25.06.2024
Blog
Cyber Security

Responding more quickly to attacks with SecOps – Part 1

In a company-wide IT security strategy, an intrusion detection system, such as a SIEM, forms a fundamental component (SIEM – Setting up intrusion detection systems (materna.de)). Detecting attacks is the first step. This alone is not enough. Defence measures must be activated immediately. In the following articles in this series, we explain which common SecOps solutions are available and how they can help to successfully fend off attacks.

Dr. Verena Pawolski
Consultant OpenText Consulting Services

Alerts from SIEM systems are usually the trigger for further action. In many cases, the alert must be assessed specifically by security managers and the cause resolved whilst systems are in operation. This is only possible through efficient communication and access to up-to-date data on the components and dependencies of the existing IT systems. In complex IT environments, these are not easy to keep track of. Furthermore, responsibilities and tasks are often spread across different teams. Without this information, it is not possible to respond to attack detection alerts within a reasonable timeframe. Forwarding precisely the information required for resolution to the correct IT team is a core capability of an IT Service Management (ITSM) suite. The same applies to highlighting dependencies between infrastructure, applications and services. By displaying alerts from the intrusion detection system within an ITSM suite and implementing a corresponding process, you ensure that an intrusion detection alert is followed by a rapid response.

Respond more quickly with OpenText SMAX (Service Management Automation X)

One example of an ITSM platform is OpenText SMAX (Service Management Automation X). Specifically, SMAX can be seamlessly integrated into the security process by automatically receiving alerts from attack detection systems (e.g. Elastic or ArcSight) via an interface. The alerts are documented centrally and are therefore manageable and auditable when automated response measures are implemented. Furthermore, this sensitive data is made available exclusively to the security team for assessment, but can be forwarded to the incident response team or any relevant operations team, depending on the situation. Security, as a key component of the IT process map, is supported across all processes in SMAX as follows:

Security Incidents: Identification of all security-related incidents

In the event of a security incident, it is important to coordinate the response and document all relevant information. To this end, SMAX enables the logging of events reported from a wide variety of sources. These may include the organisation’s own staff, but also a SIEM tool. Details such as timestamps, affected systems and the nature of the incident are automatically documented. In addition to management, SMAX also supports the handling of security incidents. Predefined playbooks are available to guide the handling process. When a security incident occurs, IT teams can track changes to the affected systems and, via a Security Emergency Change, directly comply with all change management requirements and document them in a verifiable manner. This includes, amongst other things, updates, patches and configuration changes.

Breach Events: Analysis of the scope of successful attacks

As soon as it becomes clear that an unauthorised intrusion has taken place, the analysis of the extent of the breach and the data affected can be documented and handled separately as a ‘Breach Event’. This allows these issues to be addressed in a targeted manner whilst the security incident is being handled. Dedicated forms and functionalities are available for this purpose, and, of course, all information from the security incident investigation is directly accessible, ensuring that no information is lost.

Overview of affected devices and services

SMAX provides a centralised view for monitoring all affected devices and services. This enables security teams to respond quickly and identify potentially compromised areas. Repeated and automated discovery scans ensure that the information is kept up to date at all times.

Notification to authorities, stakeholders and staff

In the event of a security incident, targeted and rapid communication is crucial. SMAX enables the creation of various templates for notifying authorities, stakeholders and staff. A defined workflow ensures that communication is managed in a controlled manner by authorised staff. This helps to maintain transparency and ensure that the relevant information is communicated in a targeted manner.

Communicating security guidelines

SMAX can communicate security guidelines to staff and agents. This includes best practice, security awareness and codes of conduct. These are maintained centrally and are therefore always available in their latest version. Agents are presented with these at the appropriate stage in their work process. For staff, they are available for viewing in the self-service portal.

Risk Management

SMAX supports risk management by assessing, prioritising and monitoring risks. This helps to identify potential security vulnerabilities, act proactively and implement appropriate measures. To actively manage these measures, SMAX offers not only a risk register but also a linked action register.

Contingency Planning/Business Continuity Management

To be prepared for a major security incident, emergency planning as part of business continuity management is essential. In SMAX, emergency plans can be created and managed to ensure that teams can respond effectively in an emergency. Furthermore, tests and drills are documented. When an emergency arises, SMAX clearly sets out the steps to be taken for those in charge and supports the coordination of emergency measures and their logging.

Attack Detection Management

To continuously update and improve attack detection, the use cases employed must be expanded and the list of assets to be monitored must be kept up to date. SMAX facilitates the integration and management of assets to be monitored for this purpose. In addition, all use cases employed can be documented, reviewed and approved within SMAX. This ensures that the configuration of attack detection can be quickly viewed at any time.

Overall, OpenText SMAX offers a powerful platform for security management. It enables organisations to maintain transparent, auditable documentation of security incidents whilst ensuring the security of their IT systems.

In the second part, we will introduce you to ServiceNow’s SecOps solution.

All posts from the “Cyber Security 2024” blog series:

  1. It will happen to us all eventually – mandatory IT security requirements in 2024
  2. Improving resilience: how to make your IT a rock in the storm
  3. Intelligent attack detection with a Security Information and Event Management (SIEM) system
  4. Responding more quickly to attacks with SecOps – Part 1
  5. Responding more quickly to attacks with SecOps – Part 2
  6. Responding more quickly to attacks with SecOps – Part 3
  7. NIS2 Directive: Implementing legislation still not in sight – what organisations should do now

Dr. Verena Pawolski
Consultant OpenText Consulting Services

Dr. Verena Pawolski arbeitet bei Materna als Consultant im Bereich OpenText Consulting Services. Sie beschäftigt sich mit den verschiedensten Aspekten rund um die Themen IT- und Enterprise Service Management und deren Abbildung im Tool.