Phase 3 – Investigate
The Investigate phase has multiple goals, but fundamentally, it needs to prepare a detection requirement for development by converting the detection requirements into more technical ones. Executing this process can identify deficiencies in intelligence or data collection, which will need to be resolved before development can start. The following are the inputs and outputs associated with this phase:
- Input: Triaged detection requirement
- Output: Detection of technical specifications and data engineering requirements (if applicable)
The Investigate phase can be broken into four steps:
- Identify the data source
- Determine detection indicator types
- Research
- Establish validation criteria
Let’s take a look.
Identify the data source
During this step, you must identify the relevant data sources needed to satisfy the detection requirement. Analysts will need to understand the intent and scope of the detection...