Expert Advice Community

Guest

ISO 27001 and SIEM

  Quote
Guest
Guest user Created:   Feb 13, 2020 Last commented:   Feb 13, 2020

ISO 27001 and SIEM

Me gustaria tratar el tema acerca de como integrar la ISO 27001 con la implementación de un SIEM, es decir, tengo claros algunos conceptos y algunas relaciones existentes, pero me gustaria fundamentar de mejor manera dicha integración y conocer mas acerca de la ISO 27001 para poder relacionarla.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 13, 2020

I would like to address the issue of how to integrate ISO 27001 with the implementation of a SIEM, that is, I have clear some concepts and some existing relationships, but I would like to better base this integration and learn more about ISO 27001 to be able to relate it.

A Security Information and Event Management (SIEM) is a software or service which combines security information management (SIM) and security event management (SEM), providing real-time analysis of security alerts generated by network hardware and applications.

ISO 27001 is a set of requirements to plan, implement, operate and improve an Information Security Management System. It is composed by a set of requirements for information security management (section 4 to 10), and a set of controls (Annex A), which can be used to treat relevant risks.

Considering these definitions, you can understand SIEM as an implementation way for some controls from Annex A (primarily those from sections A.12.4 Logging and monitoring, A.13.1 Network security management, and A.16 Information security incident management).

A proper integration between ISO 27001 and SIEM is ensured based on the results of risk assessment and risk treatment, were relevant risk are identified and treated by the application of controls defined in the above-mentioned sections.

This article will provide you further explanation about ISO 27001 security controls:

These materials will also help you regarding ISO 27001:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 13, 2020

Feb 13, 2020

Suggested Topics

Guest user Created:   Jun 13, 2023 ISO 27001 & 22301
Replies: 1
0 0

Retention for SIEM

Guest user Created:   Mar 06, 2020 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content

Guest user Created:   Jul 29, 2020 ISO 27001 & 22301
Replies: 2
0 0

27001 or NIST for Local Bank