Determine detection requirements for data sources being on-boarded to the SIEM, and assessing the value of in place SIEM detection cases, in order to determine gaps and overlap in the overall detection scheme. Experience leveraging data from security technologies and referential data sources to define security detection requirements, including detections which correlate data across multiple data sources.