SIEM correlation rules automatically detect threat patterns and generate alerts for investigation
Correlation rules that combine events across sources and raise alerts ready for investigation are one detection mechanism inside A.8.16, which also requires acting on what monitoring finds.