Book Image

Agile Security Operations

By : Hinne Hettema
Book Image

Agile Security Operations

By: Hinne Hettema

Overview of this book

Agile security operations allow organizations to survive cybersecurity incidents, deliver key insights into the security posture of an organization, and operate security as an integral part of development and operations. It is, deep down, how security has always operated at its best. Agile Security Operations will teach you how to implement and operate an agile security operations model in your organization. The book focuses on the culture, staffing, technology, strategy, and tactical aspects of security operations. You'll learn how to establish and build a team and transform your existing team into one that can execute agile security operations. As you progress through the chapters, you’ll be able to improve your understanding of some of the key concepts of security, align operations with the rest of the business, streamline your operations, learn how to report to senior levels in the organization, and acquire funding. By the end of this Agile book, you'll be ready to start implementing agile security operations, using the book as a handy reference.
Table of Contents (17 chapters)
1
Section 1: Incidence Response: The Heart of Security
5
Section 2: Defensible Organizations
10
Section 3: Advanced Agile Security Operations

A framework for uncertainty

Cyberattacks are characterized by uncertainty. The irony of most of the best practices in cyber defense is that we try to tackle uncertainty with known best practices. When we're up against smart and determined attackers, best practices may not be what we need. For many cyberattacks, strategy and tactics need to evolve alongside the response for defenders to match the strategy of the attacker.

We can characterize this situation as one where there is not only uncertainty but also adversity. That is, since the attacker and defender play a discoordination game, the attacker is intentional in their avoidance of detection, and intentionally tries to not play the game of the defender. In this section, I will focus on the most recent version of the Cynefin framework, developed by David Snowden as a generic management framework for handling uncertainty, and discuss specifically the role of constraints within it and use the recipes in the recent field guide...