Phase 2 – Triage
As the backlog for requirements increases, a Triage phase is required to identify what detection should be focused on next. The following are the inputs and outputs associated with this phase:
- Input: Detection requirement created during the previous phase
- Output: Triaged and prioritized detection requirement
In most circumstances, dependencies do not exist between detection requirements, allowing the DE team to choose the next appropriate task from the backlog. Using a first-in first-out queue or predefined priority is not preferable as these methods will not consider the changing external threat landscape and internal attack surface. In Chapter 10, we will review performance management techniques that influence the Triage phase. The Triage phase can depend upon several factors, including the following:
- The severity of the threat
- Your organizational alignment with the threat
- Your detection coverage
- Active exploits