1
00:00:00,090 --> 00:00:00,990
In this lesson,

2
00:00:00,990 --> 00:00:03,900
we'll be discussing alerting and monitoring activities.

3
00:00:03,900 --> 00:00:06,150
Now alerting and monitoring activities play a big role

4
00:00:06,150 --> 00:00:08,700
in maintaining system health by ensuring optimal performance

5
00:00:08,700 --> 00:00:11,130
and protecting against many potential threats.

6
00:00:11,130 --> 00:00:13,558
Alerting and monitoring utilizes a wide range of activities

7
00:00:13,558 --> 00:00:17,400
including log aggregation, alerting, scanning, reporting,

8
00:00:17,400 --> 00:00:20,850
archiving, alert response and remediation or validation.

9
00:00:20,850 --> 00:00:23,220
Now first we have log aggregation.

10
00:00:23,220 --> 00:00:24,900
Log aggregation is the process

11
00:00:24,900 --> 00:00:26,640
of collecting and consolidating log data

12
00:00:26,640 --> 00:00:29,370
from various sources into a centralized location.

13
00:00:29,370 --> 00:00:31,470
The log aggregation process is going to help

14
00:00:31,470 --> 00:00:33,930
with the analysis and troubleshooting of system issues,

15
00:00:33,930 --> 00:00:36,510
security incidents, and performance problems.

16
00:00:36,510 --> 00:00:38,100
This can be used for multiple purposes,

17
00:00:38,100 --> 00:00:39,090
including troubleshooting,

18
00:00:39,090 --> 00:00:41,970
performance monitoring, security analysis, and compliance.

19
00:00:41,970 --> 00:00:44,280
Now since aggregated logs can provide a holistic view

20
00:00:44,280 --> 00:00:46,890
of what's happening across various systems and applications,

21
00:00:46,890 --> 00:00:48,270
they can make it much easier for us

22
00:00:48,270 --> 00:00:50,100
to identify and troubleshoot issues

23
00:00:50,100 --> 00:00:52,380
by helping us to correlate events across different systems

24
00:00:52,380 --> 00:00:54,540
or network logs to pinpoint the root cause

25
00:00:54,540 --> 00:00:56,070
of a given problem or incident.

26
00:00:56,070 --> 00:00:57,900
Consolidated log data can also provide us

27
00:00:57,900 --> 00:01:00,570
with valuable insights into our system's performance.

28
00:01:00,570 --> 00:01:01,800
By aggregating logs,

29
00:01:01,800 --> 00:01:03,660
you can monitor performance trends over time,

30
00:01:03,660 --> 00:01:04,890
identify your bottlenecks,

31
00:01:04,890 --> 00:01:08,100
and make informed decisions about your resource allocations.

32
00:01:08,100 --> 00:01:09,630
Logs are also useful in terms

33
00:01:09,630 --> 00:01:11,280
of conducting a security analysis

34
00:01:11,280 --> 00:01:14,190
because our logs often combine data about security events

35
00:01:14,190 --> 00:01:16,920
like failed login attempts, changes to user privileges,

36
00:01:16,920 --> 00:01:18,870
and suspicious network connections.

37
00:01:18,870 --> 00:01:21,450
By aggregating and analyzing all this log data,

38
00:01:21,450 --> 00:01:23,970
you can detect security incidents, investigate breaches,

39
00:01:23,970 --> 00:01:26,460
and gather evidence for forensic analysis.

40
00:01:26,460 --> 00:01:28,050
Another use for log aggregation

41
00:01:28,050 --> 00:01:30,720
is to meet your organization's compliance requirements.

42
00:01:30,720 --> 00:01:33,840
Now many laws and regulations like GDPR and HIPAA

43
00:01:33,840 --> 00:01:36,120
require your business to maintain a comprehensive set

44
00:01:36,120 --> 00:01:38,460
of logs for certain regulated activities.

45
00:01:38,460 --> 00:01:40,500
Now log aggregation can help businesses

46
00:01:40,500 --> 00:01:41,430
meet these requirements

47
00:01:41,430 --> 00:01:43,500
by ensuring that all of your necessary log data

48
00:01:43,500 --> 00:01:46,080
is being collected and stored in a centralized location

49
00:01:46,080 --> 00:01:47,850
that can be easily reviewed by auditors

50
00:01:47,850 --> 00:01:49,350
during a compliance audit.

