02 — Capability · BC-760.30
Threat Detection & Response
Watch for attacks across the estate, respond to confirmed incidents fast enough to limit the damage, and learn enough from each one to see the next one sooner.
- Security Operations Center
- SOC
- Incident Response
In scope
- Security monitoring and alert triage
- Security incident response and containment
- Threat intelligence and hunting
- Forensic investigation and evidence handling
Out of scope
- Technology incident management for non-security outages (see BC-740)
- Crisis communications and business continuity (see BC-830)
Realized by · 2
Used in · 0
- Not yet placed on a value stream.
Build it · 0
- Nothing in the library points here yet.
Decomposes into · 4
- BC-760.30.10Security MonitoringCollect and correlate security telemetry across endpoints, networks, identities and cloud, and triage alerts to the ones worth a human's time.
- BC-760.30.20Security Incident ResponseContain, eradicate and recover from confirmed security incidents under a rehearsed plan, with legal, communications and leadership engaged at the right moments.
- BC-760.30.30Threat Intelligence & HuntingTrack the attackers and techniques relevant to the enterprise and search the environment for signs of them before an alert fires.
- BC-760.30.40Digital ForensicsPreserve and analyze evidence from compromised systems in a way that holds up to legal and regulatory scrutiny.