Certified Information Security Manager (CISM) — Question 247
An organization has purchased a security information and event management (SIEM) tool. Which of the following is MOST important to consider before implementation?
Answer options
- A. Controls to be monitored
- B. Reporting capabilities
- C. The contract with the SIEM vendor
- D. Available technical support
Correct answer: A
Explanation
Before implementing a SIEM tool, it's essential to determine which controls need to be monitored, as this will guide the configuration and effectiveness of the tool. While reporting capabilities, vendor contracts, and technical support are important, they are secondary to ensuring that the right controls are in place to protect the organization's assets.