M5: Threat Detection in Operational & Technical Controls
Bridging Governance Signals to Operational Detection
(Logs, Monitoring, Control Failures)
Justin David Pineda CISSP, CISM
Version 1
Feb 2026
Trimillos vs. FCash
Guide Questions
Pre-Work Case Scenario
Learning Objectives
Motivation Question
Governance vs Operational Detection
Governance vs Operational Detection
Governance Level | Operational Level |
Policies exist | Logs reviewed daily |
Risk accepted | Alerts triaged |
Exceptions approved | Access monitored |
Controls documented | Controls tested |
Control Design vs Control Execution
Detection Failure Pattern:
Control exists but no one validates output.
Logging & Monitoring Gaps
Alert Fatigue Risk
Symptoms:
Operational Threat:
Privileged Access Monitoring Failures
Operational Risk Signals:
ISO Mapping:
NIST CSF:
Patch Management as Detection Indicator
Not just prevention — detection signal.
Red Flags:
Operational Insight:
Backup Testing as Threat Indicator
Backup Exists ≠ Resilience
Operational Signal:
Threat Detection View:
ISO Mapping:
Exception Culture & Silent Drift
Example:
Operational Drift Pattern:
Detection Trigger:
Metrics That Detect Risk
Good Detection Metrics:
Backup restore success rate
Bad Metrics:
From Signal to Incident
Bank | SME | University |
SIEM exists but high false positives | No log retention policy | Logs exist but unmanaged |
Strong governance | Weak execution | Decentralized IT |
Metrics That Detect Risk
Operational Risk Chain:
Key Insight:
Summary
Knowledge Check 1
An organization collects firewall logs but does not review them unless an incident is reported. This is primarily:
A. Governance maturity� B. Control execution failure� C. Risk acceptance� D. Audit deficiency
Knowledge Check 2
Which metric is strongest for operational threat detection?
A. Number of security tools deployed� B. Number of policies approved� C. % of alerts reviewed within SLA� D. Number of employees trained
Knowledge Check 3
Shared privileged accounts primarily weaken which NIST CSF category?
A. ID.RA� B. PR.AC� C. RS.CO� D. RC.IM
Knowledge Check 4
If backup systems are never tested, the biggest detection risk is:
A. Increased audit scope� B. Financial inefficiency� C. False sense of resilience� D. Compliance delay
Knowledge Check 5
High false positives in SIEM primarily create:
A. Stronger prevention� B. Alert fatigue� C. Better governance� D. Risk elimination
Debrief & Reflection