Security Information and Event Management (SIEM)
Security Information and Event Management, or SIEM, refers to a centralised platform for collecting and analysing security-related data across an IT infrastructure. It aggregates logs and events from sources such as servers, firewalls, network devices, applications, cloud services and endpoints. The collected information is normalised, correlated and analysed using defined rules or analytical methods to identify suspicious activity. When potential cyberattacks or security breaches are detected, the system can generate alerts for further investigation. SIEM supports security teams with security monitoring, threat detection, incident response and forensic analysis. Centrally stored log data can also support compliance and documentation requirements. SIEM solutions are an important component of modern Security Operations and are commonly deployed within Security Operations Centers.