SecOps & threat management?

Overview

Cloud security is a shared responsibility”

Organisations are under constant threat of cyber-attacks. Assuming the measures in place will suffice in keeping hackers at bay, is not a smart strategy. The organisation must adapt continuously to threats. Assuming the cloud service provider takes full care of security would be a mistake. In the public cloud, security of the platform and solutions are the organisation’s responsibility. The cloud service provider is responsible for security of the cloud, you are responsible for security in the cloud. Even when using SaaS solutions, it is wise not to put blind faith in the cloud service provider. ?

It is better to proactively monitor platforms and solutions on intrusions, unexpected behaviours, failed access attempts and other anomalies. ?

Use systems that can detect and react to ransomware attacks, DDoS attacks, zero-day vulnerabilities and the like. ?

Important is not to rely on human intervention. Instead, automate responses to identified threats. Optimising the automated response of the platform (foundation) is a continuous task of the team operating the platform.?

Solutions, developed by DevOps teams, must comply with the organisation’s corporate information protection standards as well as legislation. Dashboards and reports should be made available to all stakeholders and parties involved detailing the compliance level as well as advise how to address issues. Follow up with DevOps teams, partners or other stakeholders ensures that security levels of solutions are also continuously adapted and improved.

Activities checklist

Initial:

  • Determining the need for logging and auditing information?
  • Choosing and configure tools, such as SIEM, a CASB or a ransomware detection aware backup solution?
  • Defining or adapting and implementing a process for performing SecOps and threat management?
  • Setting KPIs for performing SecOps & threat management?
  • Implementing dashboards and/or reports

Recurring:

  • Continuously improving the platform leveraging its security services?
  • Automating responses to identified threats?
  • Informing DevOps teams of compliance levels and issues?
  • Gathering relevant audit trails for SaaS applications

RASCI

cloud consultantinformedtransformation consultant
cloud architectconsultingcloud partnersinformed
cloud security specialistaccountableDevOps teamresponsible
cloud developerinformedbusiness stakeholder
cloud engineerresponsiblearchitecture
cloud analystresponsiblesecurityresponsible
product owner CCoEfinance
managementprocurement
Scroll to Top