Chapter 8. Cloud Security Operations
Topics covered in this chapter include:
-
Adversary types
-
Cyber kill chain
-
Attack lifecycle
-
Security operations
-
Security engineering
We covered operations in the last chapter, but keeping systems up and running is different from ensuring bad things don’t happen. Ultimately, the reason for this book, frankly, is because protecting information assets is a critical function for all organizations. There are adversaries in the world looking to obtain resources. There are many reasons for that. Information can be resold in illicit ways to obtain money. It could be about influence, including political. All you need to do is to pay even a little attention to the news to know that everyone is a potential target. This is primarily businesses today simply because the attackers can get more from going after collections of people rather than individuals.
Security operations is about the people, process, and technology required to identify, detect, and respond to attempts at attacking the organization. This requires a lot of information and coordination, which will vary by organization because some companies are more prone to being attacked than others. What they have, from information to access, is more valuable. This means they are going to be targeted more frequently because there are more groups interested in them.
While it may be quaint to think about the so-called fat kid in his parents’ basement, this is not the profile of a modern attacker ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access