Glossary · OT cybersecurity
Security information and event management (SIEM)
Also known as: SIEM, SIEM system
German: Security Information and Event Management (SIEM)
In cybersecurity, security information and event management (SIEM) is a system that collects, normalizes, stores and correlates log and event data from many sources, such as firewalls, servers, controllers and intrusion detection systems, to detect security incidents, support investigations and provide audit evidence.
- OT security
In one sentence
A SIEM collects and correlates log and event data from firewalls, servers, controllers and IDS to detect incidents and support investigations.
Example
The SIEM correlates a VPN login outside service hours with a program download to a PLC five minutes later and raises a high-priority alert to the SOC.
How it applies
- Engineering: OT sources include firewalls, switches, jump servers, Windows-based HMIs and SCADA servers, OT intrusion detection systems and, where supported, controller audit logs. Log forwarding must not load controllers or networks beyond their limits.
- Operation: Correlation rules need OT context: a program download is normal during a planned change and suspicious otherwise. Linking the SIEM to the change calendar reduces false alarms.
- Maintenance: Correct timestamps are essential; Time synchronization across devices makes events comparable.
- Documentation: Product documentation should list which security events a device logs, the log format, how logs are exported (for example syslog) and how long they are kept locally. This information is often missing, which makes SIEM integration difficult.
SIEM vs. SOC
A SIEM is a technical system. A Security operations center (SOC) is the team and process that uses the SIEM and other tools to monitor, analyze and respond.