A CISA is evaluating an organization's security incident management process. The organization has recently implemented a Security Information and Event Management (SIEM) system. During the review, the CISA observes that while the SIEM collects logs from various sources, there is no established process for regularly tuning correlation rules or updating threat intelligence feeds. What is the MOST likely consequence of this oversight?
- AThe organization's ability to detect novel or evolving threats will be severely impaired.
- BCompliance reporting for regulatory requirements will become inaccurate or incomplete.
- CThe SIEM system will generate an excessive number of false positive alerts, leading to alert fatigue.
- DThe SIEM system's storage capacity will be rapidly consumed by unanalyzed log data.
Show answer & explanationAnswer & explanation
Correct answer: A. The organization's ability to detect novel or evolving threats will be severely impaired.
Regular tuning of correlation rules and updating threat intelligence feeds are crucial for a SIEM system to effectively identify new and evolving attack patterns. Without these updates, the SIEM will primarily detect known, static threats, severely impairing the organization's ability to identify novel tactics, techniques, and procedures (TTPs) used by attackers, making it vulnerable to zero-day or advanced persistent threats.
Why the other options are wrong
- B. Compliance reporting relies on the data collected, but the primary function of tuning rules and updating feeds is detection, not reporting. Inaccurate detection would indirectly affect reporting, but impaired detection is the more direct consequence.
- C. While untuned rules can lead to false positives, the lack of threat intelligence updates is more directly linked to missing *new* threats, rather than just generating noise from existing rules.
- D. Storage consumption is a concern, but it's a consequence of log volume, not directly the lack of correlation rule tuning or threat intelligence updates, which are focused on *analysis* and *detection*.
SIEM Correlation Rule & Threat Intelligence Tuning
The ongoing process of refining SIEM correlation rules and regularly updating threat intelligence feeds to improve threat detection accuracy and relevance.
- Essential for adapting to new attack vectors and reducing false positives.
- Ensures the SIEM can identify both known and emerging threats.
- A continuous process, not a one-time configuration.
Memory trick: Keep your SIEM's 'EYES' and 'BRAIN' sharp with constant updates.