Implementing L1 – foundations
At the foundational level, every organization should be able to reach this approach regardless of headcount and budgetary resourcing. Many of us are likely aware of the popular detection engineering maturity matrix (https://detectionengineering.io/) model. However, unlike that model, this book does not majorly focus on program foundations; rather, we focus on automation foundations.
Note
The technology and practice patterns presented in this chapter are examples. Your architecture and Governance, Risk, and Compliance (GRC) teams may require different items. The concept of the patterns remains the same, but you may need to tweak your approach depending on vendor capabilities.
With that in mind, I believe a team that is maturing their internal automation will always practice detection as code at any maturity level. Engineering teams that generally meet the following profile can typically achieve an L1 pattern:
- 1-3 detection engineers...