Certified Information Security Manager (CISM)Information Security ProgramHard

An organization's information security program relies heavily on a legacy, on-premise Security Information and Event Management (SIEM) system. The CISO observes that the security operations center (SOC) team is overwhelmed by a high volume of alerts, many of which are false positives, leading to analyst fatigue and missed critical incidents. The current SIEM also lacks integration with newer cloud services. Which of the following is the MOST effective strategic initiative for the CISO to pursue to improve the program's monitoring and response capabilities?

  1. AInvest in advanced machine learning (ML) algorithms for the existing SIEM to reduce false positives.
  2. BIncrease the SOC team headcount to handle the alert volume and improve manual correlation.
  3. CDevelop custom scripts and playbooks for the current SIEM to automate basic incident response tasks.
  4. DMigrate to a cloud-native Security Orchestration, Automation, and Response (SOAR) platform integrated with a modern SIEM.
Show answer & explanation

Correct answer: D. Migrate to a cloud-native Security Orchestration, Automation, and Response (SOAR) platform integrated with a modern SIEM.

The problem describes a legacy SIEM, high false positives, analyst fatigue, missed incidents, and lack of cloud integration. Migrating to a cloud-native SOAR integrated with a modern SIEM (which often includes ML capabilities) addresses all these issues holistically: improved correlation, automation of response, reduced false positives, and native cloud integration. It represents a strategic modernization that goes beyond incremental fixes.

Why the other options are wrong

  • A. Investing in ML for an existing legacy SIEM might help with false positives but won't address the lack of cloud integration, automation (SOAR), or the fundamental architectural limitations of an outdated system.
  • B. Increasing headcount is a tactical, short-term fix that doesn't address the underlying technology limitations or the root cause of alert fatigue and false positives.
  • C. Developing custom scripts for a legacy SIEM is a tactical workaround that doesn't resolve the core issues of scalability, cloud integration, or comprehensive false positive reduction, and can be difficult to maintain.

Modernizing Security Operations

The strategic transition from legacy security tools and manual processes to integrated, automated, and cloud-native platforms like SIEM, SOAR, and XDR to enhance detection and response capabilities.

  • Addresses alert fatigue, false positives, and cloud integration gaps.
  • Combines threat intelligence, automation, and orchestration.
  • Improves incident response efficiency and effectiveness.

Memory trick: Upgrade the Control Tower, Automate the Flight, See the Clouds.

More Information Security Program questions