Infrastructure Security · IS-Q23B

Bonus Question: Are network monitoring and alerting systems continuously tuned to detect anomalies or unauthorized changes?

Why This Matters

Monitoring ensures infrastructure health and rapid detection of deviations. Continuous tuning reduces alert fatigue and improves detection fidelity.

Maturity

0 — Unaware
No proactive network monitoring.
1 — Ad Hoc
Basic SNMP or ping monitoring only.
2 — Defined
Network performance and availability dashboards established.
3 — Managed
Alerts linked to incident response workflows.
4 — Integrated
Behavioral and anomaly-based alerting implemented.
5 — Optimized
AI-driven analytics predict and prevent disruptions.

How to Level Up

| From → To | Actions | |—|—| | 0 → 1 |Deploy monitoring tools and define key metrics.|
| 1 → 2 |Set performance baselines and thresholds.|
| 2 → 3 |Integrate alerts with IR ticketing system.|
| 3 → 4 |Enable anomaly-based analytics.|
| 4 → 5 |Apply ML for predictive alerting.|

Enablers

Evidence

KPIs

Low-Cost / Open-Source Options (MSME)

| Purpose | Tool | Notes | |—|—|—| | Monitoring | Zabbix / Prometheus | Device health |
| Flow analytics | ntopng / ElastiFlow | Traffic behavior |
| AI Tuning | OpenSearch ML | Predictive anomalies |

Common Pitfalls

Compliance Mapping

| Standard | Clauses / Notes | |—|—| | ISO/IEC 27001 | A.8.16 / A.8.28 | | NIST CSF 2.0 | DE.CM / RS.AN | | CERT-In 2022 | Section 14 | | NIRMATA Mapping | IS-Q23B reinforces Infrastructure Security with adaptive monitoring maturity. |