51
00:01:49,350 --> 00:01:51,030
Second, we have alerting.

52
00:01:51,030 --> 00:01:53,040
Now alerting involves setting up notifications

53
00:01:53,040 --> 00:01:54,450
to inform relevant stakeholders

54
00:01:54,450 --> 00:01:56,790
when specific events or conditions occur.

55
00:01:56,790 --> 00:01:59,040
Alerting can be triggered based on predefined thresholds

56
00:01:59,040 --> 00:02:01,740
or anomalies that can be delivered via various channels

57
00:02:01,740 --> 00:02:05,190
like email, text messages, and push notifications.

58
00:02:05,190 --> 00:02:06,720
Alerting is also important in helping

59
00:02:06,720 --> 00:02:09,360
to ensure that issue resolution, incident detection,

60
00:02:09,360 --> 00:02:11,910
and compliance is occurring within your organization.

61
00:02:11,910 --> 00:02:14,700
By using alerts, your team can proactively address issues

62
00:02:14,700 --> 00:02:17,460
before they escalate into more significant problems.

63
00:02:17,460 --> 00:02:19,920
For example, if a server CPU utilization

64
00:02:19,920 --> 00:02:22,440
exceeds a certain threshold, an alert might be triggered

65
00:02:22,440 --> 00:02:23,970
that allows your team to investigate it

66
00:02:23,970 --> 00:02:26,070
and then resolve that issue before it impacts

67
00:02:26,070 --> 00:02:28,530
your system's overall performance or availability.

68
00:02:28,530 --> 00:02:29,700
Alerts can also be set up

69
00:02:29,700 --> 00:02:32,700
to notify security teams of potential security incidents.

70
00:02:32,700 --> 00:02:34,830
For example, multiple failed login attempts

71
00:02:34,830 --> 00:02:37,590
or unusual data access patterns could trigger alerts

72
00:02:37,590 --> 00:02:39,420
which can then enable a faster investigation

73
00:02:39,420 --> 00:02:41,190
and response to occur.

74
00:02:41,190 --> 00:02:42,870
Also, some laws and regulations

75
00:02:42,870 --> 00:02:45,660
do require the immediate notification of specific events

76
00:02:45,660 --> 00:02:48,420
like a data breach to governmental agencies.

77
00:02:48,420 --> 00:02:50,250
If you implement alerting mechanisms,

78
00:02:50,250 --> 00:02:52,230
you can be assured that you're meeting those requirements

79
00:02:52,230 --> 00:02:54,600
in order to maintain your regulatory compliance.

80
00:02:54,600 --> 00:02:56,220
Third, we have scanning.

81
00:02:56,220 --> 00:02:58,680
Now scanning involves regularly examining your systems,

82
00:02:58,680 --> 00:03:01,530
networks, or applications to identify vulnerabilities,

83
00:03:01,530 --> 00:03:04,140
configuration issues, or other potential problems.

84
00:03:04,140 --> 00:03:05,640
The scanning process is crucial

85
00:03:05,640 --> 00:03:06,990
for maintaining system health

86
00:03:06,990 --> 00:03:08,340
to ensure that your systems are operating

87
00:03:08,340 --> 00:03:09,990
within optimal performance standards

88
00:03:09,990 --> 00:03:12,360
and are safeguard against potential threats.

89
00:03:12,360 --> 00:03:13,890
Now scanning typically involves the use

90
00:03:13,890 --> 00:03:15,540
of a specialized tool or service

91
00:03:15,540 --> 00:03:17,640
like Nessus, OpenVAS, or Qualys

92
00:03:17,640 --> 00:03:19,290
to perform various types of scans

93
00:03:19,290 --> 00:03:21,690
including vulnerability scans, configuration scans,

94
00:03:21,690 --> 00:03:23,010
and code scans.

95
00:03:23,010 --> 00:03:25,290
A vulnerability scan checks for known vulnerabilities

96
00:03:25,290 --> 00:03:27,510
in your systems, networks, or applications

97
00:03:27,510 --> 00:03:29,190
by comparing your system's current state

98
00:03:29,190 --> 00:03:31,350
against a database of known vulnerabilities,

99
00:03:31,350 --> 00:03:32,760
that's known as the CVE

100
00:03:32,760 --> 00:03:34,860
or Common Vulnerabilities and Exposures

101
00:03:34,860 --> 00:03:37,350
and this is a database provided by the MITRE Corporation

102
00:03:37,350 --> 00:03:40,740
that you can find at cve.mitre.org.

