Where to begin
Three questions route a team to a path. Do you have a log source inventory: a list of every source feeding the SIEM, with who owns it, how long it is kept, whether its fields are parsed, and whether an alert fires when it goes quiet? Do you have the last 12 months of incidents, each tagged with the ATT&CK techniques the attacker used? How many analyst hours a week go to building and tuning detections?
A team with no inventory builds one, ships DET-0000 for every source, and then scores. A team with an inventory and no incident history takes threat relevance from public prevalence lists and sector reporting, scores every candidate with readiness 3 or higher, and ships the top 10. A team with both scores its own incidents at 5 and ships the top 10. Work on no more rules at once than your weekly hours divided by the hours one rule takes from build through validate. Use 8 hours per rule until you have measured your own number.
DET-0000, Log source silence: Alert when a source in the log inventory has sent nothing for three times its usual gap between events, and never sooner than 1 hour. Every other rule depends on its data arriving. A source covered by this alert is one step closer to a readiness score of 5.