SOT

SOT

SOAR
Security Orchestration, Automation and Response

Automation of response to information security incidents using dynamic playbooks and information security tools, building an attack chain and with an object-oriented approach

NG SOAR
Next Generation SOAR

Automation of response to information security incidents with built-in basic correlation (SIEM), vulnerability Scanner (VS), collection of raw events directly from information security tools, dynamic playbooks, building an attack chain and an object-oriented approach. AM and VM are included

AM
Asset Management

Description of the IT landscape, detection of new objects on the network, categorization of assets, inventory, life cycle management of equipment and software on automated workstations and servers of organizations

VS
Vulnerability Scanner

Scanning information assets with enrichment from any external services (additional scanners, The Data Security Threats Database and other analytical databases) to analyze the security of the infrastructure.

VM
Vulnerability Management

Building a process for detecting and eliminating technical vulnerabilities, collecting information from existing security scanners, update management platforms, expert external services and other solutions

FinCERT
Financial Computer Emergency Response Team

Bilateral interaction with the Central Bank, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

GovCERT
Government Computer Emergency Response Team

Bilateral interaction with the state coordination center for computer incidents, namely the transfer of information about incidents and receipt of prompt notifications/bulletins from the regulator

Mail us to sales@securityvision.ru or get demo presentation

Information security processes in ITIL

Information security processes in ITIL
06.07.2026

Ruslan Rakhmetov, Security Vision


Cybersecurity is no longer perceived by businesses as a restrictive function. Mature information security processes not only provide a secure foundation for all company business activities but also become a competitive advantage, demonstrating the organization's resilience and reliability to clients and partners. Cybersecurity is closely intertwined with IT – specialists from these fields work together to ensure that digitalized business processes function not only quickly and conveniently, but also securely. In the IT field, there are a number of well-known international frameworks and standards that enable optimal process design. The ITIL framework is focused on providing high-quality IT services to businesses and also includes a description of information security management practices – this section will be covered in this publication.

 

The acronym ITIL came into use in the late 1980s and stood for Information Technology Infrastructure Library. This library contained recommendations and best practices for IT service management. As the IT industry evolved, the approach to standardization also changed – the ITIL framework has undergone several revisions, the most popular of which are ITIL 4, released in February 2019, and ITIL 5, which was introduced in early 2026. The latest, fifth version of ITIL places emphasis on managing AI systems, IT professionals' work in conditions of uncertainty and continuous change, and extensive process automation. Compared to ITIL 4, ITIL 5 divides all practices (IT processes) not into three groups, but into just two: general management practices and product and service management practices.

 

Common management practices include:


1) Architecture Management – understanding the structure of all elements (business processes, systems, assets) of an organization and their interrelations;


2) Continual Improvement – bringing an organization's practices and services into line with changing business needs through the continuous identification and improvement of all elements involved in the management of products and services;


3) Knowledge Management – maintaining and improving the efficiency, effectiveness and ease of use of accumulated information and knowledge in an organization;


4) Measurement and Reporting is a practice aimed at supporting informed decision-making and continuous improvement by reducing the level of uncertainty;


5) Organizational Change Management – ensuring the smooth and successful implementation of changes in an organization, achieving long-term results by managing the human factor of these changes;


6) Portfolio Management – ensuring that an organization has the optimal combination of programs, projects, products and services to implement its strategy within the existing financial and resource constraints;


7) Project Management – ensuring the successful implementation of all projects of the organization;


8) Relationship Management – establishing and maintaining relationships between an organization and its stakeholders at the strategic and tactical levels;


9) Risk Management – ensuring understanding and effective risk management in an organization;


10) Strategy Management – defining the strategic goals of an organization, taking the necessary measures and allocating resources to achieve these goals;


11) Supplier Management – management of an organization's suppliers and their performance to support the uninterrupted provision of quality products and services;


12) Workforce and Talent Management is the practice of ensuring that an organization has the right people with the appropriate skills and knowledge in the right positions to achieve business goals.