103
00:03:40,740 --> 00:03:42,690
For example, a security team might use

104
00:03:42,690 --> 00:03:43,680
a vulnerability scanning tool

105
00:03:43,680 --> 00:03:46,470
like Nessus or OpenVAS to perform a vulnerability scan

106
00:03:46,470 --> 00:03:48,060
of their entire network.

107
00:03:48,060 --> 00:03:49,923
These scans will identify any unpatched software,

108
00:03:49,923 --> 00:03:53,250
misconfigured services, or other potential vulnerabilities

109
00:03:53,250 --> 00:03:55,140
that could be exploited by a threat actor

110
00:03:55,140 --> 00:03:56,400
so that your system administrators

111
00:03:56,400 --> 00:03:58,230
can then mitigate these vulnerabilities

112
00:03:58,230 --> 00:04:00,480
by patching those systems, reconfiguring them,

113
00:04:00,480 --> 00:04:02,940
or putting in place some other forms of mitigations,

114
00:04:02,940 --> 00:04:05,010
like installing a web application firewall

115
00:04:05,010 --> 00:04:06,450
if that's appropriate.

116
00:04:06,450 --> 00:04:08,460
Now a configuration scan on the other hand

117
00:04:08,460 --> 00:04:10,440
is going to be used to check for misconfigurations

118
00:04:10,440 --> 00:04:12,990
that could impact your system performance or security

119
00:04:12,990 --> 00:04:14,580
by comparing the system's configuration

120
00:04:14,580 --> 00:04:16,140
against best practice guidelines

121
00:04:16,140 --> 00:04:18,209
or specific compliance standards.

122
00:04:18,209 --> 00:04:19,470
A configuration scan

123
00:04:19,470 --> 00:04:21,300
will focus on detecting misconfigurations

124
00:04:21,300 --> 00:04:22,132
that have the potential

125
00:04:22,132 --> 00:04:24,120
to affect system performance or security.

126
00:04:24,120 --> 00:04:25,890
By conducting a configuration scan,

127
00:04:25,890 --> 00:04:27,750
organizations can proactively identify

128
00:04:27,750 --> 00:04:28,975
and rectify any deviations

129
00:04:28,975 --> 00:04:30,810
from their recommended settings,

130
00:04:30,810 --> 00:04:32,190
while ensuring that their systems

131
00:04:32,190 --> 00:04:33,870
not only operate efficiently,

132
00:04:33,870 --> 00:04:37,140
but they also adhere to security and compliance standards.

133
00:04:37,140 --> 00:04:39,030
This preventative measure will definitely help

134
00:04:39,030 --> 00:04:41,580
to maintain a robust and secure IT environment

135
00:04:41,580 --> 00:04:43,500
and it helps to minimize the risk of vulnerabilities

136
00:04:43,500 --> 00:04:46,680
and performance issues that stem from configuration errors.

137
00:04:46,680 --> 00:04:48,750
For example, if an organization is striving

138
00:04:48,750 --> 00:04:51,240
to maintain a secure and compliant network environment,

139
00:04:51,240 --> 00:04:53,430
they might choose to employ a configuration scanning tool

140
00:04:53,430 --> 00:04:56,107
like CIS-CAT to conduct periodic scans of their systems

141
00:04:56,107 --> 00:04:58,440
and network devices.

142
00:04:58,440 --> 00:04:59,460
These types of scans

143
00:04:59,460 --> 00:05:01,140
will evaluate your system configurations

144
00:05:01,140 --> 00:05:02,460
against recognized benchmarks

145
00:05:02,460 --> 00:05:05,460
like the Center for Internet Securities, CIS Controls,

146
00:05:05,460 --> 00:05:07,710
or other industry specific compliance frameworks

147
00:05:07,710 --> 00:05:11,100
like PCI DSS that's used with credit card processing.

148
00:05:11,100 --> 00:05:13,050
Any discrepancy discovered during the scan

149
00:05:13,050 --> 00:05:15,240
such as an open port, weak access controls,

150
00:05:15,240 --> 00:05:17,460
or non-compliant settings are then going to be flagged

151
00:05:17,460 --> 00:05:19,050
for attention and remediation.

