Supplement · Microsoft Azure

Defender for Cloud, Sentinel và Azure Monitor operations

Security posture, threat detection và workload observability phải dẫn đến triage/action có owner—not dashboard không người dùng.

Defender và Sentinel

Defender for Cloud cung cấp posture recommendations và workload protections tùy plan. Microsoft Sentinel là SIEM/SOAR trên Log Analytics: connectors thu data, analytics rules tạo incidents, automation/playbooks hỗ trợ response. Coverage, retention và ingestion cost phải được thiết kế.

Azure Monitor

Metrics phù hợp numeric time series; resource/platform logs và application telemetry cung cấp context. Diagnostic settings route đúng categories tới workspace/storage/Event Hub. DCR kiểm soát collection/transformation cho Azure Monitor Agent.

Alert engineering

Alert phải action-oriented, gắn severity, owner, runbook và suppression/dedup. Monitor symptom theo SLO trước, cause signals sau. Test alert delivery và query freshness; tránh coi absence of logs là healthy.

Incident response

Quy trình gồm detect, triage, contain, eradicate, recover và learn. Bảo toàn evidence, dùng break-glass có audit, rotate credentials phù hợp và theo dõi persistence. Post-incident actions cần owner/deadline và verify control improvement.

Tài liệu: Defender for Cloud · Microsoft Sentinel · Azure Monitor · Incident response
← ReliabilityDR & FinOps →