In corporations around the world, the topic of cybersecurity and information security is becoming increasingly important as the number of cyberattacks on themselves continues to grow. Nowadays, it is no longer just a matter of protecting against cyberattacks, but rather of detecting such attacks at an early stage and responding accordingly. There is currently no generic methodological approach for the implementation of Security Information and Event Management (SIEM) systems that takes academic aspects into account and can be applied independently of the product or developers of the systems. Applying Hevner's design science research approach, the goal of this paper is to develop a holistic procedure model for implementing respective SIEM systems in corporations. According to the study during the validation phase, the procedure model was verified to be applicable. As desire for future research, the procedure model should be applied in various implementation projects in different enterprises to analyze its applicability and completeness.
翻译:在全球企业中,随着针对自身的网络攻击数量持续增长,网络安全与信息安全议题日益突显其重要性。如今,问题已不再仅仅是防范网络攻击,而是需要在早期阶段检测此类攻击并做出相应响应。目前,尚无通用的方法论框架用于实施安全信息与事件管理(SIEM)系统,该框架需兼顾学术视角,并能独立于系统产品或开发者进行应用。本文基于Hevner的设计科学研究方法,旨在开发一套通用的实施流程模型,用于在企业中部署相应的SIEM系统。验证阶段的研究表明,该流程模型被证实具有适用性。未来研究方向可望将该流程模型应用于不同企业的多个实施项目中,以分析其适用性与完备性。