Chapter 5: Threat and Vulnerability Management
In this chapter, we will primarily deal with security operation center activities. Security professionals need to identify different types of threats. Insider threats and Advanced Persistent Threats (APT) are two of the biggest threats currently targeting government departments and commercial organizations. It is important to understand the threat actor skills and motivations, and also the resources that they have available to them – how much time can they afford to spend planning attacks? What is their level of financial backing? How sophisticated are the attackers? Is money an objective of the attack (for example, ransomware is nearly always about financial gain)? We need to use threat frameworks to understand how to recognize threats and respond. It is important for security professionals to be able to identify indicators of compromise, and within our security operations center, we also need to respond using a variety of techniques...