Institute Resilience Through Detection, Response, and Recovery
Dan Blum · Apress eBooks · 2020
Cyber-resilience is the ability to withstand and recover from inevitable risks materializing. Businesses should become more resilient by identifying their critical assets, top risk scenarios, and basic contingency plans. Starting with the standardization of logging formats, processes, and collection methods, businesses can build up the ability to detect suspicious or anomalous security events across all their IT environments. They can coordinate detection with third parties such as their vendors and service providers. Organizations with high levels of threat actor interest should also consider developing proactive threat hunting capabilities and building up 24x7 security operations center (SOC) coverage.