SIEM & Detection Engineering Policy
Table of Contents
- 1. Overview
- 2. Who Must Follow This Policy?
- 3. Systems & Data Covered
- 4. Key Requirements
- 5. Roles & Responsibilities
- 6. Enforcement
- 7. Exceptions
- 8. Related Policies
1. Overview
The SIEM & Detection Engineering Policy describes how Kean University monitors systems for threats, analyzes security activity, and detects suspicious behavior. This policy ensures:
- Continuous security monitoring
- Fast detection and escalation of threats
- Strong logging and alerting practices
- Compliance with regulatory and institutional requirements
2. Who Must Follow This Policy?
This policy applies to all individuals involved in monitoring, logging, or incident analysis, including:
- Kean IT – Information Security
- SOC Analysts
- System Administrators
- Third‑party vendors who manage Kean systems or supply logs
3. Systems & Data Covered
Systems
- University networks, servers, endpoints, and applications
- Cloud and SaaS environments
- Critical systems handling High or Restricted data
Data Types
- Security logs
- Authentication events
- Network traffic
- Application and endpoint logs
- Security alerts and detections
Activities Covered
- Log collection
- Detection rule development
- Alert triage and escalation
- Log retention and secure archiving
- Continuous improvement processes
4. Key Requirements
Expand Key Requirements
4.1 Log Collection
- Critical systems must send logs to the SIEM within 15 minutes.
- Collected logs must include:
- Authentication events
- Network traffic logs
- System/configuration changes
- Application logs for critical systems
- Security alerts
- Logs must contain timestamp, user ID, source IP, and event type.
4.2 Detection Engineering
- Detection rules must cover:
- Known threats
- MITRE ATT&CK techniques
- Compliance requirements
- Rules must be tested before deployment.
- Rules must be reviewed quarterly.
- Updates must occur after incidents or based on threat intelligence.
4.3 Alerting & Escalation
- SIEM alerts must be reviewed within 15 minutes.
- High‑severity alerts must be escalated within one hour.
- Escalation must follow the Incident Response Plan.
4.4 Log Retention
- Security logs must be retained for at least 12 months.
- Archived logs must be encrypted and securely stored.
- Requirements apply to both on‑premises and cloud systems.
4.5 Third‑Party Integration
- Vendors must integrate with the SIEM or provide equivalent monitoring.
- Vendors must supply logs during investigations.
4.6 Continuous Improvement
- Quarterly review of SIEM configuration and detection rules.
- Integration of lessons learned from incidents.
- Tracking and reducing false positives and missed detections.
5. Roles & Responsibilities
Expand Roles & Responsibilities
Kean IT – Information Security
- Administer and maintain the SIEM platform.
- Validate and oversee detection rules.
- Assist with alert triage and escalation.
Kean IT – SOC Analysts
- Monitor alerts continuously.
- Conduct triage and escalate incidents.
- Document findings in the incident management system.
System Owners
- Ensure logs flow to the SIEM from their systems.
- Maintain correct logging configurations.
- Follow log retention requirements.
Third‑Party Vendors
- Provide log access during investigations.
- Support incident response efforts.
Risk Management / Internal Audit
- Review SIEM control effectiveness.
- Validate compliance with governance and regulatory standards.
6. Enforcement
Noncompliance may result in warnings, required training, restricted access, HR actions, or regulatory escalation for severe violations.
7. Exceptions
Exceptions must follow the Exception Management Policy and include:
- Business justification
- Risk analysis
- Compensating controls
- Approval from Information Security
- CIO approval for high‑risk exceptions
- Maximum duration of 12 months
- Quarterly review and documentation in the Exception Register
8. Related Policies
- RC01 – Policy Governance Standard
- KU SEC 10 – Cybersecurity & IT Governance Standard
- Logging & Monitoring Standards
- Data Classification Policy
- Incident Response Plan
- Exception Management Policy
- Vendor Management Policy