It includes tools that are designed to continuously poll the information system for changes that introduce an exploitable vulnerability:
- Incident and event management: Tools that are constantly inspecting enterprise systems and applications for indicators of compromise:
- Intrusion detection systems
- Security information and event management
- Log management
- Malware detection: Tools that allow for the detection of trojans, spyware, viruses, and other malicious code throughout the enterprise information system. The best approach is to implement multiple layers of malware detection throughout your network:
- Server and workstation operating system: Traditional antivirus installed on the operating system ...