OKR template to enhance effectiveness of SIEM event management and correlation

public-lib · Published 7 days ago

This OKR is centered on improving the potency of SIEM (Security Information and Event Management) event management and correlation. It aims to bolster the security landscape of a firm. Objectively it targets to mitigate risks linked with potential security incidents and ensure robustness of the infrastructure.

The first objective under this OKR calls for building a substantial training regime centered on SIEM event correlation for the security staff of the organization. This includes scheduling training sessions for the staff, pinpointing relevant SIEM event correlation training curriculums and ensuring that at least 80% of the security staff attends these training sessions.

The second objective emphasizes increasing the capability of detecting and alerting for correlated events by 35%. It stresses on improving the existing detection and alerting techniques and implementing sophisticated correlation algorithms. It also caters to improving the alert system for linked event notifications.

The final objective is targeted at reducing false positive alerts by 30% through enhanced correlation rules. This objective pushes for formulating more concentrated correlation rules and implementing them successfully. Also, it encourages an inclusive review of the existing alert correlation rules to gauge their effectiveness.
  • ObjectiveEnhance effectiveness of SIEM event management and correlation
  • Key ResultImplement a training program on SIEM event correlation for 80% of security staff
  • TaskSchedule training sessions for security staff
  • TaskIdentify suitable SIEM event correlation training programs
  • TaskMonitor participation to ensure 80% attendance
  • Key ResultIncrease detecting and alerting for correlated events by 35%
  • TaskTrain team on updated detection and alerting methods
  • TaskImplement advanced correlation algorithms for event detection
  • TaskEnhance alert system for correlated event notifications
  • Key ResultReduce false positive alerts by 30% through improved correlation rules
  • TaskDevelop new, more focused correlation rules
  • TaskImplement and test new correlation rules
  • TaskReview existing alert correlation rules for efficacy
Try in Tability

Related OKRs examples

What's next? Try Tability's goal-setting AI

You can create an iterate on your OKRs using Tability's unique goal-setting AI.

Watch the demo below, then hop on the platform for a free trial.