Cybersecurity Operations
Your most active function will be cybersecurity operations. If set up correctly, this function will be operating 24/7/365. If it isn’t, you’ll be incurring increased risk with the possibility of threat actors infiltrating your environment without anyone monitoring activity. Trends have shown that increased activity typically occurs during off-hours, weekends, and holidays. Also, this function will most likely be your largest staffed area within the cybersecurity team, more specifically, the Security Operations Center (SOC). This team’s primary responsibility is to detect and respond to cybersecurity incidents within the organization. This function serves as a critical component within your program and it’s important you invest the time needed to ensure your cybersecurity operations are running as efficiently as possible.
We will begin this chapter with an overview of cybersecurity operations, and everything involved in running...