WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home H2OSecCon 2026 (TLP:CLEAR) CISA and Partners Release New Guidance for SIEM and SOAR Implementation
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

(TLP:CLEAR) CISA and Partners Release New Guidance for SIEM and SOAR Implementation

TLP:CLEAR

Author: Chase Snow

Created: Thursday, May 29, 2025 - 15:07

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Summary: On Tuesday, CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and other international and U.S. partners, released new guidance for organizations seeking to procure Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms.

Analyst Note: Cybersecurity teams need tools that give visibility into their organizations’ network traffic and endpoints. However, simply having the right tools doesn’t automatically offer insights into your security situation. SIEM and SOAR platforms give organizations the visibility necessary to enable efficient security operations and incident response, so far as they are implemented and configured properly. This guidance is applicable to all organizations, whether to get the most out of currently deployed SIEM and SOAR tools, or if seeking to implement these tools for the first time. WaterISAC encourages members to review this guidance and implement the recommended best practices as is appropriate for your utility.

Original Source: https://www.cisa.gov/resources-tools/resources/guidance-siem-and-soar-implementation

Additional Reading:

  • Implementing SIEM and SOAR platforms: Executive guidance
  • Implementing SIEM and SOAR platforms: Practitioner guidance
  • Priority logs for SIEM ingestion: Practitioner guidance

Related WaterISAC PIRs: 12

Related Resources

Members Only

(TLP:AMBER) DHS Office of Intelligence and Analysis Reports (May 21, 2026)

May 21, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – May 21, 2026

May 21, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:GREEN) PEAR Ransomware Claims U.S. Drinking Water Utility as Victim

May 21, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar