Reducing Inactionable Alerts via Policy Layer
Offered By: BSidesLV via YouTube
Course Description
Overview
Explore strategies for minimizing false positives and inactionable alerts in security systems through a conference talk from BSidesLV 2019. Delve into key concepts including whitelists, policy layers, and generalized ability as presented by John Seymour. Learn how to implement a separate policy layer to enhance alert management and improve overall security effectiveness. Examine the potential trade-offs of this approach and discuss potential improvements. Gain insights into integrating these techniques into existing security infrastructures and understand their impact on alert reduction. Conclude with a Q&A session to address specific implementation concerns and further clarify the presented concepts.
Syllabus
Introduction
Definitions
Examples
Whitelists
Separate Policy Layer
Generalized Ability
Integration
What we lose
Improvements
Questions
Taught by
BSidesLV
Related Courses
Computer SecurityStanford University via Coursera Cryptography II
Stanford University via Coursera Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera Building an Information Risk Management Toolkit
University of Washington via Coursera Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network