0% found this document useful (0 votes)
21 views41 pages

Modern Security Operations Best Practices

The document outlines best practices and lessons learned from Microsoft's Cyber Defense Operations Center, focusing on modernizing security operations to counter evolving cyber threats. It emphasizes the transition from reactive to proactive security measures, the importance of building business relationships, and the need for effective incident management. Key recommendations include enhancing visibility, reducing the attack surface, and adopting a Zero Trust model to improve organizational security posture.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
21 views41 pages

Modern Security Operations Best Practices

The document outlines best practices and lessons learned from Microsoft's Cyber Defense Operations Center, focusing on modernizing security operations to counter evolving cyber threats. It emphasizes the transition from reactive to proactive security measures, the importance of building business relationships, and the need for effective incident management. Key recommendations include enhancing visibility, reducing the attack surface, and adopting a Zero Trust model to improve organizational security posture.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Modern Security Operations:

Best Practices and


Lessons Learned
from the Microsoft
Cyber Defense
Operations Center
Modern Security Operations 2

Contents
1. Security operations overview 3

The role of security operations


Business relationships
Typical security operations functions

2. Modernizing security operations 13

From reactive to proactive


Increasing visibility
Reducing the attack surface
Zero Trust and modern security operations
Protecting against insider threats

3. Security operations best practices 27

4. Final recommendations 37
Modern Security Operations 3

Security operations
overview

As security professionals, you know successful ransomware and extortion attack,


the threats to your environment are both parties profit.
evolving and accelerating.
As attackers continue to innovate, it’s
Cyberattacks today are organized criminal imperative that security teams work to
endeavors. Cybercriminals share information continually modernize their security
with each other about what works and about operations to stay prepared for adversaries.
vulnerabilities. They work to evolve their
techniques as the technology evolves. This means addressing your technology stack
to ensure you have protection and visibility
Cyberattacks are more than just an evolving across all attack vectors. But it also means
technological threat. Trends like ransomware- assessing the processes of your team—is it
as-a-service (RaaS) are part of an increasingly able to protect, detect, and respond to real
industrialized and sophisticated economy, threats quickly and accurately, or are team
where attackers who may not have the skill members overwhelmed with too much
or technical wherewithal to develop their signal, and chasing false positives?
own tools can now manage ready-made
penetration testing and sysadmin tools to We’ve created this guide to help you
perform attacks. These lower-level criminals modernize your security operations and
can also simply buy network access from a protect your organization in an evolving
more sophisticated criminal group that has threat landscape.
already breached a perimeter, and with a

1. Security operations overview 2 3 4


Modern Security Operations 4

Lessons learned from


the Microsoft SOC

The learnings and best practices presented ● Analyst overload—The static rulesets
here are derived from conversations with generated excessive amounts of false
Microsoft customers and from our own positive alerts that led to alert fatigue.
experience developing and maturing our
Security Operations practices at Microsoft. ● Poor investigation workflow—
Investigation of events using the traditional
While it may seem surprising to some, the on-premises SIEM was clunky and required
Microsoft Corporate IT SOC protects a cross- manual queries and manual switching to
platform environment with a significant different tools.
population of Windows, Linux, and Macs
running Microsoft and non-Microsoft Our team knows what you’re dealing with
software. Previously, this SOC operated a because we’ve been there. Throughout this
traditional SOC model similar to what we see in guide, we’ll share with you best practices and
most organizations, and we faced the same set key lessons we’ve learned as we’ve worked
of natural challenges with the model: to modernize our own security operations
at Microsoft for both ourselves and our
● Event volume—High volume and growth customers.
(on the scale of 20 billion events a day
currently) exceeded the capacity of the
on-premises SIEM to handle it.

The Microsoft Corporate IT SOC protects a cross-platform


environment with a significant population of Windows, Linux,
and Macs running Microsoft and non-Microsoft software.

1. Security operations overview 2 3 4


Modern Security Operations 5

The role of security


operations
Security operations maintains and restores
the security assurances of the system as live
adversaries attack it. Its main functions are
described in the NIST Cybersecurity Framework
and include:

● Detect

● Respond

● Recover

1. Security operations overview 2 3 4


Modern Security Operations 6

● Detect—Security operations must detect Effectiveness in these areas reduces risk by


the presence of adversaries in the system limiting how much time and access attackers
that are incented to stay hidden in most have in the organization. This ultimately
cases, as this allows them to achieve their increases the attacker’s cost and decreases
objectives unimpeded. This can take the the benefit, which damages their return on
form of reacting to an alert of suspicious investment (ROI) and motivation for attacking
activity or proactively hunting for anomalous your organization. Additionally, security
events in the enterprise activity logs. operations teams drive overall security maturity.

● Respond—Upon detection of potential Everything in your security operations should


adversary action or campaign, security be oriented toward limiting the time and access
operations must rapidly investigate to attackers can gain to the organization’s assets
identify whether it is an actual attack (true in an attack to mitigate business risk.
positive) or a false alarm (false positive) and
then enumerate the scope and goal of the Security operations is also often an advocate
adversary operation. for increasing security maturity across the
organization because any weaknesses in
● Recover—The goal of security operations security posture can lead to incidents that have
is to preserve or restore the security to be handled by security operations.
assurances (confidentiality, integrity,
availability) of business services during and
after an attack.

1. Security operations overview 2 3 4


Modern Security Operations 7

Business relationships
Building and maintaining relationships with the
business side of the organization improves the
effectiveness of the security team. This includes
making an effort to understand business
strategies and involving leaders in ways that
help them understand what your team does to
prevent and mitigate attacks.

At Microsoft, we focus on four primary


functional integration points with
the business:

● Business context

● Joint practice exercises

● Major incidents updates

● Business intelligence

1. Security operations overview 2 3 4


Modern Security Operations 8

● Business context—Understanding what ● Major incidents updates—Providing


is most important to the organization updates to business stakeholders for major
helps the team apply that context to fluid incidents as they happen allows business
real-time security situations. What would leaders to understand their risk and take
have the most negative impact on the both proactive and reactive steps to
business? Downtime of critical systems? manage that risk.
A loss of reputation and customer trust?
Disclosure of sensitive data? Tampering with ● Business intelligence—Sharing discoveries
critical data or systems? We’ve learned it’s of unexpected targets with business
critical that key security operations leaders leaders may trigger insights such as outside
and staff understand this context as they awareness of a secret business initiative, or
wade through the continuous flood of the relative value of an overlooked dataset.
information and then triage incidents and
prioritize their time, attention, and effort.

