Defender for Cloud, Sentinel và Azure Monitor operations
Security posture, threat detection và workload observability phải dẫn đến triage/action có owner—not dashboard không người dùng.
Defender và Sentinel
Defender for Cloud cung cấp posture recommendations và workload protections tùy plan. Microsoft Sentinel là SIEM/SOAR trên Log Analytics: connectors thu data, analytics rules tạo incidents, automation/playbooks hỗ trợ response. Coverage, retention và ingestion cost phải được thiết kế.
Azure Monitor
Metrics phù hợp numeric time series; resource/platform logs và application telemetry cung cấp context. Diagnostic settings route đúng categories tới workspace/storage/Event Hub. DCR kiểm soát collection/transformation cho Azure Monitor Agent.
Alert engineering
Alert phải action-oriented, gắn severity, owner, runbook và suppression/dedup. Monitor symptom theo SLO trước, cause signals sau. Test alert delivery và query freshness; tránh coi absence of logs là healthy.
Incident response
Quy trình gồm detect, triage, contain, eradicate, recover và learn. Bảo toàn evidence, dùng break-glass có audit, rotate credentials phù hợp và theo dõi persistence. Post-incident actions cần owner/deadline và verify control improvement.