IADIS International Journal on Computer Science and Information Systems

Published by IADIS (International Association for Development of the Information Society) • ISSN (Online): 1646-3692 • ISSN (Print): 1646-3692
100% Open Access
Double-Blind Peer Review
Crossref DOI Persistent IDs
Open Access Peer-Reviewed Case Studies & Applications

Edo4siem – a Procedure Model for the Implementation of Security Information and Event Management Systems in Organisations

Maximilian Rosenberg *
Bettina Schneider *
Christopher Scherb *
Petra Maria Asprion *
* University of Applied Sciences and Arts Northwestern Switzerland FHNW, Peter Merian Str. 86, 4002 Basel, Switzerland (Portugal)
* University of Applied Sciences and Arts Northwestern Switzerland FHNW, Peter Merian Str. 86, 4002 Basel, Switzerland (Portugal)
* University of Applied Sciences and Arts Northwestern Switzerland FHNW, Peter Merian Str. 86, 4002 Basel, Switzerland (Portugal)
* University of Applied Sciences and Arts Northwestern Switzerland FHNW, Peter Merian Str. 86, 4002 Basel, Switzerland (Portugal)

Abstract

The topic of cybersecurity is becoming increasingly important as the number of cyberattacks continues to grow; it is no longer just a matter of protecting, but rather o f detecting cyberattacks at an early stage and responding accordingly. Detecting cyberattacks in organisations is an increasingly difficult task, since the ability of malware to hide from Anti-Virus systems has massively improved. Therefore, more sophisticated security measures are required, to protect complex information systems from cyberthreats. One of the state-of-the-art solutions is a ´Security Information and Event Management´ (SIEM) system, which collects all security related information and events on a centr al location. Thus, it is possible to correlate and better analyse security-rel ated events, detect, and defend sophisticated threats. The deployment of a SIEM system (SIEMS) is a process where all devices in the network need to be registered and integrated. There is no generic model for the evaluation, deployment, and operation of a sufficient SIEMS that can be applied independently of the dedicated vendor. Usually, vendors provide deployment guides for their SIEMS; however, these are product-specific and not scientifically evaluated. Applying Design Science as methodological approach, the goal of this research was to devel op and scientifically validate a generic model called ´EDO4SIEM´ for the vendor-neutral evaluation, deployment, and operation of a SIEMS in organisations. As desire for future research, the model should be applied in various organisations to confirm its applicability and to further develop it.

Keywords

Cybersecurity Frameworks EDO4SIEM Security Information and Event Management SIEM
Full-Text PDF Available

Read Complete Peer-Reviewed Manuscript

Includes full econometric models, data tables, policy recommendations, declarations, and citations.

Declarations & Ethics

Funding: This research received academic dissemination support through ESCAP / JournalsHub publishing programs.
Conflicts of Interest: The authors declare no competing financial or institutional interests.
Peer Review: Double-blind peer reviewed by international subject specialists.
License: Creative Commons Attribution 4.0 International (CC BY 4.0).
How to Cite This Article
APA / MLA / BibTeX
Rosenberg, et al. (2024). Edo4siem – a Procedure Model for the Implementation of Security Information and Event Management Systems in Organisations. IADIS International Journal on Computer Science and Information Systems, 19(1). https://doi.org/10.33965/ijcsis_2024_v19i1_04
Rosenberg, et al. "Edo4siem – a Procedure Model for the Implementation of Security Information and Event Management Systems in Organisations." IADIS International Journal on Computer Science and Information Systems, vol. 19, no. 1, 2024. https://doi.org/10.33965/ijcsis_2024_v19i1_04
Rosenberg, et al. "Edo4siem – a Procedure Model for the Implementation of Security Information and Event Management Systems in Organisations." IADIS International Journal on Computer Science and Information Systems 19, no. 1 (2024). https://doi.org/10.33965/ijcsis_2024_v19i1_04