You are deleting the only detection for a named ATT&CK technique - who signs that off, and what must the record say?
answer
- accepted risk, not housekeeping
- state the behaviour, not the rule id
- who could have funded the alternative?
- temporary by definition
- keep the telemetry even without the rule
basics
~20 sA named risk owner with the budget to fund the alternative signs it, not the SOC alone. The record names the technique and estate scope, the residual visibility, the options priced, an expiry date and the trigger to revisit.
solid answer
~50 sFrame it as accepted risk, not queue maintenance. Write the loss in behavioural terms - "we will not detect scheduled task creation for persistence, `T1053.005`, across 30,000 Windows endpoints" - and state what still covers part of it, so the residual gap is explicit rather than implied. The signatory is the person accountable if that technique appears in an incident review and who could have funded the alternative: a business or enterprise risk owner under the risk-acceptance policy, countersigned by the SOC and the detection engineer who owns the rule. The record must carry the alternatives you priced (engineering time to make the rule precise, extra analysts, a preventive control), any compensating measure such as retaining the telemetry for retro-hunting, an expiry date with a review, and a named trigger to reopen. Undated, unowned and unpriced is what reads as negligence later.
go deeper
Know that turning off a detection is a risk decision someone must own, and that the record should say which behaviour stops being detected rather than just which rule was removed.
Be able to describe what a defensible acceptance record contains: the technique and scope, residual coverage, an owner, an expiry, and a compensating measure such as retaining the telemetry.
Show that you price the alternatives before proposing deletion - engineering effort for precision, a corroborating source, a preventive control - and that you can state the residual coverage precisely rather than waving at it.
Own the escalation. Insist the signatory is whoever could have funded the alternative, keep acceptances time-boxed and in the risk register, and be ready to defend the record to an insurer, an auditor or a post-incident review.
## The decision, stated honestly A rule producing hundreds of alerts a day that four analysts cannot work has three futures: it becomes precise (engineering time), it becomes automated (a closure criterion, with all the risk that carries), or it goes away. Choosing the third is legitimate. Pretending it is a housekeeping task is not. Deleting the only detection for a technique is a decision to be blind to a class of adversary behaviour for as long as the deletion stands, and it should leave the same kind of record any other accepted risk leaves. ## Write the loss in behaviour, not in rule ids "Retired rule 47" tells a future reader nothing. "We will not detect scheduled task creation used for persistence, `T1053.005`, on any of 30,000 Windows endpoints" is a sentence someone can disagree with. Then state the **residual**: which other detections still catch part of the behaviour (the follow-on execution, the outbound connection, the account's later use), and which part is genuinely uncovered. Most deletions are partial - the honest record says how partial. ## Who signs The test is simple: **who would be asked to explain this in an incident review, and who could have funded the alternative?** That is rarely the SOC manager alone, because the SOC has no budget to hire the analysts or buy the engineering time that would have kept the rule. It is the accountable risk owner named by the organisation's risk-acceptance policy - a business owner for the affected estate, or the enterprise security risk owner - with the SOC lead and the detection engineer as countersignatories who supply the technical statement. Insisting on a signatory is not bureaucracy; it is the mechanism that converts a quiet capacity problem into a visible funding decision. A surprising number of deletions do not survive contact with the person who has to sign, and the rule gets funded instead. ## The meeting this decision is actually made in The detection engineer who wrote the rule and the queue owner who wants it gone are usually in the same room, and both are right. The queue owner has a measurement: this rule consumes a large share of a queue that cannot be finished at any tuning level. The engineer has a different one: this rule is the only place a specific behaviour is visible, and its yield was low because the estate is mostly clean, not because the logic is wrong. Neither number settles it. What settles it is pricing the third option - what it would cost in engineering time to make the rule precise, and what a corroborating source would cost - and putting that price in front of someone who can pay it or decline it in writing. ## What the record must contain to survive scrutiny - **The behaviour lost and the estate scope**, in technique terms. - **The residual coverage**, named specifically. - **The options priced**: make it precise, corroborate it, staff it, or prevent it. A record with no rejected alternatives reads as a decision made without one. - **Compensating measures.** The strongest is usually keeping the telemetry even though nothing detects on it: you lose detection at the time but keep the ability to hunt periodically and to reconstruct after the fact. A scheduled hunt for the same behaviour is a cheaper substitute for a rule nobody can work. - **A named individual signatory and a date.** A committee is not an owner. - **An expiry and a review date.** Acceptance is temporary by definition; the version that runs forever is just an undocumented gap. - **A reopen trigger** - the technique appearing in threat intelligence for your sector, an acquisition, a change in the estate that alters the volume. - **Discoverability.** It belongs in the risk register the auditor and the insurer will read, not in a comment on a closed ticket. ## How it reads later After an intrusion using that technique, two records are possible. One says a named owner accepted a specific, scoped, time-boxed blind spot after pricing the alternatives, with retained telemetry and a quarterly hunt as compensation, and a review date that had not yet passed. The other says the rule was noisy so someone turned it off. The first is a defensible risk decision that also demonstrates the programme knew where its gaps were; the second is the sentence that gets read aloud. The same asymmetry applies to an insurer asking whether you had detection for the technique used, and to an auditor sampling how exceptions are approved: the question is almost never "did you have a gap" - everyone has gaps - but "did you know, and who decided".
- The SOC manager offers to sign it themselves to keep things moving. Why push back?Because they cannot fund the alternative. A signature is meaningful when the signer had a real choice - pay for precision or extra capacity, or accept the gap - and the SOC usually controls neither budget. Letting them sign converts a funding decision into an operational one and hides it from the people who would have paid. Escalate it to the accountable risk owner.
- What compensating measure most changes how a deletion reads afterwards?Keeping the telemetry the deleted rule ran on. You lose detection at the time but keep evidence, so the behaviour is still huntable on a schedule and still reconstructable during an investigation. A quarterly hunt for the same technique plus retained logs turns total blindness into delayed sight, which is a far more defensible position.
- How do you keep a time-boxed acceptance from silently becoming permanent?Give it an expiry date on which the exception lapses rather than a review date that can be missed, put it in the risk register that gets reported on, and attach reopen triggers - the technique appearing in sector intelligence, a change in the estate, a merger. Then report expiring acceptances alongside the rest of the programme's numbers so renewal is a deliberate act.
saying these in an interview costs you the question
- Deletes a noisy rule with only a ticket comment
- Records the rule id instead of the behaviour lost
- Has the SOC accept enterprise risk it cannot fund
- Accepts the gap indefinitely with no expiry
- Never prices making the rule precise as an option
- Drops the underlying telemetry along with the rule