Overview
This article discusses the detection side of a large-scale cybersecurity attack-and-defense exercise.
Key Areas
- Monitoring scope and preparation
- Alert review and evidence collection
- Exercise records and follow-up
Planning Considerations
The suitable architecture depends on the existing environment, business use, data requirements, implementation conditions and operational responsibilities. These factors should be confirmed before product selection or migration.
