Security monitoring tools: NIST Framework, Microsoft Defender for Cloud, and SIEM Azure Sentinel

Tools that help build your security monitoring center

November 10, 2024
Table of contents
Who you gonna call?
Contact opnemen

No items found.

The NIST Framework

Where there are procedures, there are frameworks, right? They provide a solid foundation and best practices. The same goes for security management. The NIST Cybersecurity Framework is one of the most widely used and recognizable, which is why we’d like to give you a quick rundown. In the link above, you’ll find an asset management template and an online learning module, among other things. Make the most of them!  

  1. Identify

Here, we look at governance, risk management, the business environment, and your asset management. After all, how else would you know what to focus on during the ‘protect’ phase?  

  1. Protect

Phase two is all about data security, awareness & training, maintenance, and protective technology. How do we work together to protect our data and minimize risks as effectively as possible? One way to take precautions is by setting up MFA. Read more via The importance of MFA – why you really need to have it set up in 2022.

  1. Detect

This covers anomalies & events, continuous security monitoring, and detection processes. In plain English, it means we need to know about vulnerabilities and risks in time. For instance, our monitoring via Azure Secure Score helps us keep an eye on what matters. Read more via Why monitoring your secure score should be part of your security management.

  1. Respond

They say the devil is in the details, but sometimes those details aren't available yet. Phase 4 is all about response planning, analysis, mitigation, and improvements. It ensures that if a situation arises, we know exactly how to act based on our policies, procedures, framework, and past experience.  

  1. Recover

Recovery planning, improvements, and communication. If a data breach occurs internally or externally, we know how to minimize the damage and follow the procedures from the first four steps. We call that continuous learning. Example via How do you handle a cyberattack? Here’s a breakdown of the process and what we’ve learned.

Microsoft Defender 365 & Microsoft Defender for Cloud

Want to know more about how Microsoft uses the NIST Framework and what you should look out for to stay as secure as possible? Check out these papers and follow the best practices yourself. A sneak peek: the standard dashboards in both tools show you exactly where you still have work to do and what your RAG (red/amber/green) reporting looks like. More via National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) - Microsoft Compliance | Microsoft Learn.

Source: Microsoft

Want to know how to make your Azure DevOps environment as secure as possible, beyond just the basics? > NIST Cybersecurity Framework (CSF) - Azure Compliance | Microsoft Learn or read:  

Source: Microsoft

OWASP Top 10 – secure software development

We also call it security by design. For secure software development, we follow the standards of OWASP Top 10:2021. Getting into the weeds on that is a bit much for this blog, but we’d love to cover it in a future post, perhaps alongside a GitHub migration.  

Here are a few Golden Path principles you should always keep in mind while developing:

  • Doing the Things Fast - Principle of Flow
  • Doing the Things Right - Principle of Feedback
  • Doing the Right Things - Principle of Continual Learning and Experimentation
Read more at TeamValue - The Golden Path

We know what you’re thinking... The framework is in place, Microsoft Defender is running, but what’s next? Imagine having all the data and insights from these systems at a single glance. It saves time, keeps things organized, and it’s all in real-time. We use a SIEM—short for Security Information and Event Management—to set this up and handle the associated risk management. It’s a solution that helps organizations detect, analyze, and respond to threats before they can disrupt business operations. Read more about it at What is SIEM? | Microsoft Security. Azure Sentinel is a great option for setting up your SIEM.  

SIEM – the benefits of Azure Sentinel  

Azure Sentinel What is Microsoft Sentinel? | Microsoft Learn is Microsoft’s all-in-one solution for securing cloud services. It combines SIEM with SOAR, meaning Azure Sentinel doesn’t just spot and analyze threats—it can also take action when a threat arises. In our view, it’s the perfect blend of SIEM and XDR (Extended Detection and Response).

Hendrik’s take on the benefits? Get a bird’s-eye view of your entire organization with Microsoft’s cloud-native SIEM tool. Aggregate security data from virtually any source and use AI to filter out the noise from legitimate events. Correlate alerts across complex attack chains and speed up your response with built-in orchestration and automation. Check out the screenshots below to see what’s happening behind the scenes.  

Other handy reads:  

Source: Microsoft
Source: Microsoft
Wondering where to get started with Azure Sentinel? Check it out here.

Monitoring dashboard – ISO reporting

A complete dashboard that handles your security monitoring, checks code quality at the source, offers advice during both development and management phases, provides recommendations based on best practices, and keeps your ‘SecDevOps or SoCaaS status’ in check? You want that, right? First and foremost for security. Secondly, to achieve or maintain your ISO certification.  

In the fourth and final blog of this series, we’ll explain how to develop your security policy, which templates you can use, and how to keep monitoring your secure score.

Hendrik’s tip: have you got the basics of MFA sorted? Are you monitoring your secure score in Azure? The next step is to apply the security framework across all your Microsoft, Azure, and reporting environments. If you’d like to brainstorm about that, the (digital) coffee is always on for topics like these.
Dit wil je weten

Frequently asked questions

No items found.
Mehmet Gök
Hans Borkent
Ton Hilhorst
Pamir Ahrary
Albert van Nijhuis
Joeghanoe Bhatti
Anne Versteegh
Joost-Jan Huls
Sammie Woof Woof
Franka Juta
Peter Smolders
Anton Cnossen
Jogchum Hofma
Courtney Leepel
Martijn Hemelt
Christian Sinke
Cheryll Vahl
Michelle Voortman
Lars Versteeg
Marco van der Steijle
Kahn Aksu
Thom Bosman
Ilse Kooning
Jochem Spronk
Hidde Breukelaar
Evelyn Ferenczy
Jaap Meems
Xander Kuiper
Anouchka Cnossen-Oudhof
Simon de Vries
Corien Gruppen

Fancy a chat?

Do you have a data, cloud or IT transformation challenge? We are happy to think along with you. Feel free to contact us.