YoVDO

Make Alerts Great Again

Offered By: Security BSides San Francisco via YouTube

Tags

Security BSides Courses Microservices Courses Incident Response Courses

Course Description

Overview

Explore effective strategies for creating and maintaining actionable security alerts in this BSidesSF 2017 conference talk. Learn how Yelp's security team developed tools and processes to improve alert management, increase signal-to-noise ratio, and streamline incident response. Discover techniques for standardizing alert definitions, implementing self-service alerts, and establishing visibility into alert frequencies. Gain insights on overcoming common pitfalls, such as noisy or insufficient alerts, and learn how to test and maintain alert effectiveness. Understand the importance of creating run-books, assigning ownership, and measuring success in alert management. Apply these lessons to enhance your security team's efficiency and focus on more critical tasks.

Syllabus

Introduction
Microservices
Security Pipeline
Common Pitfalls
No Standards
Yelps Standards
Lack of Visibility
Actionability
Email Alerts
Email Events
Solutions
SLA
Actionable alerting service
Selfservice alerts
Selfservice alert example
Assigning ownership
Alert standardization
Testing
False Positives
Measuring Success
Recap


Taught by

Security BSides San Francisco

Related Courses

Information Security Management in a Nutshell
SAP Learning
Identifying, Monitoring, and Analyzing Risk and Incident Response and Recovery
(ISC)² via Coursera
Enterprise Security Fundamentals
Microsoft via edX
Planning a Security Incident Response
Microsoft via edX
Introduction to Cybersecurity
Udacity