● Joint practice exercises—Practicing


response to major incidents together builds
the muscle memory and relationships that
are critical to fast and effective decision-
making in the high pressure of real
incidents, reducing organizational risk. This
practice also reduces risk by exposing gaps
and assumptions in the process that can be
fixed prior to a real incident.

1. Security operations overview 2 3 4


Modern Security Operations 9

How does security operations


work with the other teams in
the organization, especially
the business side of it?

Your team should be aware of key business One of the best ways to build the necessary
priorities so that they can identify the critical relationships with business is tabletop exercises
assets and set security priorities accordingly. for practicing incident response. During the
This allows you to focus on the most critical tabletop exercises, leadership teams—as well as
assets and put the necessary defense systems, incident response stakeholders—all take part.
policies, and automated investigation around This allows security and business stakeholders to
them, so they are aligned to the business team. build relationships. The two functions will learn
how to work best together so that when there’s
Knowing who the key stakeholders are and an incident, everybody knows who the other
informing them immediately allows the whole parties are, how to engage, and what to do to
business to respond, including: address the emergency.

● Security operations

● Operations

● Logistics

● PR/communications

● Business leadership

1. Security operations overview 2 3 4


Modern Security Operations 10

Typical security
operations functions
The most common component of security
operations is incident investigation and
response, and this is where most security
operations teams will begin their development.
Typical functions include the following.

● Incident investigation and response—


This includes looking into alerts from
the security tools (e.g., SIEM, XDR, EDR),
investigating, and remediating. In larger
organizations, every aspect of incident
response is likely to be handled in-house.
But in smaller organizations, or those with
less developed security functions, sometimes
these duties are entirely outsourced to
a managed security services provider
(MSSP). In other instances, a hybrid model
will develop with triage and high-speed
remediation outsourced to the MSSP while
advanced investigation is kept in-house.

1. Security operations overview 2 3 4


Modern Security Operations 11

● Tactical threat intelligence—Most incident. Large organizations will likely


common in larger organizations, tactical have a full-time incident manager, while
threat intelligence focuses on technical smaller organizations may handle this as
things like indicators of compromise (IOCs), a temporary, as-needed role. This role
malicious IP addresses, bad DNS names, and requires a specialized skill set different
file hashes. In some cases, the organization from the technical investigative skills of
will consume information from a threat other analysts.
intelligence service to address this function,
while other organizations will produce ● Dedicated SIEM infrastructure
their own and do their own research. The management—Organizations that rely on
tactical threat intelligence is very much on-premises, infrastructure-intensive SIEMs
a support function of the investigation may have an in-house team to maintain
response function and deals with alerts and the SIEM infrastructure. The infrastructure
investigations in progress. of legacy on-premises SIEMs can become
very large and complex. In those instances,
● Incident/crisis management—When a supporting the analyst teams in their
major incident or significant crisis puts the advanced queries and hunts for attackers
business at risk, organizations may employ might require additional personnel. As
the specialized role of Incident Manager or organizations migrate to cloud-based
Crisis Manager. This is an individual who is SIEMs, like Microsoft Sentinel, we would
adept at managing crisis response, assessing expect this function to phase out or be
regulatory or compliance effects of redirected to other infrastructure needs
incidents, and maintaining communication as there is no infrastructure management
with business leaders throughout the needed with a cloud-based SIEM.

The tactical threat intelligence is very much a support


function of the investigation response function and deals
with alerts and investigations in progress.

1. Security operations overview 2 3 4


Modern Security Operations 12

For more advanced security


operations teams:

● Proactive hunting—A talented and Realistically speaking, at the current time, there
determined adversary can sometimes find is a talent shortage for security analysts. For
a way around your detections. Once inside, any company that has an in-house security
adversaries hide in the noise to look like operations team, the main focus of the team
a lower priority. They evade and can get must be incident investigation and response.
missed by normal processes. The industry is As this baseline need is met and the team
recognizing that there is a need for proactive matures and expands, the team’s functions can
hunters to go look for adversaries to find and also expand and move more toward proactive
eliminate those that have found their way hunting and strategic threat intelligence. But
around the primary defenses. We’ll talk more if you have only a small team, your focus must
about proactive hunting in the section on and should be on identifying and responding
best practices. to incidents.

● Strategic threat intelligence—This threat


intelligence function is distinct from the
tactical threat intelligence function we
discussed earlier that provides the technical
indicators of compromise. Strategic threat
intelligence is forward-looking and provides
strategic guidance, intelligence, and
research on the kinds of threats and attacks
the business may face, and consideration
of the risks and consequences to the
business if those attacks occur. Strategic
threat intelligence personnel are there to
advise the CISO or business leaders so they
understand the current threat landscape and
how to interpret the news they see from a
cybersecurity standpoint, then add it to their
strategic planning.

1. Security operations overview 2 3 4


Modern Security Operations 13

Modernizing
security operations

Modernizing security operations


requires maturing your tooling and
processes to support an evolution
from a reactive stance to a proactive
stance and from a network perimeter
model to a security model that uses
identity as the primary control plane
for security.

