SOC Types and Roles

 

Types of SOC Models

Each organization has its own requirements and budget allocated to SOC. So, there are several types of SOC based on those requirements and budget:

  1. In-House SOC – Organization builds their own cybersecurity team. But such organization should have a budget to support the survival of the SOC team.
  2. Virtual SOC – SOC team does not have their own facility and works often from remote locations.
  3. Co-Managed SOC – Organization’s internal SOC team works with an external Managed Security Service Provider (MSSP). In this model, communication and coordination between internal and external teams is important.
  4. Command SOC – Senior and experienced SOC team overseeing the smaller SOCs in a large region. Major telecom providers and defense agencies operate on this model.

SOC – People, Processes, and Technology

A strong coordination between people, processes, and technologies is required to build a strong, capable and successful SOC.

People – SOC needs highly trained employees who are familiar with security alerts, exploits, and attack scenarios. Cyber attacks are constantly evolving, employees need to research and adapt with new attack scenarios.

Processes – SOC needs to have a mature structure which can be aligned with many security requirements such as HIPAA, NIST, PCI DSS, etc. Processes need to have standardized actions to ensure nothing is skipped.

Technology – SOC needs a various tools and technologies to perform different tasks like monitoring alerts, detecting threats, analyzing, pentesting, prevention, etc. Organization need to follow market closely to find the best solution for its requirements. A best product in the market may not be the best for organization. Get the best solution based on organizations requirements and budget allocated.

SOC Roles





Comments

Popular posts from this blog

SOC L1, L2 & L3 Analyst Responsibilities

Introduction to SOC