Security monitoring tools: NIST Framework, Microsoft Defender for Cloud, and Azure Sentinel SIEM

Tools to help you build your security monitoring centre

November 10, 2024
No items found.
Table of contents
Who you gonna call?
Get in touch

Azure cost compass

T/m 30 september korting
op onze IT-scans

The NIST Framework

Where procedures are followed, frameworks are used, right? They provide guidance and best practices. This is also true for security management. The NIST Cybersecurity Framework is one of the most widely used and recognizable, which is why we would like to briefly highlight it here. In the link above, you will also find a file for completing your asset management and an online learning module. Make the most of it!  

Source: NIST.gov
  1. Identify

Here we look at governance, risk management, the business environment, and your asset management. After all, how else would you know what to focus on during the ‘protect’ phase?  

  1. Protect

Phase two is about data security, awareness & training, maintenance, and protective technology. How do we work together to protect our data and mitigate risks as effectively as possible? You can take precautionary measures by, for example, setting up MFA. More via The importance of MFA – why you really need to have it set up in 2022.

  1. Detect

This concerns anomalies & events, continuous security monitoring, and detection processes. This simply means that we know in time which vulnerabilities and risks exist. Through our monitoring via Azure Secure Score, among other things, we know what to look out for. More via Why monitoring your secure score should be part of your security management.

  1. Respond

They say the devil is in the details. But sometimes those details aren't available yet. In phase 4, it’s all in the response planning, analysis, mitigation, and improvements. This ensures that if a situation arises, we know how to act based on policy, procedures, the framework, and experience.  

  1. Recover

Recovery planning, improvements, and communications. If a data breach occurs internally or externally, we know how to minimize the damage and follow the procedures from the first four steps. We call this continuous learning. Example via How do you handle a cyberattack? The process and our lessons learned.

Microsoft Defender 365 & Microsoft Defender for Cloud

Want to know more about how Microsoft uses the NIST Framework and what you can look out for to be as secure as possible? Check out the following papers and follow the best practices yourself. A sneak peek: the standard dashboards in both tools show you immediately where you still have actions to take and what your RAG (red/amber/green) reporting status is. More via National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) - Microsoft Compliance | Microsoft Learn.

Source: Microsoft

Want to know if you can make your Azure DevOps environment as secure as possible, beyond just the basics? > NIST Cybersecurity Framework (CSF) - Azure Compliance | Microsoft Learn or read:  

Source: Microsoft

OWASP Top 10 – secure software development

We also call this security by design. For secure software development, we follow the standards of OWASP Top 10:2021. It would go too deep to dive into that completely for this blog, but in the future, we would like to write a blog about it in combination with, for example, a GitHub migration.  

A number of principles that you can always take into account during development are those of the Golden Path:

  • Doing the Things Fast - Principle of Flow
  • Doing the Things Right - Principle of Feedback
  • Doing the Right Things - Principle of Continual Learning and Experimentation
More via TeamValue - The Golden Path

And we hear you thinking... The framework has been applied, the Microsoft Defenders are running, and then what? How great would it be if you could see the data and insights from all these systems at a glance? It saves time, provides a clear overview, and is real-time to boot. We set this up, along with the associated risk management, using a SIEM. That stands for Security Information and Event Management. It is a solution that helps organizations detect, analyze, and respond to threats before they harm business operations. Read more about it via What is SIEM? | Microsoft Security. One option for setting up your SIEM effectively is Azure Sentinel.  

SIEM – the benefits of Azure Sentinel  

Azure Sentinel What is Microsoft Sentinel? | Microsoft Learn is an all-in-one Microsoft solution for securing cloud services. It combines SIEM with SOAR, allowing Azure Sentinel not only to signal and analyze threats but also to respond to them in the event of a threat. In our view, it is the ideal combination of SIEM and XDR (Extended Detection and Response).

The benefits according to Hendrik? Get an overview of the entire organization with Microsoft's cloud-native SIEM tool. Aggregate security data from virtually any source and use AI to distinguish noise from legitimate events. Correlate alerts in complex attack chains and accelerate threat response with built-in orchestration and automation. See below for a few screenshots of what you can expect behind the scenes.  

Other useful reading tips:  

Source: Microsoft
Source: Microsoft
Where could you get started with Azure Sentinel? Check it out here.

Monitoring dashboard – ISO reporting

A comprehensive dashboard that handles your security monitoring, checks code quality at the source, provides advice during both the development and management phases, offers recommendations based on best practices, and outlines your ‘SecDevOps or SoCaaS status’? That’s what you want, right? Primarily for security. Secondarily for achieving or maintaining ISO certification.  

In the fourth and final blog of this series, we explain how to establish your security policy, which templates you can use, and how to subsequently monitor your secure score.

Hendrik’s tip: have you got the basics of MFA in order? Are you monitoring your secure score in Azure? The next step is to apply the security framework across all your Microsoft, Azure, and reporting environments. If you’d like to brainstorm about that, the (digital) coffee is always on for these kinds of topics.

Scanpakket: Azure cost compass

Vol = vol
1 juli t/m 30 september
Handig informatie

Frequently asked questions (FAQ)

No items found.

Fancy a chat?

Do you have a question, or would you like to know what we can do for your organization? Feel free to get in touch with us. We’re happy to help!