Section 26.248 Automation and Orchestration Flashcards
Objective 4.7 Explain the importance of automation and orchestration related to secure operations
Automation
Execution of tasks without manual intervention
Make individual tasks easier
Orchestration
Coordinated execution of multiple automated tasks for a specific outcome or workflow
Make multiple tasks easier to achieve broader goal
Security Orchestration, Automation, and Response
SOAR
Class of security tools for incident response, threat hunting, and security configurations
■ Purpose: Orchestrate and automate runbooks, deliver data enrichment
■ Example: Integrating SIEM and SOAR for advanced security capabilities
its like a next generation SIEM mainly seen in incident response as you can automate alot
Playbook
Checklist of actions for detecting and responding to a specific incident
■ Role: Guides incident response processes
■ Example: Steps for responding to a phishing campaign
Runbook
Automated version of a playbook with defined interaction points for human analysis
■ Role: Executes automated tasks with human decision points
■ Example: Automated incident response with analyst decision points
Benefits of Automation and Orchestration
■ Efficiency: Time-saving and consistent execution
■ Standardisation: Enforces baselines and standardised configurations
■ Scalability: Scales securely and efficiently
■ Employee Retention: Reduces repetitive tasks
■ Reaction Time: Faster responses to incidents
■ Workforce Multiplier: Maximises human resources