 

Product and service management practices include:


1) Availability Management – ensuring the provision of services with a pre-agreed level of availability;


2) Business Analysis is the practice of conducting an analysis of a business or individual processes, determining needs, and providing applicable and rational solutions to the identified problems;


3) Capacity and Performance Management – achieving an agreed level of efficiency for services;


4) Ensuring Change Enablement – changes in products and services lead to increased value while minimizing risks;


5) Deployment Management – the movement of new or modified software and hardware components, processes, documents or other service components into a controlled environment;


6) IT Incident Management – the practice of minimizing the negative impact of incidents by quickly restoring service operation (in this case, we mean IT incidents, which are defined as unplanned service disruptions or reductions in service quality);


7) Infrastructure and Platform Management is the practice of monitoring infrastructure and platforms, which allows for tracking available technological solutions, including those from third-party companies;


8) IT Asset Management – planning and management of the full life cycle of all IT assets;


9) Monitoring and Event Management – the practice of systematically monitoring services and service components, recording and reporting on certain changes (events);


10) Problem Management – the practice of reducing the likelihood and consequences of IT incidents by identifying actual and potential causes of incidents and managing workarounds and known errors;


11) Release Management – the practice of providing users with new and modified services and functions;


12) Service Catalog Management – providing a single source of reliable information about all services and ensuring the availability of this information for consumers;


13) Service Configuration Management – providing accurate and reliable information about the configuration of services and the configuration elements that support them (configuration items);


14) Service Continuity Management – maintaining the availability and efficiency of services provided at a sufficient level in case of emergency situations;


15) Service Design is the practice of designing products and services that are fit for purpose, suitable for use, and can be provided by an organization;


16) Service Desk – providing all users with a single point of entry and interaction with the service provider, receiving requests for service provision and resolving incidents;


17) Service Financial Management – supporting the organization’s strategy and plans for service management by ensuring the efficient use of the organization’s financial resources and investments;


18) Service Level Management – setting clear, business-oriented service level objectives and ensuring that service delivery is measured, monitored, and managed against those objectives;


19) Service Request Management – ensuring the agreed quality of services through efficient and convenient processing of all user service requests;


20) Service Validation and Testing – ensuring that new or modified products and services comply with established requirements;


21) Software Development and Management – ensuring that software meets the needs of stakeholders in terms of functionality, reliability, maintainability, compliance with regulatory requirements, and audit capabilities:


22) Information Security Management is a policy that regulates an organization’s approach to information security management.

 

Let's take a closer look at the last point: the practice of information security management in the context of ITIL is closely interconnected with the practices of "IT Incident Management" (item 6 above), "Change Assurance" (item 4 above), "Service Continuity Management" (item 14), "Monitoring and Event Management" (item 9), as well as with such general management practices as "Risk Management" (item 9) and "Supplier Management" (item 11). The goals of information security management practice according to ITIL are:

  • Protection of confidentiality, integrity and availability of information;

  • Supporting the development of products and services by reducing risks;

  • Ensuring cyber resilience and supporting digital business transformation processes;

  • Supporting a risk-based approach to organizational decision-making;

  • Implementation of the principle of constructively embedded cybersecurity (security by design);

  • Compliance of information security management practices with legal requirements, internal and industry standards and regulations;

  • Ensuring the trust of users, customers, and stakeholders by providing secure services and products;

  • Supporting continuous improvement of information security through ongoing monitoring and reporting;

  • Ensuring the organization's secure operation with AI systems.

