CISM · Question #291
When implementing a SIEM solution to monitor the effectiveness of security controls, which of the following is the MOST important requirement from an information security manager's perspective?
The correct answer is B. Defined thresholds for each security control. Defined thresholds for each security control are the most important requirement because they establish the measurable baseline against which the SIEM determines whether a control is operating within acceptable parameters or has failed. Without defined thresholds, there is no obje
Question
When implementing a SIEM solution to monitor the effectiveness of security controls, which of the following is the MOST important requirement from an information security manager's perspective?
Options
- ACompatibility with legacy architecture
- BDefined thresholds for each security control
- CExtensive ruleset for event consolidation
- DMaximum available number of log connectors
How the community answered
(32 responses)- A6% (2)
- B72% (23)
- C16% (5)
- D6% (2)
Explanation
Defined thresholds for each security control are the most important requirement because they establish the measurable baseline against which the SIEM determines whether a control is operating within acceptable parameters or has failed. Without defined thresholds, there is no objective standard to evaluate control effectiveness - the SIEM cannot distinguish normal behavior from a control failure. From the information security manager's perspective, the entire purpose of monitoring is to detect deviations from expected control behavior, which requires those expectations to be formally defined. Compatibility (A), rulesets (C), and log connectors (D) are implementation concerns, but they are meaningless without clear thresholds that define what 'effective' looks like for each control.
Topics
Community Discussion
No community discussion yet for this question.