Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Reducing Inactionable Alerts via Policy Layer

BSidesLV via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore strategies for minimizing false positives and inactionable alerts in security systems through a conference talk from BSidesLV 2019. Delve into key concepts including whitelists, policy layers, and generalized ability as presented by John Seymour. Learn how to implement a separate policy layer to enhance alert management and improve overall security effectiveness. Examine the potential trade-offs of this approach and discuss potential improvements. Gain insights into integrating these techniques into existing security infrastructures and understand their impact on alert reduction. Conclude with a Q&A session to address specific implementation concerns and further clarify the presented concepts.

Syllabus

Introduction
Definitions
Examples
Whitelists
Separate Policy Layer
Generalized Ability
Integration
What we lose
Improvements
Questions

Taught by

BSidesLV

Reviews

Start your review of Reducing Inactionable Alerts via Policy Layer

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.