Triaging detection requirements
In this section, we’ll discuss the steps that should be taken and the criteria to be considered when prioritizing requirements. Triage is an important phase of the detection engineering lifecycle because not all detection requirements will have the same impact on the organization’s defenses, so it is important that we prioritize our efforts toward those that will provide the most value. If engineers are provided an unprioritized list of detection requirements, you risk missing the requirements that may prevent a major attack because everyone is working on what they feel like rather than what is best for the organization.
There are four criteria we mentioned in Chapter 2 as factors when triaging requirements:
- Threat Severity
- Organizational Alignment
- Detection Coverage
- Active Exploits
For each detection requirement that comes in, we need to evaluate how it is affected by the above four factors in order to determine...