152
00:05:19,050 --> 00:05:20,580
Then your system administrators

153
00:05:20,580 --> 00:05:22,050
can take their proactive steps

154
00:05:22,050 --> 00:05:23,872
to rectify all these misconfigurations

155
00:05:23,872 --> 00:05:25,560
and to ensure the network remains aligned

156
00:05:25,560 --> 00:05:26,970
with the industry best practices

157
00:05:26,970 --> 00:05:28,320
and regulatory requirements

158
00:05:28,320 --> 00:05:30,210
in order to bolster your security posture

159
00:05:30,210 --> 00:05:31,590
and compliance status.

160
00:05:31,590 --> 00:05:34,200
A code scan will check the source code of an application

161
00:05:34,200 --> 00:05:35,340
for potential issues

162
00:05:35,340 --> 00:05:37,860
such as security vulnerabilities or coding errors.

163
00:05:37,860 --> 00:05:40,470
This is often done as part of a software development process

164
00:05:40,470 --> 00:05:42,510
to catch and fix issues early.

165
00:05:42,510 --> 00:05:43,800
Code scans can be completed

166
00:05:43,800 --> 00:05:45,300
using either static code analysis

167
00:05:45,300 --> 00:05:47,850
or dynamic code analysis techniques as well.

168
00:05:47,850 --> 00:05:49,110
For example, if you're working

169
00:05:49,110 --> 00:05:50,430
as part of a software development team

170
00:05:50,430 --> 00:05:52,260
that's creating a new web application,

171
00:05:52,260 --> 00:05:53,760
you might want to perform a code scan

172
00:05:53,760 --> 00:05:56,190
to ensure the application security and functionality

173
00:05:56,190 --> 00:05:58,020
is working as you designed.

174
00:05:58,020 --> 00:06:00,450
Now you and your team can employ static code analysis tools

175
00:06:00,450 --> 00:06:03,570
like Fortify or SonarQube to examine the application

176
00:06:03,570 --> 00:06:05,760
source code thoroughly on your behalf.

177
00:06:05,760 --> 00:06:08,010
If the tool identifies a potential security vulnerability

178
00:06:08,010 --> 00:06:10,740
during its scan, such as an SQL injection point,

179
00:06:10,740 --> 00:06:12,300
cross-site scripting vulnerabilities,

180
00:06:12,300 --> 00:06:13,696
or coding errors like unsanitized

181
00:06:13,696 --> 00:06:16,680
or uninitialized variables or resource leaks,

182
00:06:16,680 --> 00:06:18,480
these issues can quickly be addressed

183
00:06:18,480 --> 00:06:19,860
during your development process

184
00:06:19,860 --> 00:06:22,560
to reduce the likelihood of a future security breach.

185
00:06:22,560 --> 00:06:24,090
This helps to prevent future issues

186
00:06:24,090 --> 00:06:25,440
while also ensuring a more robust

187
00:06:25,440 --> 00:06:27,690
and reliable application is going to be deployed

188
00:06:27,690 --> 00:06:29,190
into your production environment.

189
00:06:29,190 --> 00:06:31,470
Additionally, dynamic code analysis techniques

190
00:06:31,470 --> 00:06:33,000
such as penetration testing

191
00:06:33,000 --> 00:06:34,512
can complement your static analysis

192
00:06:34,512 --> 00:06:36,272
by evaluating the application's behavior

193
00:06:36,272 --> 00:06:39,210
while it's running to uncover any vulnerabilities

194
00:06:39,210 --> 00:06:40,230
that may not be apparent

195
00:06:40,230 --> 00:06:42,030
when you're conducting a purely static review

196
00:06:42,030 --> 00:06:43,230
of the source code.

197
00:06:43,230 --> 00:06:45,000
Fourth, we have reporting.

198
00:06:45,000 --> 00:06:46,710
Now reporting involves generating summaries

199
00:06:46,710 --> 00:06:47,700
or detailed reports

200
00:06:47,700 --> 00:06:50,010
based on the collected and analyzed data.

201
00:06:50,010 --> 00:06:52,650
These reports can provide insight into system performance,

202
00:06:52,650 --> 00:06:55,980
security incidents, compliance status, and other aspects.

