Three instruments for working out where your SIEM actually stands. No buzzwords, no vendor slides, no unrealistic promises. Built on the Realistic SIEM Maturity Model.
RSMM was written to give teams an honest way to evaluate a SIEM without drowning in buzzwords or vendor slides. It scores five levels grounded in real outcomes rather than aspiration, across dimensions covering data utility, detection content, alert quality, threat intelligence, engineering process and measurable outcomes.
These tools extend it with three areas the original article touched only lightly: cost and data economics, search and investigation experience, and portability and lock-in. Sections marked Extended in the checklist are those additions.
Everything runs in your browser. There is no backend, no database and no analytics, and nothing you enter is transmitted or stored.
Created by Reza Adineh. Inspired by the work of Anton Chuvakin, Christopher Crowley and Rob van Os, and by SOC-CMM.
See also the Unified Threat-Informed Operations Model, which covers the wider security operation that a SIEM sits inside.