 

The key areas of practice in information security management according to ITIL are:

  • Defining information security management policy: developing strategy, standards and rules, appointing responsible persons, supporting the cybersecurity management structure in the company;

  • Cyber risk management: identifying threats and vulnerabilities, determining potential damage and assigning risk owners, carrying out the stages of identification, analysis, and risk assessment, creating a risk register, developing risk treatment methods for each IT system under consideration, and implementing risk treatment plans;

  • Implementation and management of technical, organizational, and physical security measures: implementation and configuration of information security systems, development of local regulations on information security, implementation of technical security means;

  • Account and privilege management: selecting an appropriate access control model, setting up technical means for its implementation, granting access rights to users in accordance with the selected model, implementing correct authentication and authorization of users, monitoring their powers, adhering to the principles of least privilege and separation of powers, granting access only if there is approval and business necessity;

  • Vulnerability management: developing a vulnerability management policy, including insecure configurations, identifying, assessing, and prioritizing vulnerabilities, selecting a treatment method for each vulnerability based on its properties, and monitoring completed actions (installing security updates, disabling vulnerable functionality, implementing compensating measures, etc.);

  • Information security incident management: execution of all response phases (preparation, detection, analysis, localization, elimination, recovery, post-incident actions), synchronization of actions with IT incident management practices;

  • Compliance management: the implementation of information security policies must be carried out in accordance with the requirements of applicable legislative, industry, holding, corporate regulations, as well as in accordance with the requirements of partners, contractors and clients;

  • Ensuring staff awareness of information security issues: promoting a cybersecurity culture, observing cyber hygiene rules , increasing the maturity of staff training processes on information security issues, conducting classes, seminars, training sessions (including test phishing mailings, cyber exercises, training alerts, etc.);

  • Ensuring secure software development processes: If a company creates its own applications, then to ensure their security, cybersecurity requirements should be taken into account at the earliest stages of product development (the "shift left" rule) and ensure application security at all stages of the life cycle;

  • Monitoring and reporting: audit logs should be maintained, incidents and events should be analyzed, applicable metrics should be defined, and their achievement should be monitored. KPIs such as the number of information security incidents, MTTD (mean time to detect an incident) and MTTR (mean time to respond to an incident), statistics on vulnerabilities closed on time, the percentage of assets compliant with requirements, the percentage of accounts covered by MFA, the success rate of internal audits, the number of counterparties verified in the information security area, the success rate of user phishing detection during test mailings, and other indicators can be used;

  • AI Security: When using AI internally, it is important to secure the relevant systems (e.g., control the permissions of AI agents, protect LLMs from prompt injection and data poisoning attacks, and protect models from unauthorized distillation). When using external AI systems, it is important to prevent sensitive data from leaking (e.g., to third-party GPT solutions).

 

ITIL emphasizes the importance of a process-based approach to implementing information security management practices, which includes the following key steps:


1) Definition of the protected assets of the organization, their classification and assignment of responsible persons;


2) Risk analysis, threat and attacker modeling;


3) Selection of risk treatment methods, development and approval of protective measures;


4) Implementation of technical, organizational, and physical protective measures;


5) Monitoring and responding to information security incidents, exceeding the risk level, and non-compliance with legal requirements;


6) Evaluation of the effectiveness of the measures implemented (including pentests, Red Team), analysis of "lessons learned" after incidents, reassessment of cyber threats, adjustment of risk properties and methods of their treatment, fine-tuning of protection measures.

 

The success of information security management practices implemented in accordance with the ITIL framework can be assessed by the following criteria and factors:

  • Compliance of the established information security management system with the requirements and expectations of the business;

  • Support for the cybersecurity direction from the company’s management and stakeholders;

  • Level of maturity of cyber risk management processes;

  • The completeness of the implementation of the concept of constructively embedded cybersecurity (security by design);

  • Compliance of the information security management system with legal requirements, industry standards, holding and corporate standards;

  • The quality of the established information security incident management process, the depth of the post-analysis, and the stability of feedback to improve the level of security based on the results of incident investigations;

  • Level of staff awareness in information security issues;

  • Continuous improvement of information security quality based on metrics, audits, and taking into account the changing threat landscape and legislative requirements.

  • Integrating adequate security measures into software development processes and into the AI systems used.