203
00:06:55,980 --> 00:06:57,980
For example, a compliance officer might use a tool

204
00:06:57,980 --> 00:07:00,623
like Splunk or Sumo Logic to generate reports

205
00:07:00,623 --> 00:07:02,700
to help demonstrate the organization's compliance

206
00:07:02,700 --> 00:07:04,410
with data protection regulations.

207
00:07:04,410 --> 00:07:07,380
These reports can be used to satisfy regulatory requirements

208
00:07:07,380 --> 00:07:10,110
and to identify areas for continuous improvement as well.

209
00:07:10,110 --> 00:07:11,760
Fifth, we have archiving.

210
00:07:11,760 --> 00:07:13,290
Archiving involves storing data

211
00:07:13,290 --> 00:07:15,870
for long retention periods or for future reference

212
00:07:15,870 --> 00:07:17,850
including all of your organization's log data,

213
00:07:17,850 --> 00:07:19,470
performance data, incident data,

214
00:07:19,470 --> 00:07:20,850
and other types of important data

215
00:07:20,850 --> 00:07:22,710
that you may have collected over time.

216
00:07:22,710 --> 00:07:24,660
For example, a cybersecurity professional

217
00:07:24,660 --> 00:07:26,032
could use a tool like Amazon S3

218
00:07:26,032 --> 00:07:29,760
or Google Cloud storage to archive its older log data.

219
00:07:29,760 --> 00:07:32,220
This archive data can be used for further analysis,

220
00:07:32,220 --> 00:07:34,530
troubleshooting, auditing, or compliance purposes

221
00:07:34,530 --> 00:07:35,640
if it's needed.

222
00:07:35,640 --> 00:07:37,560
Depending on various laws and regulations,

223
00:07:37,560 --> 00:07:39,720
you may or may not be required to maintain an archive

224
00:07:39,720 --> 00:07:42,300
of all of your data for a certain period of time.

225
00:07:42,300 --> 00:07:44,160
HIPAA or the Health Insurance Portability

226
00:07:44,160 --> 00:07:46,020
and Accountability Act is going to require you

227
00:07:46,020 --> 00:07:47,700
to maintain all of your data for six years

228
00:07:47,700 --> 00:07:48,900
to prove compliance.

229
00:07:48,900 --> 00:07:51,240
So if you're working in a healthcare related field,

230
00:07:51,240 --> 00:07:52,350
you may want to move your data

231
00:07:52,350 --> 00:07:53,790
into either hot or cold storage

232
00:07:53,790 --> 00:07:55,170
inside of a cloud environment,

233
00:07:55,170 --> 00:07:56,070
so that way you'll be able to meet

234
00:07:56,070 --> 00:07:57,360
this regulatory requirement

235
00:07:57,360 --> 00:07:58,740
or you'll be responsible for maintaining

236
00:07:58,740 --> 00:08:01,560
all of that in your on-premise data center as well.

237
00:08:01,560 --> 00:08:05,250
Sixth, we have alert response and remediation or validation.

238
00:08:05,250 --> 00:08:06,990
Now once an alert or scan identifies

239
00:08:06,990 --> 00:08:08,940
a potential vulnerability or incident,

240
00:08:08,940 --> 00:08:10,920
we have to begin the process of managing

241
00:08:10,920 --> 00:08:12,720
and resolving those identified issues

242
00:08:12,720 --> 00:08:15,630
as part of our overall alerting and monitoring activities.

243
00:08:15,630 --> 00:08:17,280
This involves taking appropriate actions

244
00:08:17,280 --> 00:08:18,450
in response to alerts,

245
00:08:18,450 --> 00:08:19,740
ensuring that the identified issues

246
00:08:19,740 --> 00:08:21,570
have been effectively addressed.

247
00:08:21,570 --> 00:08:23,670
Now the first step in the response and remediation

248
00:08:23,670 --> 00:08:26,520
or validation process involves taking appropriate actions

249
00:08:26,520 --> 00:08:28,440
in response to a received alert.

250
00:08:28,440 --> 00:08:30,870
This response can include investigating the issue,

251
00:08:30,870 --> 00:08:32,580
escalating it to the appropriate team,

252
00:08:32,580 --> 00:08:35,280
or initiating a predefined response procedure.

