An organization can proceed gradually.
Phase 1 — Mapping
Identifier:
- users;
- servers;
- endpoints;
- cloud;
- network ;
- applications;
- critical data.
Phase 2 — Risk Analysis
Identify priority scenarios.
Phase 3 — Source Selection
Start with the most useful data.
Phase 4 — Collection
Connect gradually:
- identify ;
- endpoints;
- firewall;
- VPN;
- cloud;
- critical applications.
Phase 5 — Use Cases
Create the first rules.
Phase 6 — Tuning
Reduce false positives.
Phase 7 — SOC
Define the analysis procedures.
Phase 8 — Automation
Gradually introduce SOAR and automation.
Phase 9 — Tests
Simulate attacks.
Phase 10 — Continuous Improvement
Measure and improve.