Applying Foundational Security Operations Concepts
The behaviors of security teams are governed by policies, norms, and best practices. For security teams, there are a number of best practices that are specific to security operations and are focused on keeping the security operations themselves secure (these practices are sometimes referred to as OpSec). The aim of operational security practices is to keep the details of how a team operates out of the hands of attackers.
This section will discuss the following:
- Need to know and least privilege
- Separation of duties (SoD) and responsibilities
- Privileged account management
- Job rotation
- Service-level agreements (SLAs)
In small teams, it can be hard to meet the requirements of SoD and job rotation since there are generally not many team members to divide the duties with. However, that difficulty does not mean that teams should not consider what the requirements are and come up with the most efficient solutions...