{
  "kind": "unassessed-research-protocol",
  "version": "1.0",
  "publishedAt": "2026-09-19",
  "reviewDue": "2026-12-19",
  "slug": "siem-small-team",
  "segment": "siem",
  "title": "Investigations for a small security team",
  "profile": "Three analysts, cloud and identity logs, a named incident owner, and a requirement to export evidence.",
  "critical": [
    "Required identity and cloud sources are available.",
    "An analyst can reconstruct and export a timeline.",
    "Access to evidence can be limited to authorized responders."
  ],
  "missing": [
    "A frozen workload and exact purchased tiers",
    "Independent repeatable investigation tests",
    "Documented operating effort and cost estimates"
  ],
  "threshold": 70,
  "minimumCoverage": 0.8,
  "rubric": {
    "capability": [
      {
        "name": "Required functions",
        "weight": 40
      },
      {
        "name": "Representative effectiveness",
        "weight": 30
      },
      {
        "name": "Evidence and explainability",
        "weight": 15
      },
      {
        "name": "Required data exchange",
        "weight": 15
      }
    ],
    "operating": [
      {
        "name": "Staffing and administration",
        "weight": 30
      },
      {
        "name": "Environment and deployment",
        "weight": 25
      },
      {
        "name": "Integration maintenance",
        "weight": 20
      },
      {
        "name": "Portability and exit",
        "weight": 15
      },
      {
        "name": "Cost predictability",
        "weight": 10
      }
    ]
  },
  "products": [
    {
      "name": "Microsoft Sentinel",
      "scope": "Cloud SIEM; exact workload, retention, and purchased features must be fixed before scoring.",
      "source": "https://learn.microsoft.com/en-us/azure/sentinel/sentinel-overview",
      "status": "unassessed",
      "capability": null,
      "operating": null
    },
    {
      "name": "Elastic Security — SIEM",
      "scope": "SIEM capability; deployment model and feature tier remain unselected.",
      "source": "https://www.elastic.co/docs/solutions/security",
      "status": "unassessed",
      "capability": null,
      "operating": null
    }
  ]
}