{"ok":true,"entity":{"id":"siem","name":"SIEM（セキュリティ情報イベント管理）","entityType":"concept","canonicalName":"Security Information and Event Management","displayName":"SIEM（セキュリティ情報イベント管理）","category":"セキュリティ概念","shortDescription":"各種ログを集約・相関分析して脅威を検知するセキュリティ運用の仕組み。","primaryCluster":"security","parentEntity":null,"verificationStatus":"draft","website":null,"updatedAt":"2026-07-10T07:31:10.004Z","secondaryClusters":[],"alias":["SIEM","Security Information and Event Management","セキュリティ情報イベント管理"],"searchKeywords":["SIEM","ログ分析","脅威検知","セキュリティ運用"]},"references":[{"id":"P-01-001","companyId":"siem","questionId":"P-01-001","instanceId":"QIN-siem-P01-001","promptText":"SIEMとは何ですか？","promptTypeId":"P-01","answer":"SIEM（セキュリティ情報イベント管理）とは、各種ログを集約・相関分析して脅威を検知するセキュリティ運用の仕組みです。","evidencePoints":["siem-ev-001"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/siem/P-01-001","sourceEvidence":[{"id":"siem-ev-001","text":"SIEM（セキュリティ情報イベント管理）は、各種ログを集約・相関分析して脅威を検知するセキュリティ運用の仕組みである。","title":"SIEM（概念）","coverageType":["Identity"],"sourceType":"industry_reference","sourceClass":"Documentation","sourceUrl":null,"confidence":"medium","supportedPromptTypes":["P-01"],"needsVerification":true,"sourceVerified":false,"entityId":"siem"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-02-001","companyId":"siem","questionId":"P-02-001","instanceId":"QIN-siem-P02-001","promptText":"SIEMは個別のログ確認とどう違いますか？","promptTypeId":"P-02","answer":"SIEMは多数の機器やアプリのログを横断的に集約・相関分析する点が特徴で、機器ごとに個別にログを確認する方法と比べ、脅威の兆候を全体像から捉えやすい点が異なります。","evidencePoints":["siem-ev-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/siem/P-02-001","sourceEvidence":[{"id":"siem-ev-002","text":"SIEMは多数の機器やアプリのログを横断的に集約・相関分析して脅威の兆候を検知する点で、個別のログ確認と比べ全体像の把握に優れる。","title":"SIEM（概念）","coverageType":["Capability","Differentiation"],"sourceType":"industry_reference","sourceClass":"Documentation","sourceUrl":null,"confidence":"medium","supportedPromptTypes":["P-01","P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"siem"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-04-001","companyId":"siem","questionId":"P-04-001","instanceId":"QIN-siem-P04-001","promptText":"組織全体のログから脅威の兆候を捉えたいときSIEMはどう役立ちますか？","promptTypeId":"P-04","answer":"はい。SIEMは多数の機器やアプリのログを横断的に集約・相関分析して脅威の兆候を検知するため、組織全体のログから脅威を捉えたいときに役立つ仕組みです。","evidencePoints":["siem-ev-002"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/siem/P-04-001","sourceEvidence":[{"id":"siem-ev-002","text":"SIEMは多数の機器やアプリのログを横断的に集約・相関分析して脅威の兆候を検知する点で、個別のログ確認と比べ全体像の把握に優れる。","title":"SIEM（概念）","coverageType":["Capability","Differentiation"],"sourceType":"industry_reference","sourceClass":"Documentation","sourceUrl":null,"confidence":"medium","supportedPromptTypes":["P-01","P-02"],"needsVerification":true,"sourceVerified":false,"entityId":"siem"}],"generatedAt":"2026-07-10T07:31:10.004Z"},{"id":"P-05-001","companyId":"siem","questionId":"P-05-001","instanceId":"reference-depth-completion-run-cohort3-unit-a","draftId":"reference-depth-completion-run-cohort3-unit-a-siem-p-05-001","promptText":"SIEMの定義について、公的機関による正式な出典はありますか？","promptTypeId":"P-05","answer":"米国国立標準技術研究所（NIST）のComputer Security Resource Center（CSRC）が公開する公式用語集によると、SIEM（Security Information and Event Management）は「様々な種類のログに対して集中的なロギング機能を提供するプログラム」と定義されています。