Domain 5: Security Operations and Incident Response
Security operations turns controls into observable evidence. Logs should be collected from sources that matter, time should be consistent enough for correlation, access to logs should be protected, and retention should match operational and legal needs. A SIEM can centralize and correlate evidence, but poor source coverage or parsing produces false confidence.
Event triage prioritizes what needs attention. Consider source reliability, asset value, identity context, recurrence, exposure, threat intelligence, and correlated behavior. A single indicator may be suspicious without proving compromise. Analysts should separate observed facts from hypotheses and identify the next evidence source that can reduce uncertainty efficiently.
Incident response typically moves through preparation, detection or analysis, containment, eradication, recovery, and improvement, although real incidents may overlap phases. Containment should reduce attacker capability while considering business impact and evidence needs. Eradication removes the cause or persistence mechanism. Recovery returns systems to trusted operation and verifies that the original threat no longer has access.
Data protection includes classification, labeling, masking, sanitization, encryption, retention, and secure disposal. Asset protection includes inventory, configuration management, lifecycle state, and end-of-life planning. Unsupported systems deserve attention because security fixes, vendor support, and compatibility options become increasingly limited over time.
The revised outline also brings modern technology context into foundational study. Treat AI systems as assets that still require governance, identity, data protection, logging, change control, and secure use. Do not assume an AI-enabled tool replaces human judgment, authorization, or evidence requirements.