Why Three Teams

Another opinion on the matter

An Article Review by way of a Dan's New Leaf

For years now we have been defining a SIEM as three teams working together as one. The Security Operation Center, the Blue Team, and the Incident Response Team gather around a database – what most MSSPs call a SIEM – to manage the risk arising from technology that can be addressed with monitoring.

why three teams working together as one team is the best way to manage risk

There are three interactive processes that arise when we try to manage technology risk: Risk Measurement, Risk Response, and Risk Monitoring. Essentially, these are the three ways to manage risk. When you monitor risk, you’re not only monitoring the various decisions made when you respond to risk, but you are also monitoring for threats exploiting both known and possibly unknown vulnerabilities.

Thus, by way of an article review, I submit this article, as the reason why you want Three Teams working together as one:

https://www.bleepingcomputer.com/news/security/google-70-percent-of-exploited-flaws-disclosed-in-2023-were-zero-days/

 

Original article by Dan Hadaway CRISC CISA CISM. Founder and Information Architect, infotex


Dan’s New Leaf – a fun blog to inspire thought in  IT Governance.

To see more content like this in your inbox, sign up for our newsletter here!

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts

The Magnificent Seven 2023

Seven Trends . . . …that small bank Information Security Officers face in 2023 Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . . Welcome t...

“Patch Endpoints Holiday Sweater” – Awareness Poster

Another awareness poster for YOUR customers (and users). Now that we have our own employees aware, maybe it’s time to start posting content for our customers!Check out posters.infotex.com for th...