From reactive to proactive

Increase visibility

Deep tooling and automation provide your


analysts the visibility and time savings they
need to be able to shift from purely reactive
responses to proactively preparing for—and
searching for—adversaries. This type of tooling
is often referred to as extended detection and

1 2. Modernizing security operations 3 4


Modern Security Operations 14

response (XDR) and is focused on providing 1. Many alerts are handled via automation
high-quality detections and other capabilities without requiring an analyst’s time.
for specific resources like endpoints, identities,
cloud storage accounts, and so on. 2. The quality of alerts making it to your
analysts’ queues goes up dramatically as the
Many organizations continue to rely on analysts gain the precise visibility into what is
legacy, on-premises SIEMs, and a log-centric really happening, and where, that they need
analysis process. It is important to remember, to be successful.
though, that “collection is not detection”—
simply collecting logs won’t help you much 3. As technology increasingly automates
if there’s too much data for your analysts to security operations’ reactive functions,
sift through. You’ll miss the signal inside the analysts can focus more on the proactive
noise and increase the chances your analysts hunting aspect of security and start
will waste precious time chasing false positives searching for anomalies and hunting for
while real threats go unacknowledged. From adversaries in their environment.
the legacy SIEM and log-centric approach,
organizations should work to evolve into a This kind of evolution from reactive to
model using cloud-based SIEM, like Microsoft proactive, and from on-premises SIEM
Sentinel, and deep tooling, such as an and tooling to cloud-based, is not always a
endpoint detection and response (EDR) and straight line. But this is generally the maturity
other specialized detection tools. When these trajectory we see historically. We anticipate
detection tools are integrated with a cloud- it will increase in the future, and we
based SIEM that can apply Machine Learning, recommend it as a model for organizations
Behavior Analytics, and Security Orchestration interested in taking productive steps to
Automated Response (SOAR) technology to modernize their security operations.
the incoming alerts, three things happen:

1 2. Modernizing security operations 3 4


Modern Security Operations 15

Reducing the attack surface is another These are the steps of a


proactive step you can take. Most attacks
typical kill chain:
against an organization follow the structure
of what is known as the cyber kill chain.
1. Reconnaissance—Criminals devise ways
The kill chain helps us to understand how a
to exploit an organization or a user within
typical attack works and what technologies
an organization. This activity can include
can help mitigate the threats in each section
research to uncover information that can be
of the chain. By understanding the chain,
used in a spear-phishing campaign, dark web
organizations can place “breaks” into each
activity where criminals purchase information
link of the chain to stop an attack or keep it
on vulnerabilities within an organization, or
from spreading.
reconnaissance to uncover the weak spots in
an organization’s infrastructure or user base.

2. Exploit a vulnerability—Threat actors


then launch an attack. It could be a common
phishing campaign, or a more sophisticated
technique designed to deliver malicious code
to an organization’s systems.

3. Lateral movement—Once inside, criminals


use their access to move, often undetected,
through an organization’s systems to locate
key data. They may take steps to cover their
tracks or add other entry points should the
original breach be discovered.

4. Data exfiltration—Once they find the data


they’re seeking, whether it’s personal, financial,
intellectual property, or other sensitive
information, criminals can steal it or encrypt it
as part of a ransomware attack.

1 2. Modernizing security operations 3 4


Modern Security Operations 16

A lack of orchestration across your tools can sections of the kill chain and still leaves
put an extra burden on security analysts to organizations vulnerable, because the tools are
decipher threats manually, which slows down often siloed and must be managed separately.
responses when time is of the essence. This allows for critical gaps in visibility and
coverage—gaps that attackers can exploit.
A traditional perimeter defense strategy is no
longer enough to mitigate attacks against an A holistic approach to risk mitigation for
organization. Modern attack techniques such today’s evolving threat landscape requires
as phishing and password spray are designed a platform that can give CISOs and their
to defeat perimeter defenses. Additionally, a teams integration and visibility across the
growing amount of data exists in the cloud organization. This integrated approach closes
and on mobile devices outside the corporate your gaps to reduce the attack surface. This
network. In response, security leaders must approach is enabled by integrating a cloud-
move away from perimeter-based protections, native SIEM system, which provides breadth
which are designed simply to keep the bad across platforms with extended detection and
actors out, and toward a protect/detect/ response (XDR) solutions. These solutions in
respond approach designed for today’s turn provide in-depth threat protection across
“assume breach” world. domains to help defenders connect seemingly
disparate alerts and get ahead of attackers.
This multi-layered approach, however, is
often implemented through point solutions
deployed piecemeal to address specific

Modern attack techniques like phishing and password spray


get around the perimeter and resources increasingly live in the
cloud and on mobile devices outside the corporate network.

1 2. Modernizing security operations 3 4


Modern Security Operations 17

Microsoft´s approach

In the Microsoft SOC, we enable this breadth and depth visibility with the integrated SIEM + XDR
capabilities of Microsoft Sentinel, Microsoft 365 Defender, and Microsoft Defender for Cloud.

Microsoft Sentinel
Cloud-native SIEM, providing intelligent security analytics enterprise-wide

Ingest data Detect Investigate Hunt Automated


from your entire with correlation across all with all of workflows with
environment across signals your security your data all your tools
solutions

Shared incidents with


bi-directional syncing

XDR Additional signals


Microsoft 365 Defender Microsoft Defender for Cloud
Secure your end users with Secure your multi-cloud and
protection for: hybrid-cloud workloads with
• Endpoints • Applications protection for:
• Email • Data • Servers • Containers
• Identities • IoT • Databases • Cloud
• Storage applications

1 2. Modernizing security operations 3 4


Modern Security Operations 18

● Microsoft Sentinel, our industry-leading, Security operations


cloud-native SIEM collects from any source,
any data, and any entity. Sentinel delivers Microsoft reference architecture
intelligent security analytics and threat
intelligence across the enterprise, providing Our technical vision for security operations
alert detection, threat visibility, proactive has people—analysts and hunters—at the
hunting, and an orchestrated threat center of it. Our integrated SIEM + XDR
response with built-in SOAR technology. security technologies are applied to help the
analysts and hunters succeed by delivering
● Microsoft 365 Defender provides an deep insights for high-quality alerts that
extended detection and response (XDR) incorporate both depth of signal via XDR
across identities, endpoints, applications, and breadth of signal via our cloud-native
and email. SIEM, Microsoft Sentinel. Our XDR protection
extends from Microsoft products and services
● Microsoft Defender for Cloud provides to everything else in the environment, and
comprehensive multi-cloud protection its coordinated detection and response can
for IoT, infrastructure, cloud resources, find and remove even sophisticated chains of
and workloads. attack to stop adversaries from moving across
the environment if they do get in.

