SIEM

A Security Information and Event Management (SIEM) system aggregates and correlates logs from across the environment to detect and investigate threats. CBROPS covers SIEM alongside SOAR and log management in security monitoring.

Related Terms

All 200-201 Terms

CIA Triad

The CIA triad is confidentiality, integrity, and availability — the three goals that security controls exist to protect.

Defense in Depth

Defense in Depth layers multiple independent controls so the failure of one does not expose the asset.

SIEM

A Security Information and Event Management (SIEM) system aggregates and correlates logs from across the environment to detect and investigate threats.

SOAR

Security Orchestration, Automation, and Response (SOAR) automates incident-response workflows and playbooks to speed detection and containment.

CVSS

The Common Vulnerability Scoring System (CVSS) rates vulnerability severity using metrics like attack vector, complexity, and scope.

5-tuple

The 5-tuple is the set of source IP, destination IP, source port, destination port, and protocol that uniquely identifies a network conversation.

Threat Intelligence

Threat Intelligence is curated information about adversaries, indicators, and techniques used to inform detection and response.

Threat Hunting

Threat Hunting is the proactive search for undetected threats in an environment using hypotheses and data analysis.

Runbook Automation

Runbook Automation (RBA) executes predefined operational and response procedures automatically to reduce manual effort and errors.

Deep Packet Inspection

Deep Packet Inspection (DPI) examines packet payloads, not just headers, to identify applications and threats.

NetFlow

NetFlow records metadata about network conversations — addresses, ports, bytes, and timing — for visibility and analysis.

PCAP

A PCAP (packet capture) is a stored record of raw network traffic that analysts examine with tools like Wireshark.

Chain of Custody

Chain of Custody is the documented, unbroken record of who handled evidence and when, preserving its integrity for investigations.

Disk Image

A Disk Image is a bit-for-bit copy of storage used in forensic analysis so the original evidence is preserved.

Incident Response

Incident Response is the structured process of detecting, containing, eradicating, and recovering from security incidents, guided by frameworks like NIST.