Implementing L3 – advanced
The final maturity pattern I am suggesting takes full advantage of all the examples and skills presented throughout earlier chapters. Not only is simulated testing important but full integration testing is now a requirement in this phase. In addition, pull requests generate user stories that further merge the workstream into Jira from the GitHub repositories. AI also plays an even more intertwined role in the development and testing cycles of our detections. Additional and expensive tooling may be required to fully utilize this pattern.
Engineering teams that meet the following profile can typically achieve an L3 pattern:
- 10+ detection engineers
- An average load of 20+ detections per week mixed with SOAR and other automation requests
- Dedicated operational fiscal year expenses for the team to run enterprise-grade tools
- Globally dispersed team across multiple time zones and regions without overlap
- The majority of the team is...