Security operations encompasses the day-to-day actions, policies, and procedures an organization uses to mitigate risk and uphold the CIA Triad of confidentiality, integrity, and availability. This coverage extends to the structure of a formal security program and the collaborative SecOps methodology.
Security Operations
Everything that we really do within a security program needs to render down into action — that is, we need to take steps to mitigate risk for the organisation that we work for. That is security operations. We're going to define what security operations looks like, then we're going to get into a security program, and finish things off by talking about SecOps and what SecOps is.
One thing I always like to do is break down these words into separate components. So for instance, we have security, which means free from danger or threat. Then we also have operations, which is an active process or function. So really, security operations, when we break it down this way, really means that day-to-day stuff that we're doing, the procedures that we're following, and what we're doing to actually keep the company safe and secure — that safety net that we're laying out for the company. The key really to this is those actions that we're taking to create security.
We of course have the CIA triad — confidentiality, integrity and availability — as our model for security, what we're trying to achieve when it comes to security. So I like to think of this as anything that we're doing to propel our security efforts forward. That is the operational side of this.
One way we implement security operations is by rolling out a security program. A security program is going to be all those policies and procedures, the technologies that we implement; we're going to have people that are going to be assigned towards security; and we're also going to have a budget that's going to be able to facilitate all of this action. That's what a security program is: it's all of this together that allows us to carry out security operations.
Now there is this term SecOps, which is just security operations put together, so really it's just the same thing — or is it? I actually like to think of SecOps as going one step beyond that. SecOps comes from kind of a spin-off of the DevOps idea. It's a methodology, it's a way of thinking, and it's a way of thinking of collaboration, of getting multiple people involved into coming up with solutions.
What I mean by that is maybe we have a security department that's in charge of carrying out security. They make policies and procedures and they roll it out to keep the company secure. But without everyone else — and we're going to call it everyone else operations, everyone else who's carrying out their day-to-day functions of the business in this case right here — so we have everybody else, and what happens is everything that security is implementing affects everyone else. This could cause some problems, because we're making changes that could cause some conflict for the operations side of things, make it a little more difficult for them to do their job.
So the idea behind SecOps is that we are working together as a team: that security department and all the other departments within the company are working together to make sure that we're rolling out security functions, security operations, in a way that allows everybody to thrive and everybody to advance forward, and protect the company and all of its employees.
One of the reasons for this is that if you don't include all the employees of the company in what you're rolling out, if you're not giving consideration to what they want and how they operate, and making sure that you are working with them in rolling these out, what happens is they become a barrier to security and you can't move forward with it. So by including them in the decisions and in the processes, and educating them and bringing them along in the journey, we can actually press security forward together. That's the idea of SecOps — it's kind of a methodology that goes behind this security operations.
So really what we're mainly going to be focusing on throughout this course is those security operations, but what we want to do as we're rolling this out is be thinking about that SecOps idea: how are we going to include others in on this process to make it functional, make our security program functional?
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →