ISACA Certified Information Systems Auditor (CISA) ExamDomain 5: Protection of Information AssetsMedium

A CISA is evaluating an organization's security incident management process. The organization uses a Security Information and Event Management (SIEM) system. The CISA discovers that many security alerts generated by the SIEM are false positives, leading security analysts to ignore legitimate threats. Additionally, the SIEM is not integrating feeds from a newly deployed threat intelligence platform. What corrective action should the CISA recommend FIRST to improve the SIEM's effectiveness?

  1. AImplement an automated incident response orchestration tool.
  2. BReplace the existing SIEM system with a new one.
  3. CTune SIEM correlation rules and integrate threat intelligence feeds.
  4. DIncrease the number of security analysts to handle the alert volume.
Show answer & explanation

Correct answer: C. Tune SIEM correlation rules and integrate threat intelligence feeds.

The primary issues are excessive false positives and lack of threat intelligence integration. Tuning correlation rules directly addresses false positives, making alerts more accurate and actionable. Integrating threat intelligence provides crucial context to identify legitimate threats more effectively, thus improving the SIEM's core function.

Why the other options are wrong

  • A. Automated orchestration is valuable but secondary to ensuring the SIEM generates accurate and relevant alerts in the first place.
  • B. Replacing the SIEM is a drastic and costly measure; the current system's issues can likely be resolved through configuration and integration.
  • D. Increasing staff without addressing the root cause of false positives is inefficient and will not solve the underlying problem.

SIEM Correlation Rule & Threat Intelligence Tuning

The process of refining Security Information and Event Management (SIEM) rules to reduce false positives and integrating external threat data to enhance threat detection capabilities.

  • Reduces alert fatigue for security analysts.
  • Improves the accuracy and relevance of security alerts.
  • Threat intelligence provides context for identifying malicious activities.

Memory trick: To make your security brain smarter, teach it to filter noise and listen to the right whispers.

More Domain 5: Protection of Information Assets questions