Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

Jump to content

Blue team (computer security)

From Wikipedia, the free encyclopedia

A blue team is a group of individuals who perform an analysis of information systems to ensure security, identify security flaws, verify the effectiveness of each security measure, and make certain all security measures will continue to be effective after implementation.[1][2] The United States National Institute of Standards and Technology glossary defines a blue team as "the group responsible for defending an enterprise's use of information systems by maintaining its security posture against a group of mock attackers".

Some blue team objectives include:

  • Using risk intelligence and digital footprint analysis to find and fix vulnerabilities and prevent possible security incidents.
  • Conduct regular security audits such as incident response and recovery.[3]

History

[edit]

As part of the United States computer security defense initiative, red teams were developed to exploit other malicious entities that would do them harm. As a result, blue teams were developed to design defensive measures against such red team activities.[4]

Incident response

[edit]

If an incident does occur within the organization, the blue team will perform the following six steps to handle the situation:

  1. Preparation
  2. Identification
  3. Containment
  4. Eradication
  5. Recovery
  6. Lessons learned[5]

Operating system hardening

[edit]

In preparation for a computer security incident, the blue team will perform hardening techniques on all operating systems throughout the organization.[6]

Perimeter defense

[edit]

The blue team should consider the network perimeter, including traffic flow, packet filtering, proxy firewalls, and intrusion detection systems.[6]

Tools

[edit]

Blue teams employ a wide range of tools allowing them to detect an attack, collect forensic data, perform data analysis and make changes to thwart future attacks and mitigate threats. The tools include:

Log management and analysis

[edit]

Security information and event management (SIEM) technology

[edit]

SIEM software supports threat detection and security incident response by performing real-time data collection and analysis of security events. This type of software also uses data sources outside of the network including indicators of compromise (IoC) threat intelligence.

Exercises

[edit]

Blue teams take part in regular red team–blue team exercises, in which an attacking team attempts to compromise systems defended by the blue team under controlled conditions. One of the largest of these is Locked Shields, an annual live-fire cyber defence exercise organised since 2010 by the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), in which national blue teams defend simulated critical infrastructure against a professional red team.[7]

See also

[edit]

References

[edit]
  1. Sypris Electronics. "DoDD 8570.1: Blue Team". Sypris Electronics. Archived from the original on April 25, 2016. Retrieved July 3, 2016.
  2. "blue team - Glossary". NIST Computer Security Resource Center. National Institute of Standards and Technology. Retrieved 21 August 2026.
  3. "What is Blue Team? | IBM". www.ibm.com. 2023-12-14. Retrieved 2024-09-07.
  4. Johnson, Rowland. "How your red team penetration testers can help improve your blue team". SC Magazine. Archived from the original on May 30, 2016. Retrieved July 3, 2016.
  5. Murdoch, Don (2014). Blue Team Handbook: Incident Response Edition (2nd ed.). reateSpace Independent Publishing Platform. ISBN 978-1500734756.
  6. 1 2 SANS Institute. "Cyber Guardian: Blue Team". SANS. SANS Institute. Retrieved July 3, 2016.
  7. "Locked Shields". NATO Cooperative Cyber Defence Centre of Excellence. Retrieved 21 August 2026.