Gartner Blog Network

My “Evaluation Criteria for Security Information and Event Management” 2015 Update Publishes

by Anton Chuvakin  |  August 18, 2015  |  1 Comment

My freshly updated “Evaluation Criteria for Security Information and Event Management” (2015 edition) is up on the Gartner site. Admittedly, it is a relatively minor update, but I have expanded sections related to workflow, incident management, threat intelligence, analytics (of course!) and tightened a bunch of various loose ends. As a reminder, the document lists Required, Preferred and Optional requirements for a SIEM tool.

A few fun quotes are below – but really, this document is meant to be used (Excel tool is shipped with it), not perused:

  • “Customers must evaluate SIEM on functionality, implementation effort, maintenance effort, ease of operation, scalability up to a desired level, cost and the enterprise maturity of the solution — and must also take into account their monitoring goals and security operations process maturity. ”
  • “There is clear segmentation between vendors that commonly appear on enterprise SIEM shortlists (and thus capture the majority of enterprise deployments) and all others (that might also have a few enterprise customers).”
  • SIEM and threat intelligence feeds are a marriage made in heaven. Indeed, all SIEM users should send tactical threat intelligence feeds into their SIEM tools. ”


Other posts announcing research publication:

Additional Resources

View Free, Relevant Gartner Research

Gartner's research helps you cut through the complexity and deliver the knowledge you need to make the right decisions quickly, and with confidence.

Read Free Gartner Research

Category: announcement  security  siem  

Anton Chuvakin
Research VP and Distinguished Analyst
8 years with Gartner
19 years IT industry

Anton Chuvakin is a Research VP and Distinguished Analyst at Gartner's GTP Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio

Thoughts on My “Evaluation Criteria for Security Information and Event Management” 2015 Update Publishes

  1. […] My “Evaluation Criteria for Security Information and Event Management” 2015 Update Publishes […]

Comments are closed

Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.