July 26, 2023, 7:06 p.m. | /u/Analyst4Life

cybersecurity www.reddit.com

In short: Is any of you guys using the closure code "Benign True Positive" in your SOC?

And do you have any good source for Industry Standard closure codes (that goes a bit deeper than just FP vs TP vs Duplicate)?

Asking because some folks in my company got the idea to introduce a Closure Code "Benign True Positive". Apparently inspired by [some Microsoft bloggers](https://learn.microsoft.com/en-us/defender-for-identity/understanding-security-alerts).

Their definition: "Alerted activity matched the use case logic as intended, but deeper investigation revealed …

case code cybersecurity definition good industry investigation logic soc standard use case

Consultant infrastructure sécurité H/F

@ Hifield | Sèvres, France

SOC Analyst

@ Wix | Tel Aviv, Israel

Information Security Operations Officer

@ International Labour Organization | Geneva, CH, 1200

PMO Cybersécurité H/F

@ Hifield | Sèvres, France

Third Party Risk Management - Consultant

@ KPMG India | Bengaluru, Karnataka, India

Consultant Cyber Sécurité H/F - Strasbourg

@ Hifield | Strasbourg, France