On Finding the Gaps in One’s Tools [/ɔn ˈfaɪndɪŋ ðə ˈgæps ɪn ˈwənz ˈtulz/] n - Every other note in IOC operations ends with a thread pointing here, and that is deliberate. An operations center is never done being tuned; the worth of an analyst who lives in the tools all day is that he can see where those tools fall short and feed that back into improvement. This is the continuous-improvement loop, and keeping it turning is part of the job, not a side project.
Where the Gaps Show Themselves
I do not hunt gaps abstractly; they announce themselves in the daily work, if you are paying attention:
- A rule that fires constantly and is actioned rarely is a tuning gap.
- A step in a On Running the Root-Cause Inquiry that everyone performs by hand the same way every time is an automation candidate.
- A number in a report that is painful to produce points at a data or integration gap.
- A credit that took a day to reconstruct means the evidence trail in Data integrity and log retention needs work.
- A recurring Field Notes that keeps generating tickets asks for a permanent fix, not repeated firefighting.
From Irritation to Backlog
The discipline lies in turning “this is annoying” into something that gets fixed. Each gap becomes a tracked item in the engineering backlog (usually the Jira side of the ITSM ticketing systems) with the same three questions attached:
- How often does it hurt, and how badly? [/ˈhɒw ˈɒftɛn ˈdɒɛs ˈɪt ˈhʌrt ˈænd ˈhɒw ˈbædli/] n Frequency times impact decides what is done first.
- Is it tuning, automation, or a missing capability? [/ˈɪs ˈɪt ˈtʌnɪng ˈæʌtɒmætɪɒn ˈɒr ˈæ ˈmɪssɪng ˈkæpæbɪlɪti/] n A threshold I can fix today, a script I can build this week, or a tool we may need to replace.
- What does “fixed” look like? [/ˈwhæt ˈdɒɛs ˈfɪxɛd ˈlʌːk ˈlɪkɛ/] n A measurable outcome, fewer pages, faster reports, a manual step removed; not merely “improved.”
Automation, the Default Answer
When the same safe action is taken over and over, it should cease to be a human’s job: auto-remediation for known-benign states, auto-enrichment so responders stop hunting for context, automated report pulls, scripted access reviews. The aim is not automation for its own sake but the return of the attention that repetitive toil was eating, so that people are free for the incidents that truly need a person. That payoff, measured, closes the loop back to Operational metrics and reporting.