Network Security
Network Security Monitoring Overview.
Netzüberwachung nach ISO 27001 A.13: IDS/IPS, Traffic-Analyse, SIEM-Integration und Alarmierung.
IDS/IPS (Intrusion Detection/Prevention)
- Signature-based detection of known attack patterns
- Anomaly-based detection for zero-day and unknown threats
- Automated blocking of identified malicious traffic
- Regular update of detection rules and signatures
SIEM (Security Information & Event Management)
- Central log aggregation from all network components
- Correlation rules for multi-stage attack detection
- Automated alerting to SOC (24/7)
- Compliance reporting for audits and regulatory requirements
DORA Alignment
- Art. 10: Anomaly detection — SIEM correlation rules identify deviations from baseline
- Art. 13: Threat detection — IDS/IPS detect known and unknown threats
- Art. 24: Network resilience tests — Regular penetration tests of network components
- Art. 28-30: Third-party monitoring — Detection of anomalies in provider connections