8: Incident Prevention, Detection, and Response
-
Published:2020
Kathleen M. Moriarty, 2020. "Incident Prevention, Detection, and Response", Transforming Information Security: Optimizing Five Concurrent Data Trends to Reduce Resource Drain, Kathleen M. Moriarty
Download citation file:
Minimized OSes, assurance levels on applications via attestation, and patches to remediate deployed quickly from the code owner will flip the bolted-on security model, while also reducing the resource burden. Prevention is paramount to simplifying security management with detection based on anomalies and behavior changes.
Threat detection and prevention covers large portions of the information security market right now. Products and tools aimed at threat detection are deployed in just about every network. In many cases, tens of products are installed in-line in networks to detect a wide range of threat types. Additionally, information or threat feeds are part of this security market and are used to supplement the knowledge in these tens of products. Large organizations may have eight or more threat feeds of Indicators of Compromise (IoCs) to distribute into their disparate security products to detect specific known threats. The numerous feeds largely overlap. Organizations are fearful that if a feed is not purchased and it has knowledge of a new threat before the others, their network or systems will be at risk. Only the largest of organizations are able to manage the number of products needed to protect and defend their networks. As a result smaller organizations, parts of the supply chain, are in a security market that requires tool sets and personnel that are impossible to attain.
