SIEM rules ignore bulk of ATT&CK framework, placing risk burden on users
MITRE Corporation headquarters in McLean, Virginia. (Antony-22, CC BY-SA 4.0 https://creativecommons.org/licenses/by-sa/4.0, via Wikimedia Commons) A recent study of 10 organizations found that, on average, rules and policies tied to security information and event management solutions, or SIEM, cover only 16 percent of the tactics and techniques listed in the MITRE ATT&CK framework. Often considered a core component of security operations, SIEM solutions aggregate log data from various network devices and services and analyze them to detect threats. Please register to continue.
Source: scmagazine.com