SIEM correlation is a cybersecurity control or practice. It supports this objective: combines related events from multiple sources to identify suspicious activity. The implementation should still be validated against the organization's risk, architecture, legal obligations and operating constraints, then adapted rather than copied unchanged between environments.ISO/IEC 27001:2022: https://www.iso.org/standard/27001