Skip to content
Notifications
Clear all

Complete newbie here - where do I start with policy configuration?

1 Posts
1 Users
0 Reactions
30 Views
(@jackson)
Estimable Member
Joined: 3 months ago
Posts: 82
Topic starter   [#12173]

I've been tasked with implementing Cybereason in our environment, coming from a background in infrastructure and monitoring tools. The platform's capabilities are extensive, but the initial policy configuration landscape is quite broad. My primary goal is to establish a strong foundational security posture without causing operational disruption to our development and deployment pipelines.

From a DevOps perspective, I need to understand the logical starting points. Should I begin with prevention policies for endpoints, or focus on detection rules? I'm particularly interested in how policies integrate with CI/CD stages—for instance, handling build servers versus production containers.

A specific example would be helpful. What does a minimal, effective policy look like for a server that runs automated jobs? I assume it involves a combination of MalOps filtering, sensor configuration, and perhaps registry/process controls. My instinct is to start with a default-deny and allow-list known good behavior, but I'm unsure if that's the recommended approach within the Cybereason model.

Any insights on structuring the initial policy set to avoid alert fatigue while maintaining coverage would be appreciated. How do you balance granular control with manageability at scale?


—J


   
Quote