PwC SIEM Health Check

Qualitative analysis of SIEM systems

The SIEM Health Check service consists of a comprehensive analysis of the current state of the implementation of the client’s SIEM solution. The service is vendor agnostic – it can be applied to any SIEM product. As part of the service, a set of dedicated checks is performed.

Checks are grouped into following areas:

  • Architecture – assess if the current architecture of the SIEM system reflects vendor’s requirements and industry best practices, check if it meets client’s needs and PwC recommendations.
  • Data Sources – assess the completeness and quality of data sources currently connected to the SIEM and the procedures related to the tracking of the data sources statuses.
  • Functional Configuration – assess the quality of the functional configuration of the SIEM.
  • License and current usage – assess the operational usefulness of the current state of SIEM and the status of the license

Service purpose and benefits

The purpose of the SIEM Health Check service is to provide knowledge about the quality of the existing implementation of SIEM system and help to understand what areas are to be improved.

Specifically, the service covers following aspects:

  • Identification of potential issues and bottlenecks related to the architecture, evaluation of their impact on the system and recommendation how to resolve them.
  • Assessment of current coverage of data sources, identification of potential issues related to it (for example improper data coverage, loss of log events, improper data filtering) and recommendation how to resolve them.
  • Assessment of the functional configuration of the SIEM. Evaluation of the quality of currently implemented use cases (correlation rules and other detection mechanisms), reports, dashboards, alerts et cetera, and recommendation how to resolve potential issues.
  • Assessment of the current usage of SIEM system across the organization in order to help to understand how it is used by SOC, security department and other potential stakeholders.
  • Evaluation of current license usage and identification whether SIEM costs correspond to  value that SIEM logs bring to SOC operations.

Engagement outcomes

As a result of the service a comprehensive report is provided consisting the summary of performed checks, conclusions and recommendations.

The checks

Architecture

The goal of these checks is to assess of the current architecture of the SIEM system. Specifically, checks include the analysis of:

  1. Overall SIEM architecture.
  2. Design and the implementation of the core system components.
  3. Design and the implementation of the data collection layer components of the system.
  4. Performance of the SIEM system components.
  5. Design and the implementation of the backup process.
  6. Configuration of the communication between SIEM components.
  7. SIEM components updates availability
  8. Logs of the SIEM system components in order to identify any architecture-related issues.
We unite expertise and tech so you can outthink, outpace and outperform
See how
Follow us
Hide

Contact us

Daniela Geretshuber

Daniela Geretshuber

Member of the Board and People and Corporate Sustainability Leader, PwC Germany