Cybersecurity Blue Team Strategies by Kunal Sehgal & Nikolaos Thymianis
Author:Kunal Sehgal & Nikolaos Thymianis
Language: eng
Format: epub
Publisher: Packt
Published: 2023-01-15T00:00:00+00:00
Detective controls
These controls provide visibility into security breaches or any malicious or suspicious activity. Detective security controls function during the progression as well as after the occurrence of the activity. The blue team is responsible for defining the triggers and thresholds of the activities, and alerts are then sent to concerned individuals for action, at the time of detection.
Preventive controls cannot be designed to prevent the occurrence of a threat. Hence, these act as a retrospective check to look for any threats that were not proactively blocked by other controls.
Detective controls use physical, administrative, and technical methods. Physical controls include video surveillance and motion detection, such as activating alarms during the opening of doors without authorization. Examples of technical controls include log monitoring, SIEM, security audits, and the implementation of an intrusion detection system. Lastly, administrative controls include conducting internal audits and finding that there are excess access rights.
As a simple analogy, at an airport, preventive controls are put in place via security guards and immigration counters, to stop any unauthorized person from boarding a flight. On top of that, they may have CCTV cameras as detective controls, which are configured to record and log footage, which can be reviewed as and when needed. Such recording helps the security team look for any threats that may have been able to evade the preventive controls.
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Cryptography | Encryption |
Hacking | Network Security |
Privacy & Online Safety | Security Certifications |
Viruses |
Effective Threat Investigation for SOC Analysts by Yahia Mostafa;(7201)
Practical Memory Forensics by Svetlana Ostrovskaya & Oleg Skulkin(6896)
Machine Learning Security Principles by John Paul Mueller(6869)
Attacking and Exploiting Modern Web Applications by Simone Onofri & Donato Onofri(6524)
Operationalizing Threat Intelligence by Kyle Wilhoit & Joseph Opacki(6504)
Solidity Programming Essentials by Ritesh Modi(4403)
Microsoft 365 Security, Compliance, and Identity Administration by Peter Rising(4000)
Operationalizing Threat Intelligence by Joseph Opacki Kyle Wilhoit(3750)
Learn Computer Forensics - Second Edition by William Oettinger(3498)
Future Crimes by Marc Goodman(3467)
Blockchain Basics by Daniel Drescher(3435)
Mastering Azure Security by Mustafa Toroman and Tom Janetscheck(3429)
Mastering Python for Networking and Security by José Manuel Ortega(3425)
Building a Next-Gen SOC with IBM QRadar: Accelerate your security operations and detect cyber threats effectively by Ashish M Kothekar(3365)
Incident Response with Threat Intelligence by Roberto MartÃnez(3220)
The Code Book by Simon Singh(3030)
Mastering Bitcoin: Programming the Open Blockchain by Andreas M. Antonopoulos(2956)
Mobile App Reverse Engineering by Abhinav Mishra(2934)
From CIA to APT: An Introduction to Cyber Security by Edward G. Amoroso & Matthew E. Amoroso(2836)
