Domain 7 · 13% of the exam

Security Operations

This domain focuses our attention on the day-to-day, moment-by-moment active use of the security controls and risk mitigation strategies that an organization is using. Security professionals reviewing CISSP Domain 7 must understand the principles of security operations and the different tools and techniques that can be used to manage security incidents, disaster recovery, and business continuity planning. This includes understanding the importance of ongoing monitoring and review of security controls and systems and of following regularly updated policies and procedures. Incident detection and response is at the heart of the information security operations' set of processes and principles. Everything done in the name of security operations should revolve around this center, supporting its purpose, enabling the security operations team to quickly and accurately detect potential intrusions or other incidents, and responding to them in a timely manner.

Progress saved on this device

53 lessons · 266 slides · 108 min read

Learning objectives

  • Describe the legal, organizational, and compliance requirements of investigation activities.
  • Assess what makes logging practices effective and efficient.
  • Describe the security implications, operations, and limitations of monitoring systems, including intrusion detection and prevention (IDS/IPS), security information and event management (SIEM), and user and entity behavior analytics (UEBA).
  • Identify organizational enforcement approaches to support change management activities.
  • Justify the use of increased automation of change activities in terms of systems and information security.
  • Apply secure system design concepts, security models, and AC models to typical business and organizational processes.
  • Understand the importance of media management and media protection techniques.
  • Apply various incident response concepts and standards to incident response activities.
  • Evaluate the impact of organizational culture and compliance expectations on incident response.
  • Determine security implications for operational controls.
  • Associate incident response activities with specific attack forms.
  • Assess the security value of third-party services.
  • Identify the necessity and challenges of patch management to address vulnerabilities.
  • Relate organizational change management practices to information security.
  • Identify change management standards.
  • Describe established approaches to improving systems availability.
  • Identify the key steps and resources necessary to support business continuity and recovery processes.
  • Compare implementation and requirements of various types of testing for disaster recovery plans.
  • Discuss participation in business continuity planning and various BC exercises.
  • Identify information security implications of various physical controls.
  • Assess information security implications of personnel safety practices.

Key topics

  • Investigations
  • Logging and Monitoring Activities
  • Configuration Management
  • Security Operations Concepts
  • Resource Protection
  • Incident Management
  • Detective and Preventative Measures
  • Patch and Vulnerability Management
  • Change Management
  • Recovery Strategies
  • Disaster Recovery Processes and Plans
  • Business Continuity Planning and Exercises
  • Physical Security
  • Safety and Security Concerns

