CIO Brief: Owning Your Security Data — The OCSF Shift
Retrospective: this article looks back at events from November 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, AWS introduced Security Lake, which stores your security logs in your own cloud account, in a standard format any security tool can read. The bigger idea: you shouldn't be locked into one vendor's tool to access your own security data.
Why owning your security data matters
Many organizations send all their security logs to a single SIEM vendor and pay based on volume. Switching vendors becomes costly, and keeping logs for years becomes expensive. A security data lake keeps logs in cheaper storage you control, in an open format (OCSF), and lets multiple tools use them.
The business impact
- Lower long-term storage costs.
- Flexibility to change or add security tools.
- Better investigations with longer history available.
The trade-offs
- Another system to manage.
- Querying a data lake is slower than a SIEM for real-time detection.
- Requires skills in data management.
Questions to ask your team
- How much do we spend on security log storage each year?
- How far back can we search during an investigation?
- Could we switch SIEM vendors without losing historical data?
What good looks like
Recent, high-value data in your SIEM for fast detection; longer history in a lake you own; a standard format so tools can change without data migration.
The decision
At your next SIEM renewal, ask for an architecture that separates detection from long-term storage. It's often cheaper and more flexible.
- re:Invent 2022: Amazon Security Lake and Verified Access Previews Platform Changes
- How to Centralize AWS Security Logs With Amazon Security Lake How-To & Hardening
- Security Lake Source and Retention Planning Checklist How-To & Hardening