DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
  • United States flag United States
  • Australia flag Australia
  • United Kingdom flag United Kingdom
  • Europe flag Europe
  • New Zealand flag New Zealand
  • Canada flag Canada
DefSec Wire
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security
No Result
View All Result
DefSec Wire
No Result
View All Result
Home Security

NSA and Australia’s ACSC, with partner agencies, issue three cybersecurity information sheets on SIEM and SOAR

Lila Carvello by Lila Carvello
October 12 2025
in Security
0
172
SHARES
2.5k
VIEWS
Share on LinkedInFacebookTwitter

FORT MEADE, Md. — The National Security Agency has teamed with Australia’s cyber authority and a broad coalition of allied partners to publish three how-to guides on planning, deploying, and running Security Information and Event Management and Security Orchestration, Automation, and Response platforms. Released May 27 with the Australian Signals Directorate’s Australian Cyber Security Centre, the materials target both decision-makers and front-line defenders as agencies and contractors accelerate zero-trust adoption and modernize security operations.

The guidance distills what SIEM and SOAR are designed to do, how they work together, and where organizations often stumble. SIEM tools centralize and correlate log and event data so analysts can spot malicious behavior that would otherwise be missed. SOAR platforms then use that telemetry to automate and orchestrate responses, tightening feedback loops and reducing dwell time, particularly in zero-trust environments where continuous verification and granular policy enforcement generate vast volumes of signals.

You Might Also Like

NSA and allies warn of Russian state-backed cyber campaign targeting Western logistics and tech firms

NSA’s AISC issues joint guidance on AI data security risks and best practices

One document, “Implementing SIEM and SOAR Platforms: Executive Guidance,” maps out roles, benefits, risks, and high-level best practices for program leaders. A companion, “Implementing SIEM and SOAR Platforms: Practitioners Guidance,” drills into how the technologies boost visibility, detection, and response, and offers principles for procurement, setup, and ongoing operations. A third, “Priority Logs for SIEM Ingestion: Practitioner Guidance,” provides technical direction on which data sources to prioritize, spanning endpoint detection and response tools, Windows and Linux systems, network gear, and cloud services.

The authoring agencies say the publications are particularly aimed at National Security Systems, the Department of Defense, and the Defense Industrial Base, urging executives, network owners, and defenders in those communities to implement SIEM and SOAR in line with the recommendations to better spot and contain intrusions.

The release carries an unusually broad set of co-seals, reflecting the shared threat picture across allied networks and supply chains. In addition to ASD’s ACSC and NSA, contributors include the Cybersecurity and Infrastructure Security Agency; the Federal Bureau of Investigation; the Canadian Centre for Cyber Security; the United Kingdom’s National Cyber Security Center; New Zealand’s National Cyber Security Center; Japan’s National Center of Incident Readiness and Strategy for Cybersecurity and JPCERT; the Republic of Korea’s National Intelligence Service; the Czech Republic’s National Cyber and Information Security Agency; and Singapore’s Cyber Security Agency.

Beyond technology selection, the documents emphasize the operational realities that often derail SIEM/SOAR programs: integrating diverse data sources, tuning detections to reduce noise, managing storage and retention costs, and building playbooks that automate the right actions without introducing new risk. For leaders, the guidance frames governance, staffing, and measurable outcomes; for practitioners, it details build-and-run tasks from onboarding log sources to maintaining content and playbooks.

The full publications are available on the U.S. Department of Defense website:
– “Implementing SIEM and SOAR Platforms: Executive Guidance”
– “Implementing SIEM and SOAR Platforms: Practitioners Guidance”
– “Priority Logs for SIEM Ingestion: Practitioner Guidance”

Tags: Cybersecurity and Infrastructure Security AgencyFBINational Security AgencyNational Security Systems
Previous Post

NSA and CISA release guidance urging memory-safe languages to strengthen software security

Next Post

NSA’s AISC issues joint guidance on AI data security risks and best practices

Lila Carvello

Lila Carvello

Lila Carvello is a journalist reporting on security and intelligence in the United States and abroad. She focuses on global defence, espionage and national security developments shaping international relations.

