response.
SIEM helps organize security monitoring and investigations across many systems while exposing the limits of available evidence.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.