New Project: Security MonitoringObjectives: Meet Compliance Requirements
That'll cost a fortune
We'll need more staff
We NEED a SIEM
We should take data from everywhere
To: CEOHi, Do we really want SIEM? Its too expensive & hard to implement? Im not sure I want to sign this off!From: CFO
Titan Labs Use Case WorkshopA1 Recruitment Company DAY 1 - SESSION 1
What keeps you awake at night?
Making sure our services stay up
IT
What are you worried about?
Titan Labs Use Case WorkshopDAY 1 - SESSION 2
Redundancies & the impact on our staff
HR
Whats your number 1 concern?
Titan Labs Use Case WorkshopDAY 1 - SESSION 3
Keeping our data safe!
CISO
Titan Labs Use Case WorkshopDAY 2 - SUMMARY - TOP 3 RISKSStaff/Insider ThreatControl of DataPhishing Attacks
We can make this work!
The Plan: Focus on key areas!Increase implementation speedReduce CostReduce maintenance overheadImprove ROI
CEO
We need to monitor disgruntled staff
Titan Labs Use Case WorkshopDAY 2 - Insider Threat Focus Session
Internet Browsing (job Sites)Sending a lot of external emailsExporting company dataPut Staff On Watch Lists
Use Case - Insider ThreatIndicators:Web BrowsingEmailingData Downloads
Log SourcesWAF LogsExchange LogsSharepoint Logs
Output from Insider Threat Use CaseHigh-Risk Staff go on to a watchlist report showing:Time spent browsing the Web & Top 10 SitesVolume of Emails to External Domains + Top 10 DomainsLarge Data Downloads
Only take logs from required sourcesReview Use Cases regularlyEnsure the output is useful