Blue team (computer security)
A blue team is a group of individuals who perform an analysis of information systems to ensure security, identify security flaws, verify the effectiveness of each security measure, and make certain all security measures will continue to be effective after implementation.
Some blue team objectives include:
- Using risk intelligence and digital footprint analysis to find and fix vulnerabilities and prevent possible security incidents.
- Conduct regular security audits such as incident response and recovery.
History
As part of the United States computer security defense initiative, red teams were developed to exploit other malicious entities that would do them harm. As a result, blue teams were developed to design defensive measures against such red team activities.Incident response
If an incident does occur within the organization, the blue team will perform the following six steps to handle the situation:- Preparation
- Identification
- Containment
- Eradication
- Recovery
- Lessons learned