Lessons

  1. 01Backup Storage StrategiesAccurate and comprehensive backups are instrumental to facilitating BCDR efforts; this is an essential aspect of the availability facet of the CIA triad.2 min
  2. 02Implement Disaster Recovery Processes - AssessmentAs mentioned in earlier topics within this module, there is a fundamental need to calculate the entire, overall impact of the contingency; this includes both the damaging effects of the event itself, as well as the cost of the response efforts.1 min
  3. 03Implement Disaster Recovery Processes - Training and AwarenessPersonnel assigned to BCDR tasks (responders and those who are part of the critical path, as well as alternates) should receive formal training for their roles; this should include involvement in all tests.1 min
  4. 04Implement Disaster Recovery Processes - Personnelbpy.context.scene.objects.active = modifier_ob print("Selected" + str(modifier_ob)) = modifier ob is the active ob seirror_ob.select - •2 min
  5. 05Implement Disaster Recovery Processes - RestorationThe ultimate goal of the response action is to resume full normal operations. The process to achieve this goal might include the following:2 min
  6. 06Implement Disaster Recovery Processes - CommunicationsThe organization will need to have the capacity and resources for two types of essential contingency communications: internal and external.3 min
  7. 07Major Change Management ActivitiesAll of the major change management practices address a common set of core activities that start with a request for change and move through various development and test stages until the change is released to the end users.2 min
  8. 08Major Change Management Activities - Patch ManagementContinuing with the topic of change management activities, let's review how software routinely requires updating to address weaknesses, improve operating efficiency or added functionality.2 min
  9. 09Major Change Management Activities - Patch Management StepsGoing further with patch management steps, review the following concepts and graphic that shows a typical patch management process:2 min
  10. 10Configuration AutomationA baseline may exist for a single system or it may span thousands of systems.1 min
  11. 11Case study - Bank of Bangladesh - Security Information and Event ManagementCase studyBank of Bangladesh: Security Information and Event Management4 min
  12. 12Storage Media Protection and ManagementIt's tempting to think that the ubiquitous nature of cloud-hosted storage has eliminated the need for physical copies of important datasets or software to be created, stored, protected, managed, used, and then suitably destroyed at the end of their records…1 min
  13. 13Security Controls for AvailabilityCIA Triad Availability: A system or software should be designed and implemented to recover from disruptions in a secure and quick manner to avoid negative impacts to productivity and business continuity.1 min
  14. 14Personnel Management StrategiesIncluding Privileged Account Management, Job Rotation, Mandatory Vacation, and Other Personnel Management Strategies goNg 'A P JIME R322 R358 R3726 min
  15. 15Internal Security ControlsWithin the facility, it is still necessary to maintain levels of security. LUL1 min
  16. 16Intrusion Detection and PreventionIntrusion detection and prevention systems monitor network traffic to identify and block unauthorized or malicious activity in real time.3 min
  17. 17DuressPersonnel should have a means to report to the organization if they are ever put under duress (threatened or hindered in movement).1 min
  18. 18Change Management Standards and PracticesHow organizations affect change has been extensively studied within the context of many professional disciplines.1 min
  19. 19Change Management Board (CMB)Change management boards evaluate, approve, and oversee IT changes to minimize risk and align with business objectives.2 min
  20. 20Threat IntelligenceEffective threat intelligence enables organizations to anticipate, detect, and respond to evolving risks with informed, timely decisions.1 min
  21. 21System Resilience, High Availability, Quality of Service, and Fault ToleranceOrganizations with extreme sensitivity to downtime - medical providers, military and/or intelligence agencies, high-volume online retailers, utilities - have a greater need to ensure BCDR capabilities are comprehensive and effective.2 min
  22. 22Emergency ManagementEmergency management supports continuity by preparing for, responding to, and recovering from disruptions that threaten critical operations.1 min
  23. 23Allowed vs. Blocked ListingControlling access to systems often involves listing items to explicitly allow or block specific files, applications, or connections.2 min
  24. 24Continuous MonitoringInformation Security Continuous Monitoring (ISCM), coupled with automation, is now the norm for enterprise operations.1 min
  25. 25Security Orchestration, Automation, and Response (SOAR)SOAR is a technology solution that streamlines threat detection and response by automating repetitive tasks and workflows.2 min
  26. 26Honeypots and HoneynetsAnother method for protecting the environment involves the use of honeypots: machines that exist on the network but do not contain sensitive or valuable data (a number of machines of this kind, linked together as a network or subnet, are referred to as a…2 min
  27. 27Ingress and Egress MonitoringDifferent tools become relevant depending on whether the risk from the attack is the result of traffic coming into or leaving the infrastructure.4 min
  28. 28Log ManagementLog management collects, stores, and analyzes system activity to support security, troubleshooting, compliance, and operational awareness.3 min
  29. 29Incident Response Activities - DetectionDetecting the first signs of a kill chain in action is the most critical step in responding to the attack.2 min
  30. 30Security Training and AwarenessHealth and human safety are the paramount concern of all security efforts; ensuring personnel are properly trained and aware of safety and security threats and risks is essential.1 min
  31. 31Separation of Duties (SoD) and ResponsibilitiesSeparation of duties reduces risk by ensuring no single individual controls all critical functions or access within a system.1 min
  32. 32User and Entity Behavior Analytics (UEBA)User and Entity Behavior Analytics detects threats by analyzing unusual behavior patterns across users, devices, and systems.2 min
  33. 33Firewalls, IDS, and IPSFirewalls, intrusion detection systems, and intrusion prevention systems are network defenses that control access, detect intrusions, and block malicious activity.1 min
  34. 34Multiple Processing SitesSome organizations that seek to minimize downtime and enhance BCDR capabilities use multiple processing sites to obviate the effects of an impact to any single site.1 min
  35. 35Implement Disaster Recovery Processes - ResponseA BCDR action can be triggered by a number of possible circumstances (natural disaster/severe weather, fire, physical damage to resources, external attack, etc.); to best manage the activation of the response, the organization must determine the following:1 min
  36. 36Implement Disaster Recovery Processes - Lessons Learned From RecoveryAs you read through many business continuity and disaster recovery frameworks, standards, and guidance documents, you might get the impression that after the dust has settled and everything is back more or less to normal it is the right time to catch one's…1 min
  37. 37TravelTravel raises security concerns for cybersecurity professionals, including data theft, unsecured networks, and exposure of sensitive devices or credentials.3 min
  38. 38Recovery Site StrategiesRecovery site strategies provide alternate locations to restore operations after disruptions, ensuring business continuity and minimizing downtime.1 min
  39. 39Third-Party Provided Security ServicesAs mentioned throughout the course, organizations can avail themselves of services offered by external entities to enhance security. This is especially true for organizations for which security is not a core competency.5 min
  40. 40Maintaining the Integrity of an InvestigationPreserving the integrity of an investigation means protecting evidence from alteration, ensuring findings remain trustworthy and legally defensible.1 min
  41. 41Business Continuity Planning and ExercisesPreparing for disruptions and disasters ensures organizations can maintain critical operations and recover quickly through tested continuity strategies.3 min
  42. 42Digital Forensics Tools, Tactics, and ProceduresDigital forensics involves preserving, analyzing, and documenting electronic evidence to support investigations while maintaining its integrity and admissibility.3 min
  43. 43Incident Response Activities - ResponseNIST 800-61 characterizes these activities as Containment, Eradication and Recovery, where the ISO 27035 framework calls them Responses.1 min
  44. 44Investigative TechniquesThere are many ways to conduct an investigation and gather evidence.2 min
  45. 45Case Study - Sony PicturesCase studyThe Sony Pictures hack of 2014 was a cyberattack that targeted Sony Pictures Entertainment, resulting in a massive data breach and widespread disruption.2 min
  46. 46Possible Responses (Case Study - Sony Pictures)Case study answers1. What were the key challenges in conducting a thorough investigation into the Sony Pictures hack?1 min
  47. 47Anti-Malware DefensesAnti-malware defenses detect and remove malicious software to protect systems and networks from compromise.4 min
  48. 48Incident Response Activities, From Recovery to ReviewIncident response activities focus on identifying, containing, and resolving harmful events to minimize impact and restore normal operations.4 min
  49. 49Incident Response Activities - MitigationMitigating an attack involves two logically separate tasks, containment and eradication, which are often done in combination.3 min
  50. 50SandboxingSandboxing isolates code or files in a controlled environment to safely analyze behavior without risking the host system.1 min
  51. 51Reporting and DocumentationAccurate reporting and documentation in cyber investigations ensure accountability, support legal action, and guide future prevention efforts.3 min
  52. 52Evidence Collection and HandlingProper evidence collection and handling preserves the integrity, reliability, and admissibility of information during investigations and legal processes.4 min
  53. 53Machine Learning and AI ToolsMachine learning and Al tools enhance security operations, track performance, metrics, and post emerging threats, that defenders must anticipate and counter.1 min

Practice and revision