 

The ITIL framework emphasizes the importance of automating information security management processes – in today's rapidly changing infrastructures, ensuring cybersecurity without robotics is becoming impossible. Cybersecurity process automation platforms allow all information security processes to be aligned with the aforementioned ITIL recommendations: for example, the Security Vision platform enables asset management to be built into the Asset Management product (Security Vision AM), while vulnerability management can be organized within Vulnerability products. Management (Security Vision VM) and Vulnerability Scanner (Security Vision VS), configuration management available in the Security Profile Compliance product (Security Vision SPC), risk management is entirely dedicated to the Risk Management product (Security Vision RM), and compliance with information security requirements can be monitored in Security Vision Compliance products (CM) and Self-Assessment (Security Vision SA). Security Vision SIEM and Security Vision SOAR / NG SOAR can be used for event and incident management, Security Vision ASOC can be used for secure software development, and Security Vision BCM can be used for business continuity. The use of a unified low-code/no-code Security Vision platform enables maximum flexibility in configuring all information security processes, including those required by various frameworks, including ITIL. It also enables the use of a unified resource-service infrastructure model and the building of an entire cybersecurity management system based on actual, up-to-date data received through integration with various systems and security tools.

Recommended

Antifraud systems - what is it and how does it work
Antifraud systems - what is it and how does it work
What is the Trusted Platform Module (TPM Module) and how is it used to ensure the cybersecurity of endpoints?
What is the Trusted Platform Module (TPM Module) and how is it used to ensure the cybersecurity of endpoints?
Open and closed source code, different types of licenses and their impact on cybersecurity
Open and closed source code, different types of licenses and their impact on cybersecurity
Between biscuits and carrots: keeping the team in limbo
Between biscuits and carrots: keeping the team in limbo
Ecosystem of products for retrospective analysis
Ecosystem of products for retrospective analysis
How Zeek and Malcolm help you not only passively analyse network traffic, but also respond to threats in a timely manner
How Zeek and Malcolm help you not only passively analyse network traffic, but also respond to threats in a timely manner
What is obfuscation? Part 2
What is obfuscation? Part 2
Vulnerability search methods and types of scanners
Vulnerability search methods and types of scanners
Dynamic behavioral analysis and its tools
Dynamic behavioral analysis and its tools
Security Vision presents a new product: Security Vision Personal Data Management
Security Vision presents a new product: Security Vision Personal Data Management
Everything you wanted to know about web tokens, but were afraid to ask
Everything you wanted to know about web tokens, but were afraid to ask
SOC architecture: three response lines (L1, L2 and L3)
SOC architecture: three response lines (L1, L2 and L3)

Recommended

Antifraud systems - what is it and how does it work
Antifraud systems - what is it and how does it work
What is the Trusted Platform Module (TPM Module) and how is it used to ensure the cybersecurity of endpoints?
What is the Trusted Platform Module (TPM Module) and how is it used to ensure the cybersecurity of endpoints?
Open and closed source code, different types of licenses and their impact on cybersecurity
Open and closed source code, different types of licenses and their impact on cybersecurity
Between biscuits and carrots: keeping the team in limbo
Between biscuits and carrots: keeping the team in limbo
Ecosystem of products for retrospective analysis
Ecosystem of products for retrospective analysis
How Zeek and Malcolm help you not only passively analyse network traffic, but also respond to threats in a timely manner
How Zeek and Malcolm help you not only passively analyse network traffic, but also respond to threats in a timely manner
What is obfuscation? Part 2
What is obfuscation? Part 2
Vulnerability search methods and types of scanners
Vulnerability search methods and types of scanners
Dynamic behavioral analysis and its tools
Dynamic behavioral analysis and its tools
Security Vision presents a new product: Security Vision Personal Data Management
Security Vision presents a new product: Security Vision Personal Data Management
Everything you wanted to know about web tokens, but were afraid to ask
Everything you wanted to know about web tokens, but were afraid to ask
SOC architecture: three response lines (L1, L2 and L3)
SOC architecture: three response lines (L1, L2 and L3)