Instiq
Chapter 5 · Security operations & supplier management·v1.0.0·Updated 7/11/2026·~15 min

What's changed: Initial version

5.1Security operations

Key points

Covers the operational controls that keep information security running in live service delivery-priority judgment for patch management and vulnerability management, log collection and monitoring, the SIEM that correlates multiple logs, and the handoff that connects detected incidents into incident management-framed as the judgments of an operator upholding SLA targets.

Designing information security and running it day to day are different activities. From a service-management viewpoint, you cannot patch every system at once whenever a vulnerability is disclosed; the judgment required is to remediate in order of risk-highest-risk vulnerabilities first-via the change-management procedure, while upholding SLA targets (availability, response time). This section covers the operational controls-prioritizing patch/vulnerability management, log collection and monitoring, the SIEM that cross-references multiple logs, and connecting detected events into incident and problem management-as an operator's judgment. The focus is not deep cryptography but "keeping the service secure without stopping it."

5.1.1Patch management and vulnerability management

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.