My AiOPS Journey
My AIOps Journey: A Comprehensive Overview
I began my AIOps journey on 29th March , and I am excited to share what I have learned and how it can benefit you. Below, I outline the key areas of focus in AIOps and provide insights into my learning experience.
Core Areas of AIOps
Cyber Security
SysOps
DevOps
Cloud Computing
Artificial Intelligence
Cyber Security
In the realm of cyber security, I have gained hands-on experience in various domains, including web, mobile, and API penetration testing, source code review, and both static (SAST) and dynamic (DAST) application security testing. For vulnerability assessment and penetration testing, I follow the OWASP Top 10, WSTG, and MSTG guidelines and participate in bug bounties.
From a theoretical perspective, I have studied CISSP, which provided deep insights into concepts like:
Due care and due diligence
Types of security audits
SOC 2 reporting requirements
The importance of defining the scope of security audits
CIA (Confidentiality, Integrity, Availability) triad
Compliance with local laws
Business Continuity and Disaster Recovery (BCDR)
Recovery Time Objective (RTO)
Key Takeaways:
Data Set: An individual who is the subject of personal data.
Data Owner: The entity responsible for the data.
Security as Code: Implementing security measures as code embedded in the organization's fabric.
Additionally, I explored the Graham-Denning Security Model and preventive controls, which emphasized the gradual implementation of security measures. I also focused on top mitigation strategies, including system enumeration, entry point identification, log monitoring, account management security, backup verification, and patch management (both in-house and outsourced).
Practical Skills and Tools
I have developed practical skills in Red Hat Linux, including LUN scanning, disk scanning, logical and extended partition management, backup procedures, security configurations, GREP, IP gateway configuration, process management, and command-line tools like top
.
In coding, I have learned Python basics, Python automation, Python Selenium, and Bash scripting.
Cloud Computing
I have started learning AWS Solution Architect concepts, focusing on creating VPCs, subnets, CIDR blocks, and EC2 instances.
DevOps
My DevOps learning journey includes hands-on experience with Docker, understanding containerization, and exploring orchestration tools.
Subscribe to my newsletter
Read articles from Ashhad Ali directly inside your inbox. Subscribe to the newsletter, and don't miss out.
Written by