Skip to content

Correlation Rule

What is Correlation Rule?

A predefined logic pattern in SIEM systems that triggers alerts when specific combinations of events or conditions are detected across log sources.

Information Security

What the standards actually require on correlation rule

Requirements naming correlation rule across 6 standards, quoted from the control text.

NIST SP 800-922 controls

Design and operate the log management infrastructure per NIST SP 800-92 Chapter 3 (Log Management Infrastructure) + Chapter 5 (Operational Processes).

NISTSP92-3 · Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance

Detect is the third of five functional elements per MSC-FAL.1/Circ.3/Rev.2. Activities include: (1) Anomaly Detection - behavioural baselines for OT systems (bridge equipment patterns + engine room SCADA + propulsion + cargo) + network anomaly detection (deep...

IMO-MSC-FAL-Detect-AnomalyDetection-OT-IT-Monitoring-Reporting-BridgeAlarms · IMO MSC-FAL Detect Function - Anomaly Detection + OT and IT System Monitoring + Bridge Alarms + Log Aggregation + Incident Reporting Channels + Crew Observation

Kuwait NCF Detect function. Security Monitoring and Logging: comprehensive logging (Identity + Network + Endpoint + Cloud + Application + Database + Privileged Access + Network Devices + Cloud Trail + Container + IoT/OT) + centralised log management + Security...

KNCF-Detect-Monitoring-SIEM-SOC-Threat-Intel-CTI-MITRE-ATT-CK-EDR-XDR-MDR-24-7-Continuous · Kuwait NCF Detect + Monitoring + SIEM + SOC + Threat Intel + EDR + XDR + 24/7

Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + c...

LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM · Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12

Operate detection + logging + IR + breach notification + fraud detection per NRF framework + NIST SP 800-61 + state breach notification laws + PCI DSS incident response + brand operating rules.

NRFCS-7 · Detection, Logging, Incident Response, Breach Notification, and Fraud Detection
OSFI B-131 control

Operate cyber security per OSFI B-13 Domain 3 aligned with NIST Cybersecurity Framework 2.0 functions (Govern + Identify + Protect + Detect + Respond + Recover).

OSFIB13-3 · Cyber Security: Identification, Protection, Detection, Response, Recovery

Questions people ask about correlation rule

What is Correlation Rule?
A predefined logic pattern in SIEM systems that triggers alerts when specific combinations of events or conditions are detected across log sources.
Why is Correlation Rule important for compliance?
Correlation Rule is a key concept in Information Security. Understanding correlation rule helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Correlation Rule?
Correlation Rule appears in the requirement text of NIST SP 800-92, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), Kuwait National Cybersecurity Framework, Lloyd's Minimum Standards - Cyber Security, NRF Cybersecurity and Data Privacy Framework (National Retail Federation). Across these standards we have identified 7 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Correlation Rule?
Explore our compliance framework pages to see how correlation rule applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Correlation Rule applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.