Detecting and handling incidents at scale depends on tools that collect data, spot suspicious activity and help responders act consistently. The information security manager does not need to configure them, but must understand what each provides, how they fit together, what resources they need and how to judge whether they are working. Tools are part of a capability that also needs skilled people and sound processes.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.