Related News

NSA and allies warn of Russian state-backed cyber campaign targeting Western logistics and tech firms

by Lila Carvello
October 12 2025
0

The National Security Agency and a group of U.S. and foreign partners issued a cybersecurity advisory warning that Russia’s military...

NSA’s AISC issues joint guidance on AI data security risks and best practices

by Lila Carvello
October 12 2025
0

Fort Meade, Md. — The National Security Agency’s Artificial Intelligence Security Center has issued a joint cybersecurity information sheet aimed...

NSA and CISA release guidance urging memory-safe languages to strengthen software security

by Lila Carvello
October 12 2025
0

The National Security Agency and the Cybersecurity and Infrastructure Security Agency are urging software makers to adopt memory-safe programming languages,...

NSA, CISA, FBI and DC3 warn Iranian hackers may target vulnerable U.S. networks and high-value entities

by Lila Carvello
October 12 2025
0

Fort Meade, Md. — Four U.S. government agencies have issued a joint advisory warning that cyber actors aligned with Iran’s...

Next Post

NSA’s AISC issues joint guidance on AI data security risks and best practices

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending News

Army broadens eligibility for combat patches

Army broadens eligibility for combat patches

October 1 2025

DCSA director touts DOD, industry, academia and government partnership with America’s Gatekeeper to protect the nation’s trusted workforce, spaces and secrets

October 12 2025
Army cuts training mandates to boost combat readiness

Army cuts training mandates to boost combat readiness

October 1 2025

About

DefSec Wire reports on the news that matters in the Defence, Security and Intelligence industries across the United States and the world.

Our Network

  • DefSec Wire
  • DefSec Wire Australia
  • DefSec Wire UK
  • DefSec Wire Europe
  • DefSec Wire New Zealand
  • DefSec Wire Canada

Categories

  • Air Force
  • Army
  • Defense
  • Marine Corps
  • Navy
  • Security
  • Space Force
  • Uncategorized

Tags

Air Air Combat Command Air Force AN/SPY-6(V)1 Air and Missile Defense Radar Army B-21 Carrier Strike Groups Chance Saltzman Congress Cybersecurity and Infrastructure Security Agency David Allvin Defense Counterintelligence and Security Agency Defense Intelligence Agency Department-Level Exercise Department of Defense Department of the Air Force Eric M. Smith FBI Flashpoint Fleet Marine Force Force Design GEOINT Indo-Pacific John Bentivegna Kevin Schneider Marine Corps National Background Investigation Services National Geospatial-Intelligence Agency National Security Agency National Security Systems Navy Off Duty Pacific Air Forces Pentagon Space and Cyber Conference Space Delta Space Training and Readiness Command Special Forces STARCOM Submarine Troy Meink U.S. Air Force U.S. Army U.S. Fleet Forces Command U.S. Navy

Recent Posts

  • NSA and allies warn of Russian state-backed cyber campaign targeting Western logistics and tech firms
  • NSA’s AISC issues joint guidance on AI data security risks and best practices
  • NSA and Australia’s ACSC, with partner agencies, issue three cybersecurity information sheets on SIEM and SOAR
  • NSA and CISA release guidance urging memory-safe languages to strengthen software security
  • NSA, CISA, FBI and DC3 warn Iranian hackers may target vulnerable U.S. networks and high-value entities
  • About Us
  • Terms of Service
  • Privacy Policy
  • Advertise
  • Contact

© 2025 DefSec Wire – part of the DefSec Wire Group.

No Result
View All Result
  • Home
  • Defense
    • Army
    • Marine Corps
    • Navy
    • Air Force
    • Space Force
  • Air
  • Land
  • Sea
  • Space
  • Cyber
  • Industry
  • Security

© 2025 DefSec Wire – part of the DefSec Wire Group.