Learn more about Microsoft integrated


threat protection with SIEM and XDR.

Our integrated SIEM + XDR security technologies are


applied to help the analysts and hunters succeed by
delivering deep insights for high-quality alerts.

1 2. Modernizing security operations 3 4


Modern Security Operations 19

Zero Trust and modern


security operations
By now, most organizations have good
defenses in place for network-based attacks.
Recognizing this, attackers have shifted their
tactics to identity-based and application-
based attacks where defenses are weaker. In
addition, devices and apps are now leaving
the network, eliminating the perimeter as
point of control.

Modernizing means evolving your


defense tactics to match the tactics of
your adversaries. That’s why we strongly
recommend adopting a Zero Trust Security
model because the Zero Trust model is
an identity-first model. We are not saying
you should now ignore networks, but you
need to focus first on identity-based attack
techniques, and we recommend making it
your first priority to build identity security
skills and capabilities.

Instead of building up strong defenses on


the network and then believing everything
behind the corporate firewall is safe, the
Zero Trust model assumes breach and verifies
each request as though it originates from
an uncontrolled network. In the Zero Trust
model, there is no trusted network—every
network is hostile.

1 2. Modernizing security operations 3 4


Modern Security Operations 20

1. Verify explicitly – Always authenticate A Zero Trust approach should extend


and authorize based on all available data throughout the entire digital estate and serve
points, including user identity, location, as an integrated security philosophy and end-
device health, service or workload, data to-end strategy. This is done by implementing
classification, and anomalies. Zero Trust controls and technologies
across six foundational elements: identities,
2. Use least privileged access – Limit user endpoints, applications, data, infrastructure,
access with Just-In-Time and Just-Enough and networks. Each of these six foundational
Access (JIT/JEA), risk-based adaptive policies, elements is a source of signal, a control plane
and data protection to protect both data for enforcement, and a critical resource to be
and productivity. defended. This makes each an important area
to focus investments, starting with identity.
3. Assume breach – Minimize blast radius
for breaches and prevent lateral movement
by segmenting access by network, user,
devices, and application awareness. Verify
all sessions are encrypted end to end.
Use analytics to get visibility, drive threat
detection, and improve defenses.

Each of these six foundational elements is a source of


signal, a control plane for enforcement, and a critical
resource to be defended.

1 2. Modernizing security operations 3 4


Modern Security Operations 21

Identities Endpoints
Human Corporate
Non-human Personal

Strong Device
authentication compliance

Request Risk
enhancement assessment

Policy Threat
optimization Zero Trust protection
Governance policy Continuous assessment
Compliance Threat intelligence
Evaluation
Security posture assessment Forensics
Enforcement
Productivity optimization Response automation

Traffic filtering and segmentation

Network
Public Private

Classify, label, encrypt Adaptive access Runtime control

Data Apps Infrastructure


Emails and documents SaaS apps IaaS - PaaS - Internal sites
Structured data On-premises apps Containers - Serverless
JIT and version control

Telemetry / analytics / assessment

1 2. Modernizing security operations 3 4


Modern Security Operations 22

The role of orchestration


in Zero Trust
Orchestration is the process of integrating
applications and automating a workflow. As
already mentioned, Zero Trust is most effective
when fully integrated in an end-to-end
strategy. But achieving that integration in a
way that supports compliance and operational
efficiency requires careful orchestration.

This means enforcing clear Zero Trust


policies and continuous evaluation of
the effectiveness of these policies so that
adjustments can be made as needed.
Ongoing assessment is vital for optimizing
governance, compliance, and productivity
while maintaining a strong security posture.
Incorporation of a threat intelligence feed
makes it easier to adjust policies according to
the latest threats, and response automation
makes it possible to respond to attacks in real
time and drive efficiency.

To help you plan and implement a shift to Zero


Trust, this is our recommended roadmap for
pursuing a Zero Trust modernization strategy.

1 2. Modernizing security operations 3 4


Modern Security Operations 23

Align segmentation
Finish strategy
strategy and teams

● Unify identity, devices, applications, data, ● Modernize apps and retrofit strong
infrastructure, and networks into a single assurances to legacy on-premises assets via
enterprise segmentation strategy. You need App Proxy.
everyone on the same page, all pursuing
● Increase protection levels for sensitive data
the same strategy, with the same priorities,
(CASB, CA access control, AIP).
and speaking the same language.
● Retire legacy authentication protocols.

Build a modern, identity-


based perimeter Refine segmentation and
● Establish your critical path using user and network perimeter
device assurances. ● Segment assets with business-critical, life/
User – Require Passwordless or MFA safety, and operational/physical impact.
to access modern applications. ● Add microsegmentation to further
Device – Require device integrity reduce risk.
for access.
● Retire and isolate legacy computing
platforms such as those with unsupported
We recommend that you roll out your critical operating system and applications.
path to IT administrators first.

IT admins can give you technical feedback


to help you make refinements before wide
rollout, and IT admins are targeted by
attackers, so a breach of their accounts can
have very high impact. Secure IT admins first,
then secure regular users.

1 2. Modernizing security operations 3 4


Modern Security Operations 24

Getting started with


Zero Trust

Zero Trust is a security model, not a Step one of implementing your Zero Trust
specific technology, and achieving Zero security model, then, is to connect all your
Trust is a journey, not an on/off switch. In apps to a single cloud identity solution, like
today’s mobile, remote, and hybrid work Microsoft Azure Active Directory. This allows
environments, you can no longer rely on a you to create identity-based security and
network perimeter for security—the network apply custom policies across your entire
perimeter has disappeared. Security operations environment to control access to every
should align around identity-based protection app. With that step complete, you can then
to lay the groundwork for a Zero Trust model. implement multifactor authentication (MFA)
Users can have multiple devices and can access for all your apps. MFA is a consistent, strong
enterprise resources from a variety of networks security policy that can block up to 99.9
and apps. Almost all of these resources require percent of account compromise attacks.
authentication, making identity a common
denominator across all access requests, To evaluate your organization’s Zero
whether from a personal device on a public Trust security posture, take the Zero Trust
Wi-Fi network or a corporate device inside the maturity assessment.
network perimeter. By using identity as the
control plane, you can treat every single access Microsoft’s recommended identity solution
request as untrusted until the user, device, and for Zero Trust is Azure Active Directory, part
other factors are fully vetted. of Microsoft Entra. To learn how you can
begin your Zero Trust journey with Identity
and Access Management, read Securing
identity with Zero Trust.

