This edition publishes the evaluation question and work still required. It contains no scored vendor points.
What must be true
- Required identity and cloud sources are available.
- An analyst can reconstruct and export a timeline.
- Access to evidence can be limited to authorized responders.
Candidate scope
Two publicly documented offerings form a small pilot. Inclusion is for methodology development, not a claim that these are the only or best choices. Exact tiers and test configurations must be frozen before scoring.
| Offering | Scope | Status |
|---|---|---|
| Microsoft Sentinel | Cloud SIEM; exact workload, retention, and purchased features must be fixed before scoring. | Unassessed Capability: null Operating: null |
| Elastic Security — SIEM | SIEM capability; deployment model and feature tier remain unselected. | Unassessed Capability: null Operating: null |
Evidence still needed
- A frozen workload and exact purchased tiers
- Independent repeatable investigation tests
- Documented operating effort and cost estimates
How the evaluation will work
- Fix the workload, organizational assumptions, product editions, and mandatory requirements.
- Publish criterion-specific 0–5 anchors before collecting results.
- Collect reproducible observations, source dates, and operating measurements. Preserve contradictory evidence.
- Use the rubric below without filling unknowns with estimates.
- Have a second reviewer reproduce results. Publish only after both axes reach 80% coverage and critical requirements have explicit results.
| Axis | Criterion | Weight |
|---|---|---|
| capability | Required functions | 40% |
| capability | Representative effectiveness | 30% |
| capability | Evidence and explainability | 15% |
| capability | Required data exchange | 15% |
| operating | Staffing and administration | 30% |
| operating | Environment and deployment | 25% |
| operating | Integration maintenance | 20% |
| operating | Portability and exit | 15% |
| operating | Cost predictability | 10% |
Threshold: 70/100 on each axis. A missing-evidence interval that spans 70 prevents a definitive quadrant label. A critical failure blocks a shortlist recommendation.
Download this research protocol ↓