1 of 25

M5: Threat Detection in Operational & Technical Controls

Bridging Governance Signals to Operational Detection

(Logs, Monitoring, Control Failures)

Justin David Pineda CISSP, CISM

Version 1

Feb 2026

2 of 25

Trimillos vs. FCash

3 of 25

Guide Questions

  • What personal data did FCash access and use, and why did this become a problem?
  • Do you think installing an app automatically means you agree to everything it does with your data? Why or why not?
  • How can misuse of personal data cause harm even if there is no hacking involved?
  • Why is this case important for cybersecurity professionals, not just lawyers?
  • If you were designing a digital lending app, what controls or rules would you put in place to avoid the same issue?

4 of 25

Pre-Work Case Scenario

  • FinTech company with ISO 27001 certification
    • Logs not reviewed daily
    • Firewall alerts auto-closed
    • Backups not tested for 11 months

5 of 25

Learning Objectives

  • Identify operational threat indicators
    • Distinguish control existence vs effectiveness
    • Map weaknesses to ISO 27001 and NIST CSF
    • Explain why tools ≠ detection

6 of 25

Motivation Question

  • If you have SIEM, EDR, Firewall, DLP…
    • Why do breaches still happen?

7 of 25

Governance vs Operational Detection

  • Policies exist vs Logs reviewed daily
    • Risk accepted vs Alerts triaged
    • Controls documented vs Controls tested

8 of 25

Governance vs Operational Detection

Governance Level

Operational Level

Policies exist

Logs reviewed daily

Risk accepted

Alerts triaged

Exceptions approved

Access monitored

Controls documented

Controls tested

9 of 25

Control Design vs Control Execution

  • Designed Control: “All admin access logged.”
  • Executed Control: “Logs actually reviewed.”
  • Evidence: Daily review sign-off?
  • Escalation procedure documented?

Detection Failure Pattern:

Control exists but no one validates output.

10 of 25

Logging & Monitoring Gaps

  • Common Operational Weaknesses:
    • Logs collected but not centralized
    • SIEM tuned poorly (high false positives)
    • Alert fatigue
    • No defined response SLA
    • No after-hours monitoring

11 of 25

Alert Fatigue Risk

Symptoms:

  • Analysts auto-close alerts
  • Repetitive benign alerts
  • No alert prioritization model

Operational Threat:

  • True positive buried in noise

12 of 25

Privileged Access Monitoring Failures

Operational Risk Signals:

  • Shared admin accounts
  • No MFA on service accounts
  • Dormant accounts active
  • Admin login at 3:00 AM not reviewed

ISO Mapping:

  • A.8.2 Privileged Access Management
  • A.5.15 Access Control

NIST CSF:

  • PR.AC (Access Control)
  • DE.AE (Anomalies and Events)

13 of 25

Patch Management as Detection Indicator

Not just prevention — detection signal.

Red Flags:

  • Patch cycle exceeds 90 days
  • Critical vulnerabilities repeatedly deferred
  • No vulnerability trending dashboard

Operational Insight:

  • Unpatched systems = predictable exploitation window.

14 of 25

Backup Testing as Threat Indicator

Backup Exists ≠ Resilience

Operational Signal:

  • No restore test in 1 year
  • No ransomware simulation
  • No recovery time validation

Threat Detection View:

  • If attacker encrypts data today, can you recover?

ISO Mapping:

  • A.5.30 ICT Readiness for Business Continuity

15 of 25

Exception Culture & Silent Drift

Example:

  • Temporary firewall port opened
  • Never closed
  • No periodic review

Operational Drift Pattern:

  • “Temporary” becomes permanent.

Detection Trigger:

  • Exception register not reconciled quarterly.

16 of 25

Metrics That Detect Risk

Good Detection Metrics:

  • % of alerts reviewed within SLA
  • % of admin accounts with MFA
  • % of vulnerabilities patched within 30 days

Backup restore success rate

  • Mean time to detect (MTTD)

Bad Metrics:

  • Number of tools purchased
  • Number of policies written

17 of 25

From Signal to Incident

Bank

SME

University

SIEM exists but high false positives

No log retention policy

Logs exist but unmanaged

Strong governance

Weak execution

Decentralized IT

18 of 25

Metrics That Detect Risk

Operational Risk Chain:

  • Unreviewed Logs →
  • Missed Suspicious Login →
  • Lateral Movement →
  • Data Exfiltration →
  • Regulatory Breach

Key Insight:

  • Detection failure begins quietly.

19 of 25

Summary

  • Governance detects structural weakness.
  • Operational monitoring detects active exploitation.
  • Tools do not equal detection.
  • Control effectiveness must be measured.
  • Early operational drift predicts major incidents.

20 of 25

Knowledge Check 1

An organization collects firewall logs but does not review them unless an incident is reported. This is primarily:

A. Governance maturity� B. Control execution failure� C. Risk acceptance� D. Audit deficiency

21 of 25

Knowledge Check 2

Which metric is strongest for operational threat detection?

A. Number of security tools deployed� B. Number of policies approved� C. % of alerts reviewed within SLA� D. Number of employees trained

22 of 25

Knowledge Check 3

Shared privileged accounts primarily weaken which NIST CSF category?

A. ID.RA� B. PR.AC� C. RS.CO� D. RC.IM

23 of 25

Knowledge Check 4

If backup systems are never tested, the biggest detection risk is:

A. Increased audit scope� B. Financial inefficiency� C. False sense of resilience� D. Compliance delay

24 of 25

Knowledge Check 5

High false positives in SIEM primarily create:

A. Stronger prevention� B. Alert fatigue� C. Better governance� D. Risk elimination

25 of 25

Debrief & Reflection

  • Which operational signals are ignored in your workplace?
    • Do you measure control existence or effectiveness?