1 2. Modernizing security operations 3 4


Modern Security Operations 25

Protecting against
insider threats
With a Zero Trust security model and an
integrated security suite in place, security
operations can better protect the organization
against external threats. However, you must
also guard against insider threats with tools
and processes that protect information, users,
and devices.

Data now extends well beyond on-


premises infrastructure into multi-cloud
and hybrid cloud environments, extending
your responsibilities across the entire data
lifecycle—from when data is created to when it
is retired or deleted.

Knowing what data you have, who is accessing


it, and what they are doing with it is essential
to the security of the organization. But, as
with streamlining identity security, a key
piece of these efforts is to reduce risk without
compromising user productivity across this
expanded IT landscape.

1 2. Modernizing security operations 3 4


Modern Security Operations 26

Organizations have a variety of technology We recommend you focus your end-to-end


and tools at their disposal for managing and insider threat protection efforts around
protecting data at different stages of the three key steps:
lifecycle. While these tools provide flexibility,
they also add significant complexity. A ● Identifying your data
recent IDG study found that organizations
use an average of nearly five different data ● Classifying your data
management systems for activities such
as classification, e-discovery, and records ● Deploying tools and policies to
management. Integrated security solutions can safeguard your data
also protect against insider threats by closing
critical gaps that lead to data leakage and The goal should be to help ensure all
giving you end-to-end visibility throughout information is protected—however and
the data lifecycle. wherever it’s used.

Knowing what data you have, who is accessing it, and


what they are doing with it is essential to the security of
the organization.

1 2. Modernizing security operations 3 4


Modern Security Operations 27

Differentiating intentional
versus unintentional risk

Internal threats are an inevitable part of every But there are other classes of threats where
business and sometimes data is put at risk the user may not even know they’re breaking
even in the normal course of legitimate work. corporate policy. A user might be excited
Think about the number of people who access about a project and share information about
resources, the natural cycle of people coming it outside their group, for example, and in the
and going from a company. With the right process they commit a data leak not realizing
processes, capabilities, and controls in place, they’re sending sensitive information. Tools to
you can maintain oversight of data and trust stop that inadvertent data leak before it can
with users without undermining productivity. happen and/or to investigate it and see it in
real time, in context, enable you to determine
One important capability to have in place is the intent and the impact—and decide if this
that of differentiating between an intentional was a single act of carelessness or part of a
and an unintentional risk from your users. A larger, potentially malicious pattern.
truly malicious user might try to do things that
go against your corporate policies—turning As you surface risk you need to make sure your
off security controls, for example, or installing focus remains on the genuinely suspicious
malicious software. activity, so you don’t cause problems with
users or overwhelm analysts with alerts that
Often the intent is to leak or steal data for are false positives.
personal gain or for malicious reasons.
Learn about Insider Risk Management in
Security operations must be prepared for such Microsoft Purview.
events and needs ways to prevent, detect, and
contain those types of threats.

1 2. Modernizing security operations 3 4


Modern Security Operations 28

Security operations
best practices

As we mentioned earlier, at the center Your goals should be to empower your people
of security operations are people— to progress through the OODA loop as quickly
specifically the security analysts. as possible, with the best information possible,
so they can make the best decisions and take
As your analysts do their work, they will either the most effective actions possible.
formally or informally progress through what is
known as an OODA loop: To make better decisions faster, focus on
maximizing visibility, reducing manual steps,
and maximizing human impact.
● Observe

● Orient

● Decide

● Act

1 2 3. Security operations best practices 4


Modern Security Operations 29

Maximize visibility We strongly believe in the power of


automation and technology to reduce
● Internal—Minimize internal blind spots
human toil. But ultimately, the attackers
by ensuring you have good coverage (as
you’re dealing with are human operators so
close to 100 percent as you can manage) as
human judgment is critical to the process of
well as coverage of asset types (including
defending against threats.
identities, endpoints, email, cloud
applications, on-premises datacenters,
Automation should not be about using
cloud datacenters, and data on cloud SaaS
efficiency to remove humans from the
and PaaS applications).
process—it is about empowering humans.
Think about how you can automate
● External—Ensure you have a diversity of
repetitive tasks from the analyst’s job, so
threat feeds from external sources that
they can focus on the complex problems
gives you insight and context from the
that people are uniquely able to solve.
external environment of malware, email
attacks, attack websites, compromised
Automation empowers humans to do more
passwords/identities, etc. Maximize the
by increasing response speed and capturing
freshness and fidelity (relevant details) of
human expertise. It reduces the burden
the external threat sources you use.
and boredom of repetitive tasks, enabling
analysts to focus time and creativity on new
Reduce manual steps (and errors) challenges and threats.

Automate and integrate as many manual


processes as possible to remove unneeded
human actions that lead to slowdowns and
potential human errors.

Rapidly sorting out the signal (real detections)


from the noise (false positives) requires
investing in both humans and automation.

1 2 3. Security operations best practices 4


Modern Security Operations 30

Maximize human impact

For the places in the process where it makes Additionally, you should ensure learning is
sense to have human interaction (difficult integrated throughout the process, up to
choices, new decisions, etc.), you should and including consideration of when you
ensure that your analysts have access to deep would watch an attack unfold to learn its
expertise and intelligence to make those objective (long-term value) vs. blocking it
decisions better. (short-term value).

