<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DEMM :: ODEF</title><link>https://odef.wiki/demm/index.html</link><description>Chapter 2 Detection Engineering Maturity Model Working with the Detection Engineering Maturity Model</description><generator>Hugo</generator><language>en-US</language><atom:link href="https://odef.wiki/demm/index.xml" rel="self" type="application/rss+xml"/><item><title>Maturity Model</title><link>https://odef.wiki/demm/intro/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://odef.wiki/demm/intro/index.html</guid><description>Introduction Maturity is a self-evaluation process conducted by the team. ODEF provides guidance and structure and assures that all the relevant areas are covered. The goal of the review process is to give a baseline that helps achieving a common understanding about the organization security posture.&#10;Dimensions Threat Detection Content Assurance Knowledge sharing flowchart RL Assurance(Assurance) &lt;---&gt;Threat[Threat Detection Content] Knowledge[Knowledge sharing] &lt;---&gt; Assurance(Assurance) Knowledge[Knowledge sharing] &lt;---&gt; Threat(Threat Detection Content) Maturity levels</description></item><item><title>Operational Maturity</title><link>https://odef.wiki/demm/operational-maturity/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://odef.wiki/demm/operational-maturity/index.html</guid><description>Maturity Review Process (MRP) The process of evaluating the maturity:&#10;Collect - Collect information about your processes, people and tools. Identify changes to any. The goal is to gain a holistic understanding of the organization's security teams, tools and processes. Based on that information various posture improvements can be identified. Analyze - Based on the data that you have collected and find the corresponding maturity level. Finding where in the maturity level the organization is important for understanding the impact and importance of each identified security improvement initiative and thus prioritize accordingly. Prioritize - Prioritize and decide which is the next low hanging fruit that can be improved. Not all security issues are equally important, prioritization should focus on those initiatives that influence and change the security posture and introduce the most maturity. Improve - Create an initiative or a project for improving the identified gap. Security Improvement Initiative Security improvement initiatives are likely outcomes of the MRP process. The goal of the security improvement initiative is to address identified visibility gaps in the organization's security posture. For example, during the review process or detection engineering we may identify that our application is not providing sufficient logging in order to detect particular behavior or ttp of interest. That is a good candidate for a security improvement initiative. The goal of the initiative would be to deliver the visibility needed and notify back the Detection Engineer so that they can proceed with the detection creation. Depending on the size of the organization and internal processes, this process might be driven by the Detection Engineer or completely separate team.</description></item></channel></rss>