253
00:08:35,280 --> 00:08:37,770
For example, if a network engineer receives an alert

254
00:08:37,770 --> 00:08:38,789
about a network outage

255
00:08:38,789 --> 00:08:40,559
and they respond by investigating the issue

256
00:08:40,559 --> 00:08:42,330
and identifying the cause of the outage,

257
00:08:42,330 --> 00:08:44,640
they have completed this step of the process.

258
00:08:44,640 --> 00:08:47,910
Then we need to begin the remediation or validation process

259
00:08:47,910 --> 00:08:49,710
which helps to determine the specific response

260
00:08:49,710 --> 00:08:51,240
based on the nature of the alert

261
00:08:51,240 --> 00:08:53,880
and the organization's incident response procedures.

262
00:08:53,880 --> 00:08:55,440
When we talk about remediation,

263
00:08:55,440 --> 00:08:56,490
we're really talking about the steps

264
00:08:56,490 --> 00:08:59,190
used to resolve the identified issues or vulnerabilities,

265
00:08:59,190 --> 00:09:00,090
which could include things

266
00:09:00,090 --> 00:09:02,940
like patching outdated software, reconfiguring services,

267
00:09:02,940 --> 00:09:05,430
or modifying an application's source code.

268
00:09:05,430 --> 00:09:07,770
Now validation on the other hand involves verifying

269
00:09:07,770 --> 00:09:10,620
that the remediation you implemented was actually successful

270
00:09:10,620 --> 00:09:11,670
and has effectively addressed

271
00:09:11,670 --> 00:09:13,800
the given vulnerability or issue.

272
00:09:13,800 --> 00:09:16,890
So for example, if an alert notified a security analyst

273
00:09:16,890 --> 00:09:19,140
that a missing software patch was not installed

274
00:09:19,140 --> 00:09:20,700
and this represents a known vulnerability

275
00:09:20,700 --> 00:09:24,060
on a Windows domain controller, this is considered an alert.

276
00:09:24,060 --> 00:09:26,760
Now the security analyst might respond to this alert

277
00:09:26,760 --> 00:09:27,990
by installing a security update

278
00:09:27,990 --> 00:09:29,670
to patch this known vulnerability.

279
00:09:29,670 --> 00:09:32,460
This is the remediation portion of this process.

280
00:09:32,460 --> 00:09:34,020
Now the security analyst

281
00:09:34,020 --> 00:09:35,730
also needs to run a vulnerability scan

282
00:09:35,730 --> 00:09:38,130
on that domain controller again to validate

283
00:09:38,130 --> 00:09:40,110
that the patch was successfully installed

284
00:09:40,110 --> 00:09:42,360
and that the threat that vulnerability represents

285
00:09:42,360 --> 00:09:44,610
has been fully eliminated from this server.

286
00:09:44,610 --> 00:09:47,100
Now when your security analyst respond to a given alert,

287
00:09:47,100 --> 00:09:49,380
you may also find that they're going to use two other actions

288
00:09:49,380 --> 00:09:51,750
known as quarantining or alert tuning.

289
00:09:51,750 --> 00:09:53,130
Now a common remediation step

290
00:09:53,130 --> 00:09:54,750
might involve quarantining a system

291
00:09:54,750 --> 00:09:57,270
or file that's suspected to be malicious.

292
00:09:57,270 --> 00:09:58,960
Quarantining involves isolating a system,

293
00:09:58,960 --> 00:10:02,370
network or application to prevent the spread of a threat

294
00:10:02,370 --> 00:10:03,931
and limit its potential impact.

295
00:10:03,931 --> 00:10:06,190
For example, if a workstation is suspected

296
00:10:06,190 --> 00:10:07,920
to be infected with malware,

297
00:10:07,920 --> 00:10:10,170
the security team might quarantine this workstation

298
00:10:10,170 --> 00:10:12,660
by logically isolating it from the rest of the network

299
00:10:12,660 --> 00:10:14,910
while the security team investigates the issue further

300
00:10:14,910 --> 00:10:15,990
and then undertakes the rest

301
00:10:15,990 --> 00:10:17,910
of the organization's incident response procedures

302
00:10:17,910 --> 00:10:20,250
on this suspected malicious workstation.

303
00:10:20,250 --> 00:10:22,230
This prevents the malware from spreading to other systems

304
00:10:22,230 --> 00:10:24,210
while the team is working to remove that infection

305
00:10:24,210 --> 00:10:25,920
which is why we quarantine it.

