CIOPages
All RFP packages

RFP Package · Cybersecurity & Identity

SIEM & Security Analytics RFP questions and template

126 questions, 10 demo scenarios and a five-vendor scorecard for choosing SIEM & Security Analytics software, in one Excel workbook.

What this package is for

Use it to run a SIEM & Security Analytics software selection, from the first long list to the final scorecard.

What the category covers. Software that collects, normalizes and stores security telemetry, detects threats with rules and behavioral analytics, and supports investigation, case management and automated response. Bought by security operations, detection engineering and IT security leaders replacing a legacy SIEM or consolidating SIEM, UEBA and SOAR.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 29 questions screen out products that lack something you need.
  • RFP, to the shortlist. 63 questions ask how each product does the work.
  • Deep dive, to the finalists. 34 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 100 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Provide your catalog of prebuilt connectors for [log sources in scope], stating for each connector its collection method, its maintainer (you, the source vendor or a community contributor), whether it parses events into your common schema and its last-updated date.

Why it matters. Connectors maintained by third parties or the community may not be updated when a source changes. The buyer then has to repair collection gaps it did not plan to own.

Good answer
  • Each source in [log sources in scope] is listed by name with its collection method (agent, API pull, syslog, cloud storage).
  • The maintainer is stated for every connector.
  • Each entry shows whether events are parsed into the common schema or collected only as raw text.
Red flags
  • A total integration count with no source-by-source list.
  • Connectors that only collect raw events are counted as supported without saying so.
  • No maintainer is stated, or all connectors are described as vendor-supported without distinction.

2. For each point in the data path where your product can apply filter rules before events are stored for search, such as a collector we host or your cloud service, state the filter actions available at that point.

Why it matters. If filtering happens only after ingest, the buyer pays network and processing costs for data it then discards. It also cannot keep sensitive fields off the platform.

3. For each storage tier your product offers, state which of these functions work on data held in that tier, with any limits that apply: interactive search, scheduled detection rules, dashboards and retroactive threat intelligence matching.

Why it matters. If detection rules or searches stop at a tier boundary, events older than [hot retention period] are not covered by detections or hunts the buyer assumes cover them. The buyer cannot size [hot retention period] without knowing what stops working after it.

Capability areas

Data Source Onboarding & Normalization (12)

Prebuilt collectors and connectors for security-relevant sources (endpoint, identity, cloud control planes, network, SaaS), custom parser creation, field normalization to a common schema, and handling of parser breakage when source formats change. Out: generic enterprise APIs and SSO, covered by the integration module.

Ingestion Pipeline, Filtering & Source Health (10)

Pre-ingest filtering, sampling, enrichment with asset and identity context, and routing of events to different destinations; ingestion latency; detection of sources that stop sending or send malformed data. Out: pricing terms for ingestion volume, covered by the commercial module.

Storage Tiering & Retention (9)

Hot, warm, cold and archive tiers, search behavior across tiers, rehydration of archived data, federated query against external security data lakes, and log immutability and integrity for retained data. Out: vendor-side backup and disaster recovery, covered by the business-continuity module.

Detection Engineering & ATT&CK Coverage (14)

Authoring, testing, versioning and deploying correlation and detection rules, detection-as-code workflows, mapping of content to MITRE ATT&CK techniques, vendor-supplied content updates, and tuning and suppression of noisy rules. Out: ML-based behavioral models, covered in UBA.

Behavioral Analytics & Anomaly Detection (10)

User and entity behavior baselining, peer-group comparison, risk scoring and accumulation across entities, baseline learning periods, and analyst control over model sensitivity and exclusions. Out: generative AI assistants, covered in AIA.

Threat Intelligence Integration (8)

Ingestion of indicator feeds over STIX/TAXII and other formats, indicator lifecycle and expiry, automated enrichment of alerts, and retroactive matching of new indicators against historical data. Out: the vendor's own security posture.

Search, Investigation & Threat Hunting (12)

Query language, search performance at the buyer's data volumes, entity timelines and relationship graphs, pivoting between related events, saved hunts and hunting notebooks, and hunt-to-detection conversion. Out: AI-generated query assistance, covered in AIA.

AI-Assisted Triage & Investigation (9)

Natural-language querying, AI-generated alert and incident summaries, automated triage verdicts, evidence and source traceability for AI output, and analyst feedback on AI conclusions. Out: model governance, AI safety and autonomy controls in general, covered by the AI modules.

Alert Triage & Case Management (11)

Alert grouping into incidents, deduplication, triage queues and assignment, case workflow and evidence collection, analyst collaboration, and SOC operating metrics such as MTTD and MTTR computed from case data. Out: external ticketing system connectors, covered by the integration module.

Response Automation & Playbooks (12)

Built-in orchestration, playbook authoring and testing, prebuilt playbooks, bidirectional response actions against EDR, firewall, identity and email controls, approval gates, and rollback of automated actions. Out: generic agent permission frameworks, covered by the agentic autonomy module.

Data Access Segregation, Audit & Compliance Reporting (11)

Restricting which analysts can search which data by business unit, region or tenant (including MSSP-style multi-tenant operation), tamper-evident audit trails of analyst searches and actions inside the SIEM, and compliance reporting and log-review evidence for regulated scopes. Out: the vendor's own certifications, covered by the compliance-certifications module.

Legacy SIEM Migration & Detection Parity (8)

Translation of existing detection rules, dashboards and saved searches from a legacy SIEM, parallel-run comparison of alert output, import or federated access to historical log data, and tooling to confirm no detection gap during cutover. Out: general implementation methodology and staffing, covered by the implementation-onboarding module.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Onboard a log source you have not seen
  2. Trace a stolen credential to containment
  3. Hunt a new indicator set across past data
  4. Write, test and deploy a detection rule
  5. Work a morning alert queue with AI summaries
  6. A critical log source goes silent
  7. One noisy source floods ingestion
  8. Produce retention and review evidence for an auditor
  9. Translate legacy rules and compare alert output
  10. Build and test a containment playbook

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many SIEM & Security Analytics RFP questions are there?

126 solution questions in 12 capability areas: 29 for the RFI, 63 for the RFP and 34 deep-dive questions for the finalists. The workbook adds 100 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
SIEM & Security Analytics

For the business side of the same change: