SOC Update (2-9 Dec 2019)
Progress / Completed Projects & Tasks
- Akamai Playbook for High Severity Network issues
- Fortigate Firewall / UTM initial assessment of capabilities and security posture
- Integrated GuardDuty Medium severity alerts to secops-alerts-stg for review
- Completed internal incident report and post-mortem document on
Plan / Work in progress
- SOC-19 CloudConformty alert tune up.
- Onboard tvlk-dev and tvlk-data AWS accounts to SAML
- Create SNS Topic for Guard Duty Alerts
- SIEMmonster POC Testing.
- Continue integrating log sources and features.
- Planning Akamai DSA migration.
Roadblocks / Problems
- SIEMonster PoC
- No connectivity between AWS and corporate internal resources. Working on getting connectivity established.
Notable Incidents
SOC-56 S3 Bucket Public Access in TVLK Dev
AWS S3 service open permission
RCA: New Service deployment testing config.
Status: All have been resolved
Impact: Internal: None External: None
Details at:
https://29022131.atlassian.net/browse/SOC-56