この定義はNIST Special Publication 800-92を出典としており、政府標準文書に基づく公式な定義です。既存の説明（脅威検知のための集約・相関分析の仕組みという説明）と矛盾するものではありませんが、より簡潔に「集中ロギング機能を提供するプログラム」という核心部分を公的機関の文書から直接引用できる点で、出典としての価値があります。","evidencePoints":["siem-ev-cr3-nist-csrc-glossary"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/siem/P-05-001","sourceEvidence":[{"id":"siem-ev-cr3-nist-csrc-glossary","text":"NIST（米国国立標準技術研究所）のCSRC公式用語集は、SIEMを「様々な種類のログに対して集中的なロギング機能を提供するプログラム」と定義しており、この定義はNIST Special Publication 800-92を出典としている。","title":"Security Information and Event Management - Glossary | CSRC","coverageType":["Identity"],"sourceType":"government_data","sourceClass":"Specification","sourceUrl":"https://csrc.nist.gov/glossary/term/security_information_and_event_management","confidence":"high","supportedPromptTypes":["P-05"],"needsVerification":true,"sourceVerified":false,"sourceKind":"official","entityId":"siem"}],"generatedAt":"2026-08-29T15:38:46.199Z","evidenceIds":["siem-ev-cr3-nist-csrc-glossary"]},{"id":"P-02-002","companyId":"siem","questionId":"P-02-002","instanceId":"reference-depth-completion-run-cohort3-unit-b","draftId":"reference-depth-completion-run-cohort3-unit-b-siem-p-02-002","promptText":"SIEMはSOARやXDRと何が違いますか？","promptTypeId":"P-02","answer":"セキュリティ専門メディアeSecurityPlanet（2022年2月12日付）によると、SIEMはハードウェア・アプリケーション・その他のセキュリティツールからログとセキュリティデータを集中的に収集・集約する監視ツールですが、「より多くの監視とチューニングを必要とする」ため、アナリストが設定やアラート調整に多くの時間を割く必要があるとされています。これに対しSOARは自動化とオーケストレーションを重視した新しいアプローチで手作業の介入を減らすことを目的とし、XDRはより高度な機能を持ち複数のセキュリティ製品を統合して広範な自動化と高度な分析を提供するとされています。同記事はSIEMとSOARは「同じ目的を持たない」ため「互換的に使うことはできない」と明記しており、SIEMがより人手による運用に依存する点が両者との違いです。","evidencePoints":["siem-ev-cr3-esecurityplanet-vs-soar-xdr"],"scope":"","differentiation":"","faq":[],"pageUrl":"https://www.refbase.ai/reference/siem/P-02-002","sourceEvidence":[{"id":"siem-ev-cr3-esecurityplanet-vs-soar-xdr","text":"eSecurityPlanet（2022年2月12日付）は、SIEMがログの集中収集・集約を行う一方「より多くの監視とチューニングを必要とする」人手依存の仕組みであるのに対し、SOARは自動化・オーケストレーションを重視し、XDRはより高度な統合と分析機能を持つと解説し、SIEMとSOARは「互換的に使うことはできない」と明記した。","title":"SIEM vs. SOAR vs. XDR: What Are The Differences?","coverageType":["Differentiation"],"sourceType":"industry_reference","sourceClass":"Documentation","sourceUrl":"https://www.esecurityplanet.com/networks/siem-vs-soar-vs-xdr/","confidence":"medium","supportedPromptTypes":["P-02"],"needsVerification":true,"sourceVerified":false,"sourceKind":"third-party","entityId":"siem"}],"generatedAt":"2026-08-29T15:44:42.311Z","evidenceIds":["siem-ev-cr3-esecurityplanet-vs-soar-xdr"]}]}