CyberzSOC

Publication detail
← Back to advisories & guidance

Implementing SIEM and SOAR Platforms: Practitioners Guidance ↗ source

May 27, 2025 NSA Advisory
Co-sealed by: ASD/ACSC, NSA

Summary

4. Best practice principles for implementing a SIEM and/or SOAR 12 This publication provides high-level guidance for cyber security practitioners on Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. While this guidance is primarily intended for practitioners within government and critical infrastructure organisations, it can also be used by practitioners in any organisation that is interested in, or currently using, SIEM and/or SOAR platforms. This publication has four sections that: implementing a SIEM and/or SOAR: procurement, establishment, and maintenance. The recommendations in this publication should be treated as generic advice; each organisation should tailor the collection, centralisation, and analysis of logs to its specific environment and This publication is one of three in a suite of guidance on SIEM/SOAR platforms: This document is primarily intended for executives. It defines Implementing SIEM and SOAR SIEM/SOAR platforms, outlines their benefits and challenges, platforms: Executive guidance and provides broad recommendations for implementation that are relevant to executives.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.