simpl.
Cybersecurity GRC 17 items

SIEM Detection Engineering Review

Reviews the detection engineering lifecycle for a SIEM or analytics platform, covering log coverage, rule development, ATT&CK mapping, tuning, and detection-as-code practices.

MITRE ATT&CKNIST 800-53CIS v8

Free PDF · enter your email to download.

Log Source Coverage

  • Is there a documented inventory of log sources ingested into the SIEM with owners and criticality? *
  • Are critical sources (EDR, identity provider, cloud audit logs, DNS, firewall) confirmed as ingesting? *
  • Is log source health monitored to alert on ingestion gaps or silent sources? *
  • Is time synchronization (NTP) enforced across log sources for accurate correlation? *
  • Is a target for detection coverage against the ATT&CK matrix defined and tracked?

Detection Development

  • Do new detections follow a documented development and peer-review workflow? *
  • Are detections mapped to MITRE ATT&CK tactics and techniques? *
  • Does each detection include documented logic, rationale, and expected data source? *
  • Are detections version-controlled as detection-as-code?
  • Is each detection assigned a severity and a linked response playbook? *

Tuning & Quality

  • Are false-positive rates tracked per detection and reviewed for tuning? *
  • Are noisy or deprecated detections retired through a documented process? *
  • Are detections tested against known-good samples or adversary emulation before deployment? *
  • Is there a feedback loop from incident response to improve or create detections?

Metrics & Validation

  • Is detection coverage measured and reported to leadership periodically? *
  • Is mean time to detect (MTTD) tracked for validated true positives?
  • Are purple-team or breach-and-attack-simulation exercises used to validate detections?

Download the full SIEM Detection Engineering Review checklist

Get it as a clean, printable PDF — free.