skip to content

Your post-intrusion collection requirement is refused on cost by the platform owner - what does the closure document record?

level: principalimportance: nice to knowfreq 32%

answer

  1. silence is the worst available option
  2. a decision needs a named decider
  3. negotiate the scope, not the principle
  4. write only mitigations you will perform
  5. written for a reader outside the SOC

basics

~20 s

Record the requirement as raised, the refusal, who decided it and when, the exposure that remains in operational terms, any compensating measure you will actually perform, and a date to revisit. Never quietly delete the requirement.

solid answer

~50 s

You do not delete it and you do not soften it into a suggestion. The closure states what was asked for, what was declined, who declined it, on what grounds, and what remains undetectable as a result - written plainly enough that a reader outside the SOC understands the exposure. Then you go looking for the smaller ask: a narrower event set, cheap cold storage instead of hot indexing, a scheduled manual pull of the gateway's local logs, or a preventive control that removes the need for the visibility altogether. And you push the acceptance upward: a decision to keep running blind belongs to someone with authority to accept the risk and should carry their name, not be absorbed silently by the SOC. Keep the tone factual - an auditor or examiner may read this, and it is not the place for an indictment.

go deeper

for a junior

Know that a security gap you cannot close yourself gets escalated and written down rather than dropped, and that the write-up says who decided and what stays exposed.

for a middle

Be ready to describe the record itself: the requirement as raised, the decision and its grounds, the decider and date, the residual exposure in operational terms, any compensating measure, and a review point.

for a senior

Show that you counter a flat no with a scoped ask - fewer event types, cold storage, a preventive control - and that you commit only to compensating measures you can evidence being performed.

for a principal

Own the framing that running blind is an accepted risk belonging to an accountable owner, and defend the record you leave behind when the organisation chooses cost over visibility.

## The situation The intrusion is closed. The write-up says, correctly, that the activity was invisible because a source was never collected, and it carries a scoped collection requirement naming the log, the host set, the events and the retention. The platform owner comes back with a number and a no: the ingest volume is not funded this year. The gap stays open, and the document is not finished. This is where a lot of security functions quietly fail. The requirement is dropped from the final version to avoid conflict, or downgraded to a sentence about `exploring options`, and eighteen months later the same blind spot appears in a worse incident with no record that anyone ever asked. ## What goes on the record Five things, and they are small: 1. **The requirement as raised** - unchanged, in its scoped form, with the cost estimate if you have one. The next reader must be able to see exactly what was asked for. 2. **The decision and its grounds** - declined, and why: volume cost, licence tier, no engineering capacity this cycle. Grounds, not motives. 3. **The decider and the date.** A decision without a name is not a decision; it is an outcome nobody owns. 4. **The residual exposure, in operational terms.** Not `risk remains high`, but: activity of this kind on this host class will not generate an alert, and after the fact it can only be reconstructed from local logs that overwrite within roughly N days, so an investigation reaching back further will not be able to answer when access began. 5. **What you will do instead, and the date this is re-examined.** ## Compensating measures that are honest Record only what you will actually perform and can evidence performing. Realistic options when central ingest is unfunded include a scheduled manual collection of the source's local logs at a defined cadence, a recurring hunt over the pulled copy, raising the local log's maximum size so the rollover window at least covers the review interval, or narrowing who can reach the system at all - a preventive control is sometimes cheaper than the visibility it replaces. Each needs a named performer and a way to show it happened. The failure mode is the compensating measure nobody performs. It is worse than an empty box, because in the document it reads as coverage: the next reader sees a mitigation and stops asking. If you cannot commit to running it, write that the exposure is unmitigated. ## Negotiate scope, not principle A flat no is often a no to the size of the ask. The scoped counter-offer is the professional move: only the two or three event identifiers that carry the behaviour rather than the whole log; ninety days hot and a year in cheap cold storage that is searchable slowly rather than everything indexed; the gateway pool only rather than the fleet. And make the cost case in terms the owner can act on - not `security is important`, but what the blind period cost this time: the analyst-days spent reconstructing by hand, the questions the investigation could not answer, the notification judgement made on an incomplete picture, and how much of the estate the same gap covers. Compare the narrowest ingest that would have answered those questions against that, rather than comparing the incident to the whole logging budget. ## Who accepts the risk The SOC's job is to identify and quantify a gap. Accepting the consequence of leaving it open is a business decision, and it belongs to an owner with the authority to make it - typically the accountable executive for the platform, or the risk function, depending on how the organisation is set up. Escalating is not an act of aggression; it is putting the decision at the level that can actually take it. Where a formal risk register exists, the entry goes there and the closure points at it. What must not happen is the SOC absorbing the acceptance by silence, which leaves the organisation exposed and the security function accountable for a call it never had the authority to make. ## Writing for a reader you have not met Assume an auditor, a customer's assurance team, a regulator or an examiner reads this in three years with no context. Two implications. First, factual register: what was asked, what was decided, by whom, what remains. No characterisation of the platform team, no editorialising, no hinting. Second, and counter-intuitively, the documented refusal **protects** the organisation rather than incriminating it. A named requirement, a named decision-maker and a stated residual exposure describe a process that found a gap and escalated it properly. The version that reads badly is the gap that everyone in the SOC knew about and that appears nowhere at all - because then there is no evidence the organisation ever knew, and an accepted risk becomes indistinguishable from negligence.

  • Is writing down a refused control not just creating evidence against your own organisation?
    In practice it is the opposite. A named requirement, a named decision-maker and a stated residual exposure describe a function that found a gap and escalated it properly. The damaging version is the gap the SOC knew about that appears nowhere - then nothing shows the organisation ever knew, and an accepted risk becomes indistinguishable from negligence. Keep the wording factual and free of characterisation.
  • What compensating measures are honest to record when central ingest is not funded?
    Only ones you will run and can evidence. A scheduled manual pull of the source's local logs at a stated cadence, a recurring hunt over the pulled copy, enlarging the local log so its rollover window covers that cadence, or restricting who can reach the system at all. Each needs a named performer. A measure nobody performs is worse than none, because in the document it reads as coverage.
  • How do you argue the cost case without simply re-telling the incident?
    Convert it into what the blind period actually cost: analyst-days spent reconstructing by hand, the questions the investigation could not answer, a notification judgement made on an incomplete picture, and how much of the estate carries the same gap. Then price the narrowest ingest that would have answered those questions. The owner can act on scoped cost versus investigation cost; they cannot act on an appeal to importance.

It is the difference between a declined insurance claim and a policy nobody remembers cancelling. The refusal is survivable when it is on the record with a name and a date, and indefensible when it is not.

saying these in an interview costs you the question

  • Quietly drops the requirement to avoid conflict
  • Writes the refusal as blame aimed at the platform team
  • Lets the SOC absorb the risk acceptance itself
  • Lists compensating measures nobody will perform
  • Re-argues the whole logging budget instead of a scoped ask
  • States residual exposure only as a colour or a score

context