Making better decisions faster

Maximize visibility Internal – Sensor coverage completeness and diversity

External – Threat Feed Diversity and fidelity

Reduce manual steps Automate – Detection and response tasks


(and errors) Integrate – Investigation tools

Maximize human impact Provide analysts with access to deep expertise and
intelligence Continous Learning—observe attacks
and integrate learnings into defenses

Detect Respond Recover

Observe Orient Decide Act

1 2 3. Security operations best practices 4


Modern Security Operations 31

Security operations culture

Culture guides countless decisions each day ● Teamwork—We recommend that you
by establishing what the right answer looks shouldn’t tolerate the “lone hero” mindset
and feels like in ambiguous situations, which on the team. Nobody alone is as smart as
are plentiful in security operations. the whole team together. Teamwork makes
a high-pressure working environment much
Focusing cultural elements on people, more fun, enjoyable, and productive when
teamwork, and continuous learning helps everyone knows they’re on the same team
ensure your team is continually evolving and everyone has each other’s back. In the
to keep pace with the threats it is there to Microsoft Security Operations Center, we
protect against: design our processes and tools to divide
up tasks into specialties and to encourage
● Use your human talent wisely—Our people to share insights, coordinate and
people are our most valuable assets, and check each other’s work, and constantly
we can’t afford to waste their time on learn from each other.
repetitive, thoughtless tasks that can be
automated. To combat the human threats ● Shift left mindset—To get ahead and stay
we face, we need knowledgeable and ahead of cybercriminals and hackers who
well-equipped humans that can apply constantly evolve their techniques requires
expertise, judgment, and creative thinking. continuously improving and shifting your
This human factor affects almost every activities “left” in the attack timeline.
aspect of security operations, including the Focusing on speed and efficiency helps the
role of tools and automation to empower team get “faster than the speed of attack”
humans to do more (versus replacing by looking at ways they could have detected
them) and in reducing toil on our analysts. attacks earlier and responded more quickly.
This principle is effectively an application of
a continuous-learning growth mindset that
keeps the team laser-focused on reducing
risk for the organization and customers.

1 2 3. Security operations best practices 4


Modern Security Operations 32

Segregate high-privileged
accounts

Not all attacks are created equal from the significant variables that are out of our direct
standpoint of the damage they could do control (attacks, attackers, etc.). We view
to your business if successful. High profile deviations primarily as a learning opportunity
accounts—board members, CEO, CFO, for process or tool improvement rather than
for example—and administrator accounts a failing on the part of the SOC to meet a goal.
present the most risk to you if compromised.
Therefore, you should give special attention
to proactively protecting these accounts
first by segregating them in dedicated
computing environments using Privileged
Access Workstations (PAWs) that protect these
important accounts from Internet attacks and
other threat vectors.

Metrics – measuring success

Metrics translate culture into clear measurable


objectives and have a powerful influence
on shaping people’s behavior. It’s critical to
consider both what you measure, as well
as the way that you focus on and enforce
those metrics. At Microsoft, we measure
several indicators of success in the Security
Operations Center (SOC), but we always
recognize that the SOC’s job is to manage

1 2 3. Security operations best practices 4


Modern Security Operations 33

These are the metrics we track, trend, and ● Incidents remediated (manually vs. with
report on: automation)—We measure how many
incidents are remediated manually and how
● Mean time to acknowledge (MTTA)— many are resolved with automation. This
Responsiveness is one of the few elements ensures our staffing levels are appropriate
the SOC has direct control over. We and measures the effectiveness of our
measure the time between an alert being automation technology.
raised and when an analyst acknowledges
that alert and begins the investigation. ● Escalations between each tier—We track
Improving this responsiveness requires that how many incidents are escalated between
analysts don’t waste time investigating false analyst tiers to ensure we accurately capture
positives while another true positive alert the workload for each tier. For example,
sits waiting. We achieve this with ruthless we need to ensure that tier 1 work on an
prioritization. Any alert that requires an escalated incident isn’t fully attributed to
analyst response must have a track record tier 2.
of 90 percent true positive.

● Mean time to remediate (MTTR)—


Much like many SOCs, we track the
time to remediate an incident to ensure
we’re limiting the time attackers have
access to our environment, which drives
effectiveness and efficiencies in our SOC
processes and tools.

1 2 3. Security operations best practices 4


Modern Security Operations 34

Maintain critical hygiene

Methods, defenses, and effects may vary, but As attackers find new ways to build a business
simply put, attackers exploit vulnerabilities. model or come up with a new attack technique,
Which in turn makes your job as security they are often simply exploiting the same old
professionals simple: Eliminate your vulnerabilities, just in new ways. In some cases,
vulnerabilities. they may exploit vulnerabilities you didn’t
previously know you had. So, while attacker
Every team has work to do to update its techniques may evolve, the imperative for good
environment—we refer to this as carrying old-fashioned technical hygiene remains the
“technical debt.” You need to make backups, or same. Keeping your environment up to date in
you need to update file permissions. Or there’s ways you’ve known about for a long time and
patching to do, or you have old protocols to learning what else you have to do based on
retire. These are all well-known best practices. attacker behavior are critical to protecting your
organization against attacks—even the newest
kinds of attacks.

As attackers find new ways to build a business model or


come up with a new attack technique, they often are simply
exploiting the same old vulnerabilities just in new ways.

1 2 3. Security operations best practices 4


Modern Security Operations 35

Critical hygiene = Technical debt to pay off

Cloud can speed this up, but some hard work must be done

“New” Element Increase priority Increase priority Increase priority


• Credential theft • Backups • Patching • Web app security
• File permissions • Retire old • Performance
protocols monitoring

Auditors Targeted Ramsomware Destruction Cryptominers


(& phishing, data theft (Rapid
SPAM, botnet) cyberattacks)

New monetization models simply reshuffle


priorities of the same old hygiene debt:

1. Look at your critical hygiene 3. Revisit your list of best practices


needs regularly. and priorities often to ensure it
applies to current conditions.
2. Prioritize based on what is
happening now. 4. Continually work to eliminate
your “technical debt.”

