Security Operations¶
Security operations is the day-to-day work of protecting the running tenant: detecting threats, responding to incidents, finding and fixing vulnerabilities, and looking after keys and secrets. The Security Model decides who can change the tenant. This section covers what happens when something goes wrong, or is about to.
- Defender Plans: which Defender for Cloud protections are switched on, and where.
- Threat Detection: alert rules on the central workspace, and the path to a SIEM.
- Incident Response: runbooks for the incidents most likely to hit this platform.
- Vulnerability Management: finding weaknesses in infrastructure, code and dependencies, and how quickly to fix them.
- Key and Secret Management: the zero-secrets principle, and the Key Vault standard for workloads.
Related:
- Governance: the logs these pages depend on.
- Exceptions Register