Part 3 – Continuous Improvement and Innovation
The third and final part of this book is about triaging. You are provided with example triage scenarios, flowcharts, and playbooks. The intent is to give you practical knowledge on how to triage detections and how that can still be mapped to the ATT&CK framework. There is even coverage for how the ATT&CK framework can be applied to other teams, showing how universal it can be. It also covers ways to make triaging more efficient through the use of metrics, labels, and automation. The final chapter is where you will hear directly from industry professionals on where they believe the future of cybersecurity and SOC environments is headed.
This part has the following chapters:
- Chapter 9, What Happens After an Alert is Triggered?
- Chapter 10, Validating Any Mappings and Detections
- Chapter 11, Implementing ATT&CK in All Parts of Your SOC
- Chapter 12, What’s Next? Areas for Innovation in Your SOC...