Reporting strategy overview
Reporting should help both technical staff and managers get a global overview of the past, present, and future. The reporting strategy we will look at will cover the three main security pillars: people, processes, and technologies.
Reporting must show increases or decreases in the tasks and actions that are generated by these three pillars over time.
While building purple teaming dashboards, you may rely on the following data sources:
- Documentation:
- Emulation plans
- Purple teaming reports
- Collaboration templates (in particular, those that highlight the gap in analysis)
- Cybersecurity project roadmap and investment plans
- Technical:
- Access to the blue team/SOC case management system
- Alerts from SIEM or analytics solutions (or EDR/XDR)
- Detection rules catalog
- MITRE ATT&CK references in CSV format (https://attack.mitre.org/docs/subtechniques/subtechniques-csv.zip)
- If relevant, Ansible logs (for Purple Teaming eXtended (PTX)
The next few sections...