Reference no: EM133955355
Assignment:
Description of SIEM use cases. Give an overview of SIEM Use Cases and cover;
a. Why does the organization need SIEM use Cases?
b. Challenges with creating the Use Cases, for example do we have data?
c. How did you frame the use cases, in other words, what problem are you trying to solve?
For ex: Reduce the Risk of Data Exfiltration, Comply with PCI regulations etc ...
Guidelines
1. Refer to the Gartner document referenced in the description (Gartner, July 2019, How to Build Security Use Cases for Your SIEM). This document is available online from the PSU library from Gartner Reports (Information Technology) database under and is a great introduction to using this type of research or your analysis. Pay close attention to the Recommendations section of the Gartner document.
2. Splunk also has great resources on Security Use-Cases and video on "Splunk Enterprise Security: SIEM Use Case Library"
3. Be sure to Frame the Use Case using the Triangle of Insight, Analytics and Data.