
Industrial Cybersecurity
By :

Holistic is defined by the Cambridge English Dictionary as "dealing with or treating the whole of something or someone and not just a part". In the light of cybersecurity monitoring, this means we should leave no stone unturned, no log unchecked, and no system unmonitored. In this chapter, we will see that by combining a variety of security monitoring tools, each geared toward monitoring a certain aspect of the environment, we create a holistic view of the current state of the cybersecurity posture.
Typically, implementing a holistic cybersecurity monitoring program involves applying a combination of several solutions or appliances, distributed over the network or environment they should monitor. For the purpose of this book, we will use a single solution that encompasses an open source variety of each category of these security monitoring applications—namely, Security Onion. We will be expanding Security Onion's functionality...