Cybersecurity GRC 17 items
SIEM Detection Engineering Review
Reviews the detection engineering lifecycle for a SIEM or analytics platform, covering log coverage, rule development, ATT&CK mapping, tuning, and detection-as-code practices.
MITRE ATT&CKNIST 800-53CIS v8
Free PDF · enter your email to download.
Log Source Coverage
- Is there a documented inventory of log sources ingested into the SIEM with owners and criticality? *
- Are critical sources (EDR, identity provider, cloud audit logs, DNS, firewall) confirmed as ingesting? *
- Is log source health monitored to alert on ingestion gaps or silent sources? *
- Is time synchronization (NTP) enforced across log sources for accurate correlation? *
- Is a target for detection coverage against the ATT&CK matrix defined and tracked?
Detection Development
- Do new detections follow a documented development and peer-review workflow? *
- Are detections mapped to MITRE ATT&CK tactics and techniques? *
- Does each detection include documented logic, rationale, and expected data source? *
- Are detections version-controlled as detection-as-code?
- Is each detection assigned a severity and a linked response playbook? *
Tuning & Quality
- Are false-positive rates tracked per detection and reviewed for tuning? *
- Are noisy or deprecated detections retired through a documented process? *
- Are detections tested against known-good samples or adversary emulation before deployment? *
- Is there a feedback loop from incident response to improve or create detections?
Metrics & Validation
- Is detection coverage measured and reported to leadership periodically? *
- Is mean time to detect (MTTD) tracked for validated true positives?
- Are purple-team or breach-and-attack-simulation exercises used to validate detections?
Download the full SIEM Detection Engineering Review checklist
Get it as a clean, printable PDF — free.