1 2 3. Security operations best practices 4


Modern Security Operations 36

Proactive hunting

Threat hunting is a powerful way to reduce At Microsoft, our SOC approaches threat
organizational risk. But it’s commonly hunting by applying our analysts to different
portrayed as a complex and mysterious art types of threat hunting tasks:
form for deep experts only, which can be
counterproductive. The term “threat hunting” 1. Proactive adversary research and
simply refers to the process of experienced threat hunting. This is what most of our
analysts proactively and iteratively searching threat hunters spend the majority of their time
through the environment to find attacker doing. The team searches through a variety
operations that have evaded other detections. of sources including alerts, external indicators
of compromise, and other sources. The team
Hunting is a complement to reactive primarily works to build and refine structured
processes, alerts, and detections, and hypotheses of what the attackers may do
enables you to proactively get ahead of based on threat intelligence (TI), unusual
attackers. What sets hunting apart from observations in the environment, and their
reactive activities is the proactive nature of own experience. In practice, this type of threat
it, where hunters spend extended focus time hunting includes:
thinking through issues, identifying trends
and patterns, and getting a bigger-picture ● Proactive search through the data
perspective. A successful hunting program is (queries or manual review).
not purely proactive, however, as it requires
continuously balancing attention between ● Proactive development of hypotheses
reactive efforts and proactive efforts. based on TI and other sources. (See
Operationalize the MITRE ATT&CK
Threat hunters still need to maintain a Knowledge Base.)
connection to the reactive side to keep their
skills sharp, and to keep attuned to trends in
the alert queue.

1 2 3. Security operations best practices 4


Modern Security Operations 37

2. Red and purple teaming. Some of Operationalize the MITRE


our threat hunters, working as blue teams
ATT&CK Knowledge Base
protecting the environment, coordinate with
red teams who simulate attacks and others
The MITRE ATT&CK Knowledge Base is a
who conduct authorized penetration testing
treasure trove of information, but the amount
against our environment. This is a rotating
of information there can be intimidating. The
duty for our threat hunters and typically
good news is technology products can help
involves purple teaming, where both red and
you reduce the effort of deriving value from
blue teams work to do their jobs and learn
MITRE ATT&CK. Many tools today, including
from each other. Each activity is followed up by
security solutions from Microsoft, have already
fully transparent reviews that capture lessons
done a lot of mapping to the knowledge base.
learned which are shared throughout the SOC,
In fact, the Security Stack Mappings for Azure
with product engineering teams, and with
research project recently introduced a library
other security teams in the company.
of mappings linking built-in Azure security
controls to the MITRE ATT&CK techniques
3. Incidents and escalations. Proactive
they mitigate. Keep in mind, however, that
hunters aren’t sequestered somewhere away
mappings aren’t generally comprehensive.
from the watch floor. They are co-located
Your organization should assess where the
with reactive analysts and frequently check in
tools cover you by default and where you still
with each other, share what they are working
have gaps.
on, share interesting findings or observations,
and generally maintain situational awareness
Where those gaps exist, you can customize
of current operations. Threat hunters aren’t
mapping of existing tools and technology to
necessarily assigned to this task full time; they
the areas of the MITRE ATT&CK Knowledge
may simply remain flexible and jump in to help
Base that best apply to your organization
when needed.
to make sure you’re covered. In addition,
you probably don’t need all of what’s in
These are not isolated functions—the
the MITRE ATT&CK Knowledge Base. Look
members of these teams work in the same
at the knowledge base from an adversary
facility and frequently check in with each other.
perspective: not every single adversary in the
world wants to target your organization or
business. Reduce the volume of information

1 2 3. Security operations best practices 4


Modern Security Operations 38

in the knowledge base that you have to require action by IT personnel. Having good
track by looking at adversaries that target relationships and knowledge of IT personnel
businesses like yours and understanding roles, responsibilities, and the skill sets of IT
what techniques they use in their attacks. You team members can help you get to the right
can build your detections based on which person more quickly when there is an incident.
adversaries and techniques are most likely to
target your organization.

Continuous improvement
In this way, the MITRE ATT&CK Knowledge
Base becomes a tool you can use to
Once an attack is remediated, you must
conceptualize what attackers are likely to do
assume that adversaries will try to learn from
if they try to exploit your organization and
what happened and they will try again with
to proactively build detections around those
fresh ideas and tools. Your analysts should
potential attack patterns.
also focus on learning from each incident to
improve their skills, processes, and tooling.
This continuous improvement can occur
Build rapport with IT through many informal and formal processes
ranging from formal case reviews to casual
In many organizations, security operations conversations where analysts tell the stories of
doesn’t control the technology environment. incidents and interesting observations.
It is often up to IT how the environment is
tooled. The response and remediation options As caseload allows, the investigation team can
available to you are often dependent on the also hunt proactively for adversaries, which
technology choices IT has independently can help them stay sharp and grow their skills.
made. It can be helpful to build relationships Finally, purple-teaming exercises should be
and cross-functional awareness with IT. designed with continuous improvement as one
When each group knows what the other is of the goals. As red teams succeed in evading
working on, as well as the challenges and detection by the defenders in the exercises,
limitations they face in fulfilling their part of embrace those moments as important chances
the mission to protect the organization, they for everyone to learn and get better.
can accelerate modernization and enhance
security. In addition, there will be many
occasions when a successful remediation will

1 2 3. Security operations best practices 4


Modern Security Operations 39

Final
recommendations

Modernizing your security operations 1. Embrace Zero Trust – The Zero Trust
is a big undertaking. You’ll need to model is about verifying explicitly, utilizing
involve stakeholders from across the the concept of least privileged access, and
maintaining an “assume breach” mindset.
organization and you shouldn’t think
Start your Zero Trust journey by shifting the
you can do it all at once. But there are
control plane for security from your network
some things you can do right now to perimeters to identity.
reduce your vulnerabilities, increase
visibility, and improve efficiency and 2. Segregate high-privileged accounts –
effectiveness as you defend against Identify the accounts in your organization
advanced attackers: that would be most desirable to attackers
and segregate them using privileged
access workstations (PAWs) and secure your
administrator accounts. These accounts
could do the most amount of damage if
compromised, so start your protection
efforts there.

