An organization's SIEM generates 500,000 events per day. The security team wants to prioritize which alerts to investigate first. Which framework BEST guides alert prioritization?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because risk-based prioritization multiplies threat severity by asset value and context — is the targeted asset internet-facing, is it in PCI scope — ensuring the most impactful potential incidents receive attention first. A is wrong because alphabetical ordering has no relationship to risk.
Full explanation below image
Full Explanation
B is correct because risk-based prioritization multiplies threat severity by asset value and context — is the targeted asset internet-facing, is it in PCI scope — ensuring the most impactful potential incidents receive attention first. A is wrong because alphabetical ordering has no relationship to risk. C is wrong because chronological ordering does not account for the relative risk of different alerts. D is wrong because endpoint alerts are critical sources of attack chain evidence and ignoring them creates major blind spots.