Incident Prevention A process to set instruments/tools/services to avoid possible threats or impacts during an attack Incident Response Plan What to do when once we are impacted
Compliance Updates Maintain your instances up to date (OS, Libraries) Network Does this need to be public accessible? What ports should I let in? What traffic should go out? Encryption At rest In transit Secret Management Keep your secret data secret
Preparation Log everything you can (this will also help for auditing) ● Application Logs ● Server Logs ● Network Logs (Traces) ● Access Logs and more Design the infrastructure to prevent single point of failure
Detection Monitoring and Alerting ● Behaviour rules like traffic spikes, CPU and Memory consumption ● Traffic from countries not served ● Sign in failures Page System :(