Certified Information Security Manager (CISM)Information Security ProgramMedium

An organization is experiencing a high volume of security alerts, many of which are false positives, leading to analyst fatigue and delayed response to legitimate threats. The CISO wants to optimize the Security Operations (SecOps) function within the information security program. Which of the following initiatives should the CISO prioritize to address this issue MOST effectively?

  1. AImplementing a new Security Information and Event Management (SIEM) system with advanced correlation capabilities.
  2. BHiring more security analysts to handle the increased alert volume.
  3. CConducting more frequent penetration tests to identify vulnerabilities pre-emptively.
  4. DEnhancing automation and orchestration (SOAR) capabilities to triage and respond to common alerts.
Show answer & explanation

Correct answer: D. Enhancing automation and orchestration (SOAR) capabilities to triage and respond to common alerts.

A high volume of false positives and analyst fatigue indicates a need for more efficient alert handling. Security Orchestration, Automation, and Response (SOAR) capabilities directly address this by automating the triage, enrichment, and initial response to common alerts, reducing manual effort and allowing analysts to focus on legitimate, complex threats.

Why the other options are wrong

  • A. A new SIEM might offer better correlation, but without automation, analysts will still be overwhelmed by the volume of alerts requiring manual investigation.
  • B. Hiring more analysts is a reactive solution that doesn't address the root cause of inefficient alert processing and may lead to more fatigue if the process isn't optimized.
  • C. Penetration testing identifies vulnerabilities, which is proactive, but doesn't directly solve the operational problem of alert fatigue and inefficient response to existing alerts.

Security Operations Optimization

The process of improving the efficiency, effectiveness, and responsiveness of security operations, often through automation, orchestration, and streamlined workflows.

  • Reduces manual effort and analyst fatigue.
  • Speeds up detection and response.
  • Leverages automation (SOAR) and improved processes.

Memory trick: Overwhelmed SecOps? 'Automate Orchestrate Respond' to clear the queue.

More Information Security Program questions