Protecting the data
The importance of protecting the customer's data cannot be understated – as soon as the team accesses customer data or their network, the team has the primary responsibility of protecting that access. Data protection is the team's main goal and comes before any of the other requirements within the threat hunting plan. Failure to do so is not just a failure of the hunt but of the threat hunting team.
During planning, the network and data types that will be reviewed will have been identified along with the customer organization's expectations and requirements for the protection of that data. For example, if the team will be accessing a network that has Payment Card Information (PCI) data on it and the team will be viewing that data, then they must comply with the same cybersecurity standards as the original organization. The easiest way to know what data requires specific security requirements is to ask the organization during the scoping...