Blueprint: Build the Best in Cyber Defense

Strategy 7: Select and Collect the Right Data

4 snips
Jun 19, 2023
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Shift to Endpoint and Identity Data

  • The focus of data collection has shifted from primarily network data to endpoint and now identity data sources.
  • Identity logging is becoming crucial as it reflects who accesses what and is heavily exploited by attackers.
ADVICE

Start Small, Build Momentum

  • Start data collection by focusing on specific use cases or threats with a small team and enterprise partners.
  • Build momentum through incremental value and avoid waiting for perfect governance before collecting data.
ADVICE

Plan Data Retention Strategically

  • Define retention policies based on data volume, cost, and access needs; keep alerts long-term but large-volume data shorter.
  • Partner with IT to balance storage costs and accessibility for security data.
Get the Snipd Podcast app to discover more snips from this episode
Get the app