306
00:10:25,920 --> 00:10:27,540
Now alert tuning on the other hand,

307
00:10:27,540 --> 00:10:28,980
is a form of remediation

308
00:10:28,980 --> 00:10:30,870
where we're going to adjust the alert parameters

309
00:10:30,870 --> 00:10:32,760
to reduce errors, false positives,

310
00:10:32,760 --> 00:10:34,260
and to improve the overall relevance

311
00:10:34,260 --> 00:10:36,870
of the alerts being generated by a given system.

312
00:10:36,870 --> 00:10:39,210
Alert tuning can also involve changing the thresholds

313
00:10:39,210 --> 00:10:40,320
that trigger an alert,

314
00:10:40,320 --> 00:10:42,240
adjusting the conditions that define an alert,

315
00:10:42,240 --> 00:10:44,640
or modifying the alert delivery methods.

316
00:10:44,640 --> 00:10:46,470
For example, a system administrator

317
00:10:46,470 --> 00:10:47,880
might be receiving too many alerts

318
00:10:47,880 --> 00:10:50,100
about a minor CPU utilization spike

319
00:10:50,100 --> 00:10:51,030
that really doesn't impact

320
00:10:51,030 --> 00:10:52,890
your system's overall performance.

321
00:10:52,890 --> 00:10:54,900
So to reduce the excessive noise being created

322
00:10:54,900 --> 00:10:56,010
by all these alerts,

323
00:10:56,010 --> 00:10:58,290
the system administrator could retune that alert

324
00:10:58,290 --> 00:11:00,780
to only trigger when the system's CPU utilization

325
00:11:00,780 --> 00:11:03,240
exceeds a higher threshold or remains high

326
00:11:03,240 --> 00:11:05,610
for at least 30 or 60 seconds or longer

327
00:11:05,610 --> 00:11:07,170
to reduce the amount of alerts being generated

328
00:11:07,170 --> 00:11:08,490
by this system.

329
00:11:08,490 --> 00:11:11,190
So remember, log aggregation is used to collect

330
00:11:11,190 --> 00:11:13,140
and consolidate log data from various sources

331
00:11:13,140 --> 00:11:14,790
into a centralized location.

332
00:11:14,790 --> 00:11:17,070
Alerting is going to be used to set up notifications

333
00:11:17,070 --> 00:11:18,390
to inform relevant stakeholders

334
00:11:18,390 --> 00:11:20,940
when specific events or conditions are occurring.

335
00:11:20,940 --> 00:11:23,400
Scanning involves conducting regular examinations

336
00:11:23,400 --> 00:11:24,660
of your systems, networks,

337
00:11:24,660 --> 00:11:26,790
or applications to identify vulnerabilities,

338
00:11:26,790 --> 00:11:29,400
configuration issues, or other potential problems.

339
00:11:29,400 --> 00:11:31,440
Reporting is going to be used to generate summaries

340
00:11:31,440 --> 00:11:32,340
or detailed reports

341
00:11:32,340 --> 00:11:34,710
based on the collected and analyzed data.

342
00:11:34,710 --> 00:11:36,240
Archiving is used to store data

343
00:11:36,240 --> 00:11:37,620
for long-term retention periods

344
00:11:37,620 --> 00:11:39,240
and for future reference.

345
00:11:39,240 --> 00:11:41,790
Alert response involves taking the appropriate actions

346
00:11:41,790 --> 00:11:43,620
in response to received alerts.

347
00:11:43,620 --> 00:11:45,540
Remediation and validation is going to be used

348
00:11:45,540 --> 00:11:47,970
to take the steps necessary to resolve identified issues

349
00:11:47,970 --> 00:11:50,354
or vulnerabilities, and verify that your remediation efforts

350
00:11:50,354 --> 00:11:52,207
were actually successful.

351
00:11:52,207 --> 00:11:54,720
Now it's important to always conduct proper alerting

352
00:11:54,720 --> 00:11:55,740
and monitoring activities

353
00:11:55,740 --> 00:11:57,900
in order to maintain your system's overall health

354
00:11:57,900 --> 00:11:59,310
and ensure it's optimal performance

355
00:11:59,310 --> 00:12:01,170
while still safeguarding your organization

356
00:12:01,170 --> 00:12:02,460
against potential threats.

357
00:12:02,460 --> 00:12:03,603
So keep this in mind.

