What security information and event management and security orchestration, automation and response each do, and how they fit together.
From Ultra Transcenders SC-900 by Tony Rough (publishing soon)
Security teams receive far more signals than people can read. SIEM and SOAR are the two complementary technologies that turn that flood into investigations and actions.
A security information and event management (SIEM) system collects data from across the whole digital estate (infrastructure, software, services and resources, on-premises or in the cloud) and analyses it to surface threats. Its purposes are:
A security orchestration, automation and response (SOAR) system takes alerts from a SIEM and other tools and triggers automated workflows to respond. It adds two ideas:
The central SOAR object is the playbook, a predefined sequence of automated actions triggered by a type of alert or incident, for example disable the account, notify the team, open a help desk ticket and gather recent activity.
| Aspect | SIEM | SOAR |
|---|---|---|
| Main job | Visibility: collect, correlate and detect | Speed: automate and coordinate response |
| Input | Logs and events from many sources | Alerts and incidents from the SIEM and other tools |
| Typical output | Alerts and incidents | Actions taken, such as accounts disabled or tickets opened |
| Key object | Analytics rule and incident | Playbook |
Combining the two reduces alert fatigue, the state where analysts are so overwhelmed by alert volume that they start dismissing alerts without proper review.
Common trap: Thinking SIEM and SOAR are rival products to choose between - they are complementary. SIEM detects and correlates; SOAR automates the response. Microsoft Sentinel provides both in one service.
This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · SC-900 terms in the glossary · All SC-900 study notes
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
What the free posture management tier includes and what the paid Defender CSPM plan adds.
The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.
The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.