✳ Field lesson F8b / 7 min

Categories are capabilities

Match a named outcome to a capability such as IAM, PAM, SIEM, EDR, or WAF, and notice when labels such as XDR, MDR, SASE, and SSE overlap. Optional after F8a. Not required to start SOC, AppSec, or GRC practice.

foundationsproductscategories

What you’ll be able to do

  • Match IAM, PAM, SIEM, EDR, and WAF to a capability, and name what each label does not prove.
  • Explain why XDR, MDR, SASE, and SSE overlap instead of naming four finished jobs.
  • Keep the F1 loss sentence and the F8a outcome in the note even when a category might help.

Categories are capabilities, not endorsements

Once F8a has named the outcome, a product category might help. Identity and access management (IAM) helps create and authenticate Jordan’s record. Privileged access management (PAM) helps wrap the YardOS admin role. A security information and event management (SIEM) system helps collect the 02:14 logs. Endpoint detection and response (EDR) helps inspect the contractor laptop. A web application firewall (WAF) might sit in front of TrackPort. None of those names is a substitute for the F1 loss sentence.

This lesson is optional. SOC triage, vulnerability prioritization, and the AppSec lessons do not wait on it. Buying a category is not how you start those paths.

  • Outcome: drivers cannot be impersonated into TrackPort exports.
  • Control: phishing-resistant MFA, scoped tokens, export authorization, session revoke.
  • Evidence: identity logs, application authorization denials, restore-test records.
  • Category: IAM plus SIEM plus, if needed, PAM. Do not buy a label and skip the sentence.

Labels overlap

Industry labels overlap on purpose. Extended detection and response (XDR) vendors claim to stitch endpoint, network, and identity signals. Managed detection and response (MDR) sells people plus tooling. Secure access service edge (SASE) and security service edge (SSE) packages network and cloud access controls. If you cannot say which outcome a category is serving, you are shopping.

ATT&CK can later describe adversary behaviors you hope to detect. It is not a coverage score for a purchase. A brochure cell is not evidence that TrackPort exports would be caught.

Worked gap: what might help the VPN and the export

F8a already wrote the VPN-and-export outcomes, the IG1-minded actions, and the evidence line. Categories that might support those controls: vulnerability management for the appliance queue, IAM for MFA, a SIEM for joining identity and TrackPort logs, and EDR for the laptop that approved the prompt. Each name is a capability. None of them is the geofence question, and none of them is the loss sentence.

You can leave Foundations after F8a. You can start SOC practice without naming XDR, MDR, SASE, or SSE. Use a category only when an outcome you already wrote still has a gap.

CHECK YOUR JUDGMENT

Devon says buying an XDR finishes Detect for the VPN-and-export risk, so Riverstone can skip the outcome sentence and start the SOC path on the strength of the purchase. What should Maya record?

Put your learning to work ↗

Find your next idea.

Tip: press / to open search. Escape closes this window.