1 2 3 4. Final recommendations
Modern Security Operations 40

3. Shore up your supply chain – This fits 4. Invest in penetration testing – Look before
into the “shift left” mentality we discussed the bad guys do. Use penetration testing to
in the Best Practices section of this guide. find your fail points before you’re attacked. Use
Slipping malicious code or components into the findings of your penetration testing not as
the software products you receive and trust a report card, but as an input into a continuous
from suppliers is an increasingly common improvement process.
way that attackers attempt to evade your
defenses. Move your awareness further up the 5. Ensure you have comprehensive
attack chain by knowing what your suppliers investigation capabilities – Make sure you
are doing to stay secure, knowing what you have the ability to investigate across your whole
use and where, and continuing to invest in environment. Work to get comprehensive
better asset management. visibility from different perspectives—from
endpoint to identity, from data to IoT, and
across clouds. This will allow you to do the rapid
investigation and early detection that is so
critical to maintaining your security.

6. Integrate your Security Operations


tools – Eliminate silos and gaps in coverage
by embracing an integrated approach. Arm
your analysts with both breadth and depth of
coverage using an integrated, cloud-native
SIEM and XDR.

1 2 3 4. Final recommendations
41

Learn more about how Microsoft’s


integrated security solutions can help you
modernize your security operations and
provide the visibility you need to keep
your organization protected.

SIEM and XDR: Your ally An integrated approach for


against ransomware > increased SOC efficiency >

©2022 Microsoft Corporation. All rights reserved. This document is provided “as-is.” Information and views
expressed in this document, including URL and other Internet website references, may change without notice.
You bear the risk of using it. This document does not provide you with any legal rights to any intellectual
property in any Microsoft product. You may copy and use this document for your internal, reference purposes.

Common questions

Powered by AI

An identity-first approach is recommended in modern security operations, particularly with the Zero Trust model, because identities form the backbone of verifying access requests across multiple platforms and locations. In the context of Zero Trust, where assumed breach is the foundation, continuously verifying identities and their associated devices or applications ensures that only authenticated and authorized users gain access to resources. This approach is crucial given the dissolving traditional network perimeters and the rise in mobile and remote work environments, making identity the central control plane for enforcing policies effectively across the digital estate .

To combat alert fatigue in security operation centers, strategies such as integrating SIEM and XDR to filter high-quality alerts and using automation to reduce manual interventions can be employed. Alert fatigue is reduced by prioritizing true threats through better detection algorithms and context enrichment, ensuring that analysts focus on meaningful alerts. Modernizing security operations also entails employing machine learning and threat intelligence to continuously refine and optimize the alerting processes, thus maintaining a high level of situational awareness without overwhelming analysts .

Organizations should integrate threat intelligence into their security operations by frequently updating and analyzing threat data through automated systems and manual expert analysis. This integration aids in understanding potential adversary behaviors and refining detection mechanisms. By aligning threat intelligence with existing security measures, organizations can proactively adapt to threats, anticipate potential attack vectors, and enhance response strategies, ultimately strengthening their security posture. Continuous improvement practices, informed by threat intelligence, assist in keeping defenses adaptive and current against emerging threats .

Automation and orchestration are pivotal in enhancing security operations efficiency within a Zero Trust approach by streamlining workflows and reducing human intervention in repetitive tasks. Automation enables the swift detection and response to threats, while orchestration integrates disparate security tools into cohesive, automated processes. These capabilities facilitate real-time policy enforcement and threat response, ensuring compliance and operational efficiency. Additionally, automation assists in continuous assessment, allowing security teams to adjust to evolving threats quickly and maintain a robust defensive posture across the network .

The Zero Trust security model redefines the traditional network perimeter by assuming that there is no trusted network, treating every network as hostile. Unlike the traditional security model where defenses are mainly focused on network-based attacks, Zero Trust focuses on identity-based security. It requires verification of each access request and treats them as untrusted, irrespective of whether they originate from inside or outside the network perimeter. This approach leads to the implementation of authentication, device integrity checks, and adaptive access controls as primary security measures, moving away from relying on a secured internal network .

A security operations team can enhance its effectiveness by building relationships with the business side of the organization through several means: understanding business strategies to apply relevant security contexts in real-time, involving business leaders in security practice exercises for better mutual comprehension, and providing updates on major incidents to keep business sections informed and aligned on risk management. These interactions ensure that security priorities resonate with business priorities, build trust, and align security initiatives with organizational goals, improving overall security posture and response capability .

Implementing a successful Zero Trust strategy involves several essential steps: connecting all apps to a single cloud identity solution to ensure centralized control, applying strong, consistent security policies like MFA to prevent account compromise, segmenting networks and restricting access based on identities. Identities are fundamental because they serve as the primary control plane for access decisions, ensuring each access request is authenticated and authorized. Data plays a critical role as it requires ongoing protection, tracking access patterns, and ensuring that security measures adapt to maintain confidentiality, integrity, and availability across multiple environments .

The concept of 'Assume breach' in the Zero Trust model minimizes the impact of security incidents by preparing defenses under the assumption that breaches will occur. This approach focuses on reducing the blast radius for breaches and prevents lateral movement within the network through segmentation strategies, encryption of all sessions, and continuous visibility across digital assets. By considering each network segment, identity, or device as a potential attack vector, and ensuring they are continuously monitored and controlled, organizations can significantly limit an attacker's ability to move undetected within the environment .

Prioritizing human expertise and teamwork over purely automated tools is crucial in modern security operations because humans bring critical thinking, creativity, and contextual understanding that machines lack. Automated systems excel at processing large volumes of data and identifying anomalies, but human analysts are needed to interpret results, make judgments in ambiguous situations, and guide strategic decisions. Teamwork fosters a collaborative environment where expertise is shared, insights are collective, and morale is elevated, especially in high-pressure scenarios. This human factor is essential for adapting to dynamic threat landscapes and ensures that tools empower analysts rather than replace them .

Microsoft's integrated SIEM and XDR security technologies include Microsoft Sentinel and Microsoft 365 Defender, which contribute to modern security operations by providing comprehensive tools for alert detection, threat visibility, proactive hunting, and orchestrated threat response. Sentinel collects data from any source and across any entity, delivering intelligent security analytics and threat intelligence throughout the enterprise. Microsoft 365 Defender extends detection and response capabilities across identities, endpoints, applications, and email, helping analysts and hunters with deep insights for generating high-quality alerts .

You might also like